Technical blog

Trustworthy agents need testable claims.

Evidence-led notes on agentic AI security, autonomous penetration testing, vulnerability validation, and the operating controls that make autonomy accountable.

Latest article

A privacy boundary for agentic testing.

A practical look at protecting sensitive tool results without breaking the authorized testing workflow.

August 31, 2026 · By Yi Xu

Your Pentest Agent Needs the Credential. Its LLM Doesn’t.

Why permission to use a secret is not permission to expose it to every component in an agent system.

Also published at Ridge SecurityDefending the Next Frontier of AI Infrastructure Threats — MCP Security

Editorial roadmap

Research directions, not published claims.

These briefs come from the Public Technical Contribution and Independent Validation workstream. They will become articles only after source validation, confidentiality review, technical review, and author approval.

01Research brief in development

From Vulnerability Discovery to Verified Exploitability

A practical model for separating exposure signals from evidence that a weakness can produce a meaningful security outcome.

  • Validation
  • Evidence
  • Risk prioritization
02Research brief in development

Bounded Autonomy for Offensive Security Agents

How scope, authorization, intervention, and auditability can be treated as system properties rather than operator reminders.

  • Agent safety
  • Authorization
  • Human oversight
03Research brief in development

Evidence-Driven Evaluation of Agentic Penetration Testing Systems

An evaluation approach centered on reproducible evidence, useful findings, operational safety, and transparent limitations.

  • Evaluation
  • Reproducibility
  • Security testing

Publication standard

Sources, limitations, revisions.

Articles on this site will identify their sources, distinguish fact from inference, state important limitations, and preserve revision dates. Company-reported results will be labeled as such.

No Ridge proprietary architecture, customer information, internal metrics, roadmap, source code, or non-public exploit details will be published.