llm
Safeguard articles tagged "llm" — guides, analysis, and best practices for software supply chain and application security.
25 articles
A LinkedIn Post Questioned Anthropic's Claude OSS Scanner License. Here Is What It Grants
Anthropic's opt-in OSS Scanner, built on its experience using Claude to find vulnerabilities, asks contributors to sign a contributor license agreement. What that agreement grants Anthropic, what it does not say, and ten questions to ask any AI vendor before you send code.
Authorization Belongs in the Tool, Not in the Prompt
Your support chatbot can now issue refunds and look up orders, because someone connected it to real tools. Every one of those actions sits behind a customer-facing text box, protected however carefully the prompt was worded.
A Poisoned Memory Outlives the Conversation That Created It
Prompt injection in a single turn affects one response, then the next request starts clean. A persistent memory feature breaks that boundary by design, so a single successful injection becomes durable, recalled and trusted in every future session.
LLM-assisted vulnerability autofixing: approaches and how to validate the patches
At DARPA's AIxCC finals in August 2025, AI systems patched 68% of vulnerabilities they found — up from 25% at semifinals. Here's how the approaches differ and why validation still matters most.
AI Code Review Tools Compared: An Honest 2026 Guide
A balanced 2026 comparison of AI code review tools — GitHub Copilot, CodeRabbit, Qodo, Graphite, Amazon Q, Snyk DeepCode — with honest tradeoffs, the security gap, and where Safeguard fits.
OpenRouter API Security: Using the Unified LLM Gateway Safely
The OpenRouter API routes your prompts through one endpoint to many model providers. Convenient, but it changes where your data goes and where your keys live.
Claude Code Skills: A Security Guide to SKILL.md and Agent Extensions
Claude Code skills package instructions and scripts an AI agent runs on your behalf. That power is also the risk. Here is how to vet and sandbox them.
What Is Prompt Engineering? A Security Guide for LLM Applications
Prompt engineering is how you steer an LLM, and it is also where a lot of application security now lives. Here is how to write prompts that resist injection and leakage.
OWASP LLM Top 10 2025: System Prompt Leakage and Vector Weaknesses
The OWASP Top 10 for LLM Applications 2025 added System Prompt Leakage and Vector/Embedding Weaknesses, and elevated Sensitive Information Disclosure to #2. Here is the defender view.
MCP Meaning: What the Model Context Protocol Is and Why It Matters
The MCP meaning most people are asking about is the Model Context Protocol, an open standard that lets AI models connect to tools and data through one common interface.
Prompt Injection in RAG: Indirect Attacks
A senior engineer's breakdown of indirect prompt injection in RAG pipelines, how real attacks land through retrieved content, and what actually reduces exposure.
How to Use AI for Stock Trading (and the Risks Nobody Mentions)
Using AI for stock trading means applying models to signals, screening, and execution, but the security and reliability risks are as important as the strategy. Here is a grounded look.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.