NKNivethitha Kumaraveluinnebulablogs.com·7h ago · 16 min readSecurity Reviews of Enterprise AI Systems in 2026When I look at design docs for RAG and MCP systems, the security section is usually the same few lines. Retrieval so the model doesn't hallucinate. Tools so it can act. A prompt-injection classifier o00
NKNivethitha Kumaraveluinnebulablogs.com·Aug 16 · 12 min readHow Frontier Model Agents Accidentally Do Offensive SecurityI spent an evening going through OpenAI's Black Hat USA 2026 session, The 'Breaking' News: The OpenAI-Hugging Face Incident, and the follow-up writeups that filled in the timeline. The short version s21J
NKNivethitha Kumaraveluinnebulablogs.com·May 23 · 5 min readAdapting Matt Pocock's grill-with-docs skill to create a Threat Modeling skillI was working on a new app and came across Matt Pocock's /grill-with-docs skill that works as a structured interrogation tool that stress-tests your plan against your project's domain model, cross-ref00
NKNivethitha Kumaraveluinnebulablogs.com·May 19 · 33 min readOne MCP Server Over Six Scanners: Security Posture as a Queryable API"Why do I have to open five tabs to find out what's on fire?" -- every engineer, every Monday morning Modern engineering orgs run a small zoo of security scanners. A dependency scanner watches your s85AU
NKNivethitha Kumaraveluinnebulablogs.com·May 19 · 12 min readPipeline Security and Supply Chain Risk: Closing the Gap Between AppSec and CloudSecWorking in cloud security, I spend a lot of time thinking about the seams between systems: the places where one team's security coverage ends and another's begins. The gap I keep coming back to is CI/00