Writing
- note CVEAgentNet and the Next Control Plane for Vulnerability Management
A short note on agentic vulnerability collaboration, continuous assurance, and why the next frontier is connecting enriched security intelligence to bounded action and verification.
- paper Agent Control Plane Reference Architecture (ACP-RA)
A reference architecture for governed, scalable agentic autonomy—single agents and swarms—aligned to DoD CIO patterns (Zero Trust, ICAM, CNAP, DevSecOps, cATO) and designed for contested/degraded operations.
- note Notes: Research that shaped ACP-RA (agent security, tool use, evaluation)
Reading notes on prompt injection, tool-use at scale, and execution-based evaluation that drove ACP-RA design choices (gateways, envelopes, evidence, anti-replay, and upgrade discipline).
- paper From PDFs to Pull Requests
Code-as-Policy: transforming Department of Defense policy workflows with DevSecOps, version control, and continuous verification.