5,660 AI security links: prompt injection, LLM & AI agent security, MCP, coding agents, agent skills & supply chain, red teaming, guardrails, sandboxing, incidents & CVEs, governance. 570 arXiv papers, 1,155 GitHub repos, 570 X posts, 29 categories of plain markdown you can grep, diff and fork. Obsidian vault export. Added, not endorsed.
See the code
5,660 links on AI security: prompt injection, LLM and AI agent security, MCP, coding agents, agent skills and supply chain, red teaming, guardrails, sandboxing, incidents and CVEs, governance.
One person's reading list that got out of hand. No gatekeeping: if it is even remotely about AI and/or security, it goes in. Added, not endorsed.
Browse the site · Foundations · Attacks · Defense · Agents · Coding · Research · Practice · General · Stats · Maintenance
5,660links | 29categories | 108sections | 570arXiv papers | 1,155GitHub repos | 570posts on X |
| Section | Category | Links |
|---|---|---|
| Security News and Research | General Reading | 748 |
| AI Industry and Ecosystem | General Reading | 613 |
| Tools | Red Teaming | 340 |
| Resources | Supply Chain | 315 |
| Coding Tools and Assistants | Coding Tools | 206 |
2026-09-04 @office-agents/sdk - headless agent runtime SDK for AI-powered Office Add-ins2026-09-04 Agent Development Kit - ADK - build multi-agent systems2026-09-04 agent-browser - browser automation CLI for AI agents2026-09-04 agents-cli - build AI agents on Google Cloud2026-09-04 ANUS - Autonomous Networked Utility System open-source AI agent framework2026-09-04 Azure Functions serverless agents runtime2026-09-04 Centaur - self-hosted control plane for sandboxed, credential-safe AI agents in Slack2026-09-04 CLI-Anything - making all software agent-nativemindmap
root((AI Security Corpus · 5,660 links))
Foundations · 297
Frameworks and Standards · 95
Governance and Policy · 138
Threat Modeling · 48
Architecture · 16
Attacks · 612
Prompt Injection · 117
Jailbreaking · 26
Model Attacks · 34
Supply Chain · 315
Incidents · 120
Defense · 580
Guardrails and Firewalls · 37
Sandboxing and Isolation · 71
Detection and Monitoring · 330
Secrets Management · 95
Honeypots and Deception · 29
Anti-Crawling · 18
Agents · 751
Agent Security · 119
Agent Identity · 126
MCP - Model Context Protocol · 304
Agent Frameworks · 202
Coding · 455
Secure Coding · 40
Code Analysis · 186
Coding Tools · 229
Research · 515
Papers · 402
Benchmarks · 60
Safety and Alignment · 53
Practice · 624
Red Teaming · 524
Engineering Patterns · 48
Privacy · 52
General · 1,833
General Reading · 1,833
297 links across 4 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Frameworks and Standards | 95 | 4 | Risk frameworks, standards, and foundational security references |
| Governance and Policy | 138 | 6 | Compliance, AI policy, legal, and trust |
| Threat Modeling | 48 | 4 | Threat modeling frameworks, tools, and methodologies |
| Architecture | 16 | 2 | Secure AI design patterns and principles |
612 links across 5 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Prompt Injection | 117 | 7 | Taxonomy, techniques, datasets, and defenses |
| Jailbreaking | 26 | 1 | Jailbreaking techniques and research |
| Model Attacks | 34 | 5 | Poisoning, backdoors, extraction, and adversarial ML |
| Supply Chain | 315 | 1 | Dependency attacks, model integrity, and signing |
| Incidents | 120 | 5 | Real-world breaches, exploits, and case studies |
580 links across 6 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Guardrails and Firewalls | 37 | 3 | Guardrails, firewalls, and runtime protection |
| Sandboxing and Isolation | 71 | 3 | Runtime containment and code execution security |
| Detection and Monitoring | 330 | 4 | Vulnerability scanners and threat detection |
| Secrets Management | 95 | 3 | Protecting secrets from AI agents |
| Honeypots and Deception | 29 | 2 | Honeypots and adversary engagement |
| Anti-Crawling | 18 | 3 | Tarpits, cloaking, data poisoning, and crawler access control |
751 links across 4 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Agent Security | 119 | 2 | Agent-specific security concerns and threats |
| Agent Identity | 126 | 1 | OAuth, NHI, authentication, and authorization |
| MCP (Model Context Protocol) | 304 | 12 | Gateways, scanners, research, and tooling |
| Agent Frameworks | 202 | 5 | General agent frameworks, platforms, and tools |
455 links across 3 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Secure Coding | 40 | 3 | Rules files, vibe coding security, and secure prompt engineering |
| Code Analysis | 186 | 3 | SAST, code review, and vulnerability scanning |
| Coding Tools | 229 | 2 | IDE integrations, copilots, and assistants |
515 links across 3 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Papers | 402 | 8 | Academic papers and surveys |
| Benchmarks | 60 | 3 | Evaluation frameworks and datasets |
| Safety and Alignment | 53 | 2 | AI safety, alignment, and privacy |
624 links across 3 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Red Teaming | 524 | 3 | Offensive AI security, tools, and methodologies |
| Engineering Patterns | 48 | 2 | Harness engineering and building patterns |
| Privacy | 52 | 4 | Data leakage, PII protection, and exfiltration |
1,833 links across 1 category
| Category | Links | Sections | What's inside |
|---|---|---|---|
| General Reading | 1,833 | 5 | Blog posts, talks, opinion, commentary, and security news |
Every category is a plain markdown file of - [Title](url) lines under ## sections, so the whole thing greps, diffs, and forks cleanly.
| What | How |
|---|---|
| Add links | /add-resource <url> [url2] ... — an agent command that fetches titles, classifies each link into the right file and section, and commits. The rules live in agents.md, so any coding agent that reads it can do the same |
| Search | /search-resources <query> — grep across every category file |
| Obsidian vault | python3 scripts/sync-vault.py regenerates vault/ with one note per category, wiki-linked and tagged |
| Website | python3 scripts/build-site.py renders every category to a static page at anthonyherman.github.io/ai-security-corpus with client-side search (deployed by CI on every push) |
| Stats and charts | python3 scripts/stats.py recounts the corpus, redraws the SVGs in assets/, and rewrites the numbers above (also runs in CI on every push) |
Links are added, not endorsed. Some of them are wrong, some are marketing, some are exploits. That is the corpus.
Licensed CC BY 4.0: fork it, grep it, republish it, just link back.
Python
60.8%
CSS
28.3%
JavaScript
10.9%
5,660 AI security links: prompt injection, LLM & AI agent security, MCP, coding agents, agent skills & supply chain, red teaming, guardrails, sandboxing, incidents & CVEs, governance. 570 arXiv papers, 1,155 GitHub repos, 570 X posts, 29 categories of plain markdown you can grep, diff and fork. Obsidian vault export. Added, not endorsed.
See the code
5,660 links on AI security: prompt injection, LLM and AI agent security, MCP, coding agents, agent skills and supply chain, red teaming, guardrails, sandboxing, incidents and CVEs, governance.
One person's reading list that got out of hand. No gatekeeping: if it is even remotely about AI and/or security, it goes in. Added, not endorsed.
Browse the site · Foundations · Attacks · Defense · Agents · Coding · Research · Practice · General · Stats · Maintenance
5,660links | 29categories | 108sections | 570arXiv papers | 1,155GitHub repos | 570posts on X |
| Section | Category | Links |
|---|---|---|
| Security News and Research | General Reading | 748 |
| AI Industry and Ecosystem | General Reading | 613 |
| Tools | Red Teaming | 340 |
| Resources | Supply Chain | 315 |
| Coding Tools and Assistants | Coding Tools | 206 |
2026-09-04 @office-agents/sdk - headless agent runtime SDK for AI-powered Office Add-ins2026-09-04 Agent Development Kit - ADK - build multi-agent systems2026-09-04 agent-browser - browser automation CLI for AI agents2026-09-04 agents-cli - build AI agents on Google Cloud2026-09-04 ANUS - Autonomous Networked Utility System open-source AI agent framework2026-09-04 Azure Functions serverless agents runtime2026-09-04 Centaur - self-hosted control plane for sandboxed, credential-safe AI agents in Slack2026-09-04 CLI-Anything - making all software agent-nativemindmap
root((AI Security Corpus · 5,660 links))
Foundations · 297
Frameworks and Standards · 95
Governance and Policy · 138
Threat Modeling · 48
Architecture · 16
Attacks · 612
Prompt Injection · 117
Jailbreaking · 26
Model Attacks · 34
Supply Chain · 315
Incidents · 120
Defense · 580
Guardrails and Firewalls · 37
Sandboxing and Isolation · 71
Detection and Monitoring · 330
Secrets Management · 95
Honeypots and Deception · 29
Anti-Crawling · 18
Agents · 751
Agent Security · 119
Agent Identity · 126
MCP - Model Context Protocol · 304
Agent Frameworks · 202
Coding · 455
Secure Coding · 40
Code Analysis · 186
Coding Tools · 229
Research · 515
Papers · 402
Benchmarks · 60
Safety and Alignment · 53
Practice · 624
Red Teaming · 524
Engineering Patterns · 48
Privacy · 52
General · 1,833
General Reading · 1,833
297 links across 4 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Frameworks and Standards | 95 | 4 | Risk frameworks, standards, and foundational security references |
| Governance and Policy | 138 | 6 | Compliance, AI policy, legal, and trust |
| Threat Modeling | 48 | 4 | Threat modeling frameworks, tools, and methodologies |
| Architecture | 16 | 2 | Secure AI design patterns and principles |
612 links across 5 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Prompt Injection | 117 | 7 | Taxonomy, techniques, datasets, and defenses |
| Jailbreaking | 26 | 1 | Jailbreaking techniques and research |
| Model Attacks | 34 | 5 | Poisoning, backdoors, extraction, and adversarial ML |
| Supply Chain | 315 | 1 | Dependency attacks, model integrity, and signing |
| Incidents | 120 | 5 | Real-world breaches, exploits, and case studies |
580 links across 6 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Guardrails and Firewalls | 37 | 3 | Guardrails, firewalls, and runtime protection |
| Sandboxing and Isolation | 71 | 3 | Runtime containment and code execution security |
| Detection and Monitoring | 330 | 4 | Vulnerability scanners and threat detection |
| Secrets Management | 95 | 3 | Protecting secrets from AI agents |
| Honeypots and Deception | 29 | 2 | Honeypots and adversary engagement |
| Anti-Crawling | 18 | 3 | Tarpits, cloaking, data poisoning, and crawler access control |
751 links across 4 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Agent Security | 119 | 2 | Agent-specific security concerns and threats |
| Agent Identity | 126 | 1 | OAuth, NHI, authentication, and authorization |
| MCP (Model Context Protocol) | 304 | 12 | Gateways, scanners, research, and tooling |
| Agent Frameworks | 202 | 5 | General agent frameworks, platforms, and tools |
455 links across 3 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Secure Coding | 40 | 3 | Rules files, vibe coding security, and secure prompt engineering |
| Code Analysis | 186 | 3 | SAST, code review, and vulnerability scanning |
| Coding Tools | 229 | 2 | IDE integrations, copilots, and assistants |
515 links across 3 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Papers | 402 | 8 | Academic papers and surveys |
| Benchmarks | 60 | 3 | Evaluation frameworks and datasets |
| Safety and Alignment | 53 | 2 | AI safety, alignment, and privacy |
624 links across 3 categories
| Category | Links | Sections | What's inside |
|---|---|---|---|
| Red Teaming | 524 | 3 | Offensive AI security, tools, and methodologies |
| Engineering Patterns | 48 | 2 | Harness engineering and building patterns |
| Privacy | 52 | 4 | Data leakage, PII protection, and exfiltration |
1,833 links across 1 category
| Category | Links | Sections | What's inside |
|---|---|---|---|
| General Reading | 1,833 | 5 | Blog posts, talks, opinion, commentary, and security news |
Every category is a plain markdown file of - [Title](url) lines under ## sections, so the whole thing greps, diffs, and forks cleanly.
| What | How |
|---|---|
| Add links | /add-resource <url> [url2] ... — an agent command that fetches titles, classifies each link into the right file and section, and commits. The rules live in agents.md, so any coding agent that reads it can do the same |
| Search | /search-resources <query> — grep across every category file |
| Obsidian vault | python3 scripts/sync-vault.py regenerates vault/ with one note per category, wiki-linked and tagged |
| Website | python3 scripts/build-site.py renders every category to a static page at anthonyherman.github.io/ai-security-corpus with client-side search (deployed by CI on every push) |
| Stats and charts | python3 scripts/stats.py recounts the corpus, redraws the SVGs in assets/, and rewrites the numbers above (also runs in CI on every push) |
Links are added, not endorsed. Some of them are wrong, some are marketing, some are exploits. That is the corpus.
Licensed CC BY 4.0: fork it, grep it, republish it, just link back.
Python
60.8%
CSS
28.3%
JavaScript
10.9%