Skip to content
Shengxing Zhang
ProjectsWritingAbout
中文

Writing

Engineering notes

Long-form notes from building and testing security boundaries for AI agents.

AGENTGUARD · DESIGN & THREAT MODEL · 5 MIN READ

Why I put a proxy between my AI agent and my server

Why the enforcement point sits between an AI agent and an MCP server, and which failure modes require separate controls.

AGENTGUARD · IMPLEMENTATION & TRADEOFFS · 5 MIN READ

Rule-based prompt-injection detection: what it catches, what it costs

Why a detected injection blocks the whole result, why v1 uses deterministic rules, and what the tests found.

© 2026 Shengxing Zhang

Interests GitHub Email