NKNivethitha Kumaraveluinnebulablogs.com·Sep 5 · 10 min readSecurity-review the agent app the coding agent just shippedWhen a coding agent builds a a brand-new AI integration on your ecommerce site (for example), you often get a big PR and a short note that "auth and tool calling are done." If your job is to check the00
NKNivethitha Kumaraveluinnebulablogs.com·Sep 4 · 8 min readAgentic AI is evolving the WAFWeb application firewalls still sit in front of the request. What is changing is how rules get researched, drafted, tested and promoted when a new exploit lands. Agentic AI helps because it can join w00
NKNivethitha Kumaraveluinnebulablogs.com·Aug 31 · 10 min readAgent skills in security engineering: encoding the vulnerability triage loopWorking through the security queue, I keep hitting the same friction. A CVE lands with a CVSS 9.8 and a recommended library bump. Looks clear. Except: is this service actually internet-facing, or is i00
NKNivethitha Kumaraveluinnebulablogs.com·Aug 26 · 13 min readFrom Finding Bugs to Fixing Them: How Far Has AI Vulnerability Remediation Come?By August 2026, frontier labs (Google DeepMind, OpenAI, Anthropic) and AppSec startups have all shipped some version of autonomous vulnerability remediation, and every one of them stops at the same ga10
NKNivethitha Kumaraveluinnebulablogs.com·Aug 25 · 16 min readSecurity Reviews of Enterprise AI Systems in 2026When I look at design docs for RAG and MCP systems, the security section is usually the same few lines. Retrieval so the model doesn't hallucinate. Tools so it can act. A prompt-injection classifier o10