Llm

Rethinking MCP or Tool Calling Through Permission Based System
Explore a permission-based security model for MCP and Tool Calling in LLMs, inspired by Android's runtime permissions, to protect sensitive data while maintaining functionality.
Static Analysis Isn't Enough: Understanding Library Interactions for Effective Data Flow Tracking
Static analysis tools go blind without understanding library calls – learn why modeling them is critical for finding real security flaws.
Lessons from Building Sherlock: Automating Security Code Reviews with Sourcegraph
Explore how Sherlock leverages Sourcegraph to automate security code reviews, enhancing productivity and ensuring robust code security.
LLM-Powered Security Reviews: Insights and Challenges
Exploring the potential and challenges of LLM-assisted security reviews
How I Use AI to Streamline/Assist My Work
A short blog post on how I leverage LLMs (AI) to streamline or assist my work