AAPT Research

Field notes on AI agent security

MCP servers, GraphQL agents, multi-turn manipulation — the surfaces everyone now claims to cover, what that coverage actually amounts to, and what it takes to really pen-test the agents you ship.

CommentaryJuly 21, 2026 · 6 min

Trust is the bottleneck for enterprise AI. Here's what earning it would actually look like.

GoTo's CTO says the hard part is no longer the technology — it's trust. But trust in security is a measurement, not a posture. What earning it concretely requires for AI agents, and the published OWASP buyer standard you can hold every vendor to.

Read the post →
Security ResearchJuly 16, 2026 · 6 min

Your AI agent has attack surfaces you're not testing

Prompt injection is the one everybody knows about — and the best covered. The surfaces that will actually get you breached are MCP servers, GraphQL-fronted agents, and multi-turn manipulation. Vendors have started claiming all three; here's the full map, concrete examples of each, and an honest read on what that coverage is really worth.

Read the post →