Feeling overwhelmed by AI? Learn the Centaur Mindset. Read More →
Terminal output from agent-bom scan showing a security posture summary with 2 critical, 21 high, 20 medium, and 5 low findings, a posture grade of F, and a findings table naming a CVE in axios with a blast radius chain ending in a browser session token

The CVE List Isn't the Point: Mapping Blast Radius in AI Infrastructure with agent-bom

The Rabbit Hole Generator gave me agent-bom this week, and it landed on a question I’ve been circling for a while: what does a vulnerability scanner actually owe you once “AI agent” and “MCP server” show up in your stack next to the usual packages and containers? A traditional scanner tells you a package has a CVE. It stops there. It doesn’t know that package sits inside an MCP server (a small local process that gives an AI agent tools like “read this file” or “run this shell command”), and it definitely doesn’t know that server has an AWS_SECRET_ACCESS_KEY sitting in its environment. agent-bom is built specifically to answer the next question a CVE list never does: from this vulnerable package, what can actually be reached? ...

September 18, 2026 · 12 min · Scott Algatt
Terminal-style output from macaron analyze against Django 5.0.6, showing four failed provenance/build checks, one passed license check, a 17-check summary totaling 10 failures, and the report JSON showing is_inferred true with a Not Available justification

Beyond CVEs: Verifying Supply Chain Provenance with Macaron

The Rabbit Hole Generator gave me Macaron this week, Oracle’s open-source tool for checking software supply chain security. My first instinct was to file it next to every other dependency scanner I’ve used: point it at a package, get a list of CVEs back. That’s not what it does, and the gap between those two things turned out to be the actual point. A vulnerability scanner answers “does this package version have a known CVE.” Macaron answers a different question: “was this artifact actually built from the source code we think it was, by a process we can verify, with evidence that isn’t just the vendor’s word for it.” Those sound similar. They aren’t. A package can have zero known CVEs and still have no evidence at all connecting the file you pip installed to the GitHub repo everyone assumes it came from. ...

September 11, 2026 · 11 min · Scott Algatt
A visual representation of an intercepting proxy sitting between a client and a server, with traffic flows being inspected in a terminal-like view.

Intercepting Opaque Traffic: A mitmproxy Security Regression Harness

Most security monitoring tools rely on server-side logs or cloud-native telemetry. But what happens when the client is opaque? When a mobile app, a single-page application (SPA), or a proprietary service is behaving in ways the server doesn’t fully document, you need a way to look at the wire directly. This post also marks the beginning of a new experiment: The Rabbit Hole Series. Every Friday, a “Rabbit Hole Generator” I built (which I later took apart in its own post) spits out a new technical topic for me to explore for 30 minutes. This week, the generator gave me mitmproxy. ...

April 3, 2026 · 5 min · Scott Algatt
A developer tracing through error output in a terminal with AI suggestions alongside

Error Debugging with AI: Beyond Stack Overflow

This post continues “The Centaur’s Toolkit” series on practical human-AI collaboration in technical work. The error showed up in production on a Wednesday afternoon. sqlalchemy.exc.OperationalError: (psycopg2.OperationalError) SSL SYSCALL error: EOF detected I knew this error. Or thought I did. Stack Overflow had dozens of answers: upgrade psycopg2, check your SSL certificates, adjust your connection timeout. I’d even hit this error two years earlier on a different project, and the fix had been a connection pool configuration change. ...

February 27, 2026 · 10 min · Scott Algatt
Terminal windows showing code running on different operating systems

Cross-Platform Scripting Tips and Tricks

Note: This guide combines personal experience from writing deployment scripts across macOS, Linux, and Windows environments with patterns documented in the Python pathlib documentation, Git documentation, PowerShell cross-platform guidance, Python subprocess module, and GitHub Actions runner images. A deployment script that works on macOS. A colleague runs it on Windows. It fails immediately. The culprit? A hardcoded forward slash in a file path. I’ve seen this exact scenario play out multiple times over the past five years, and it’s almost always preventable. ...

January 30, 2026 · 8 min · Scott Algatt