Security Resources for
the AI Agent Era
Practical, opinionated playbooks and frameworks for security engineers shipping autonomous systems. No theory padding. No vendor pitches.

Securing Autonomous AI
Patterns for Controlling Agents, Models & Tools
16 chapters of battle-tested defensive patterns — from threat modeling to incident response, including supply-chain attacks on third-party skills and memory poisoning. Includes a 90-day hardening plan, security checklist, and threat model template.
For: Security engineers, DevSecOps, SREs, AI/ML engineers deploying agents in production.

AI Agent Defense Kit
Production-Ready IR Playbooks, Templates & Compliance Mapping
20 actionable files: 12 incident response playbooks for AI agent failures, threat model templates, SOC 2 & ISO 27001 compliance mapping, security posture scoring rubric, and implementation guide with architecture decisions.
For: Security teams deploying AI agents who need ready-to-use frameworks, not just theory.
Includes: 12 IR playbooks · 3 templates · Compliance mapping · Scoring rubric · Implementation guide
Detection Engineering Starter Kit
Free — 3 Production-Ready Detection Templates + AI Triage Prompts
A free starter kit for security engineers: 3 production-tested detection templates (AWS CloudTrail, authentication anomalies, supply chain), AI triage prompts for Claude and GPT, and a detection-as-code workflow with a GitHub Actions template.
For: Anyone starting with detection-as-code who wants high-signal rules they can deploy today.
What's Inside the Book
- The Gap
- Threat Modeling Autonomous Systems
- Principles That Don't Expire
- Your Agent Leaked Credentials
- An Untrusted Input Hijacked Your Agent
- Your Agent Made 47 API Calls Nobody Approved
- The Intern Shipped an Agent with Admin Access
- The Skill You Installed Was Working for Someone Else
- Something Went Wrong and Nobody Knows What
- The Alert That Cried Wolf
- Someone Tampered With Your Guardrails
- The Agent Believed a Lie It Was Told Last Week
- When Agents Spawn Agents
- Monitoring What You Can't Predict
- Incident Response — Agent Edition
- Your 90-Day Hardening Plan
Plus: Security Checklist + Threat Model Template
About the Author
Javier Morales is a Staff Security Engineer focused on detection engineering and AI-driven security operations. He spends his days figuring out how autonomous agents can be compromised — and building the systems that stop them.