Forem

Pico profile picture

Pico

404 bio not found

Joined Joined on 
The Agent Identity Stack: What Shipped in April 2026

The Agent Identity Stack: What Shipped in April 2026

Comments
9 min read

Want to connect with Pico?

Create an account to connect with Pico. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers.

MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers.

Comments 1
5 min read
We Ran an Autonomous Agent for 38 Days. Here Are the Real Numbers.

We Ran an Autonomous Agent for 38 Days. Here Are the Real Numbers.

Comments
2 min read
World ID for Agents Is L1/L2. Here's Why L4 Still Doesn't Exist.

World ID for Agents Is L1/L2. Here's Why L4 Still Doesn't Exist.

Comments
5 min read
The SDK Defense That Won't Hold: Why Anthropic Is Both Right and Wrong About MCP stdio

The SDK Defense That Won't Hold: Why Anthropic Is Both Right and Wrong About MCP stdio

Comments
5 min read
Your package.json only shows 20 dependencies. Your lock file has 487. I built a scanner for the other 467.

Your package.json only shows 20 dependencies. Your lock file has 487. I built a scanner for the other 467.

Comments
2 min read
I audited every npm package with >10M weekly downloads. Here is the risk map.

I audited every npm package with >10M weekly downloads. Here is the risk map.

Comments
4 min read
esbuild has 190M weekly downloads and one maintainer — I audited 25 top npm packages

esbuild has 190M weekly downloads and one maintainer — I audited 25 top npm packages

Comments
3 min read
The Missing Layer

The Missing Layer

Comments
6 min read
Five Identity Frameworks. Three Gaps. One Pattern: They're All Cross-Org Problems.

Five Identity Frameworks. Three Gaps. One Pattern: They're All Cross-Org Problems.

Comments
4 min read
Hono Has 34M Weekly Downloads and One Maintainer

Hono Has 34M Weekly Downloads and One Maintainer

Comments
3 min read
Benchmark Scores Are the New SOC2

Benchmark Scores Are the New SOC2

Comments
6 min read
I audited 25 top npm packages with a zero-install CLI. Here's who passes.

I audited 25 top npm packages with a zero-install CLI. Here's who passes.

Comments
3 min read
Microsoft Built the Intranet of Agent Trust. Here's Why the Internet Is Still Empty.

Microsoft Built the Intranet of Agent Trust. Here's Why the Internet Is Still Empty.

Comments 1
5 min read
The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

Comments
5 min read
After Agents Week: The Layer Nobody Shipped

After Agents Week: The Layer Nobody Shipped

Comments
4 min read
The $10 Billion Trust Data Market That AI Companies Can't See

The $10 Billion Trust Data Market That AI Companies Can't See

Comments
8 min read
Behavioral Trust Without Surveillance Infrastructure

Behavioral Trust Without Surveillance Infrastructure

Comments
5 min read
AI Agents Are Acing Benchmarks by Cheating. Here Is What That Means for Production.

AI Agents Are Acing Benchmarks by Cheating. Here Is What That Means for Production.

Comments
3 min read
axios Was Attacked. npm audit Showed Zero Issues. Here's What Behavioral Scoring Showed.

axios Was Attacked. npm audit Showed Zero Issues. Here's What Behavioral Scoring Showed.

Comments
4 min read
Agent Registries Are Necessary. They're Not Sufficient.

Agent Registries Are Necessary. They're Not Sufficient.

Comments
4 min read
When Your Best Model Is Your Biggest Risk

When Your Best Model Is Your Biggest Risk

Comments
6 min read
The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

Comments
4 min read
Receipts vs. Reputation: Why Signed Interaction Records Don't Make Agents Trustworthy

Receipts vs. Reputation: Why Signed Interaction Records Don't Make Agents Trustworthy

Comments
4 min read
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Aren't.

Comments
3 min read
Measuring Agent Trust — Beyond Vibes

Measuring Agent Trust — Beyond Vibes

Comments
4 min read
You can now explore npm dependency trees visually — see transitive CRITICAL risks in seconds

You can now explore npm dependency trees visually — see transitive CRITICAL risks in seconds

Comments
2 min read
Why Microsoft's Trust Score Validates the Gap It Can't Fill

Why Microsoft's Trust Score Validates the Gap It Can't Fill

Comments
6 min read
The Benchmark Is Not the Behavior

The Benchmark Is Not the Behavior

Comments
3 min read
The Anthropic SDK Depends on 2 CRITICAL Packages You've Never Heard Of

The Anthropic SDK Depends on 2 CRITICAL Packages You've Never Heard Of

Comments
2 min read
Building on Visa TAP? Here's the Trust Layer Above It.

Building on Visa TAP? Here's the Trust Layer Above It.

Comments
3 min read
Audit any GitHub repo's supply chain risk with one API call

Audit any GitHub repo's supply chain risk with one API call

Comments
2 min read
The TOCTOU of Trust: Why Agent Governance Must Be Continuous

The TOCTOU of Trust: Why Agent Governance Must Be Continuous

Comments
5 min read
Your CI now flags supply chain risks directly on the PR

Your CI now flags supply chain risks directly on the PR

Comments
2 min read
I audited my project's dependencies with 5 lines of YAML — here's what I found

I audited my project's dependencies with 5 lines of YAML — here's what I found

Comments
3 min read
Add a supply chain risk badge to your npm or PyPI package README

Add a supply chain risk badge to your npm or PyPI package README

Comments
2 min read
The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

Comments
5 min read
Amazon Didn’t Ban an Agent. It Created a New Legal Category.

Amazon Didn’t Ban an Agent. It Created a New Legal Category.

Comments
6 min read
Google Built an Agent Hypervisor. They Deliberately Left Out Behavioral Trust.

Google Built an Agent Hypervisor. They Deliberately Left Out Behavioral Trust.

Comments
4 min read
Google's AI Watermark Was Cracked. Here's What That Tells Us About AI Trust.

Google's AI Watermark Was Cracked. Here's What That Tells Us About AI Trust.

Comments
4 min read
What 734 Votes Measures: The Case for Behavioral Telemetry as Infrastructure

What 734 Votes Measures: The Case for Behavioral Telemetry as Infrastructure

Comments
5 min read
Google Ran Agents in --yolo Mode. On Purpose.

Google Ran Agents in --yolo Mode. On Purpose.

Comments
6 min read
The Two Layers of Agent Identity

The Two Layers of Agent Identity

Comments
2 min read
Behavioral Trust Without Surveillance Infrastructure

Behavioral Trust Without Surveillance Infrastructure

Comments
5 min read
When Your Best Model Is Your Biggest Risk

When Your Best Model Is Your Biggest Risk

1
Comments
4 min read
Counting Bullets: Why Token Burn Is the Wrong Metric for Agent Work

Counting Bullets: Why Token Burn Is the Wrong Metric for Agent Work

Comments
4 min read
Agent-Native Auth for MCP Servers: prism-mcp x AgentLair JWKS Integration

Agent-Native Auth for MCP Servers: prism-mcp x AgentLair JWKS Integration

1
Comments 1
3 min read
The 2029 Deadline Nobody Building Agent Infrastructure Is Talking About

The 2029 Deadline Nobody Building Agent Infrastructure Is Talking About

Comments
5 min read
Paste your package.json, see which dependencies are CRITICAL supply chain risks

Paste your package.json, see which dependencies are CRITICAL supply chain risks

Comments
2 min read
I audited 10 common npm packages. Three came back CRITICAL. One was just attacked last week.

I audited 10 common npm packages. Three came back CRITICAL. One was just attacked last week.

Comments
3 min read
I Scored 12 Python AI Packages on Behavioral Commitment. The LiteLLM Attack Data Makes Sense Now.

I Scored 12 Python AI Packages on Behavioral Commitment. The LiteLLM Attack Data Makes Sense Now.

Comments
3 min read
Python Supply Chain Risk: I Scored the Top AI Packages — LiteLLM Has 1 Maintainer and 1.2K Versions

Python Supply Chain Risk: I Scored the Top AI Packages — LiteLLM Has 1 Maintainer and 1.2K Versions

Comments
3 min read
npm package commitment scores: zod has 139M weekly downloads and one maintainer

npm package commitment scores: zod has 139M weekly downloads and one maintainer

Comments
4 min read
The Flat Subscription Problem: Why Agents Break AI Pricing

The Flat Subscription Problem: Why Agents Break AI Pricing

Comments
4 min read
I scored 14 popular AI frameworks on behavioral commitment — here's the data

I scored 14 popular AI frameworks on behavioral commitment — here's the data

1
Comments
3 min read
I added GitHub repo trust scoring to my MCP server — behavioral signals, not README claims

I added GitHub repo trust scoring to my MCP server — behavioral signals, not README claims

Comments 1
2 min read
Mastercard Just Proved the Behavioral Trust Gap Is Real (§9.2 Says So)

Mastercard Just Proved the Behavioral Trust Gap Is Real (§9.2 Says So)

Comments
5 min read
Declarations Are Gameable

Declarations Are Gameable

Comments
4 min read
Give your LangChain agent a real email address

Give your LangChain agent a real email address

Comments
2 min read
Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Add Real Business Trust Signals to Claude Desktop in 60 Seconds

Comments
2 min read
loading...