Secure Steps · field notes by Daniel Begimher
Field notes from the frontier of AI security.
An engineer building, breaking, and evaluating AI security systems — writing the practical version in public. Agents, prompt injection, RAG, evaluation, and developer-first tooling.
Four paths in
Clear routes for first-time visitors — no empty archives, no guessing.
AI Security
Agent evaluation, prompt injection, RAG security, GenAI threat modeling, and AI Leak Watch.
Cloud & AppSec
Secure SDLC, AWS security, CI/CD, container security, and AppSec programs.
Tools & Research
ASH, AI Leak Watch, SIR-Bench, ThreatForest, publications, and talks gathered into one index.
Career Guidance
Beginner-friendly security career advice grounded in real proof of work.
Built & measured
Public-safe work across AI security, open source, and applied research.
Automated Security Helper
One CLI command runs SAST, SCA, IaC, secret, and SBOM scanners — nine open-source tools across your code, dependencies, containers, and infrastructure, in local dev or CI/CD.
200k+ monthly clones · 650+ GitHub stars
SIR-Bench
An open benchmark that tests whether an AI incident-response agent actually investigates — finding new evidence and using tools — instead of just rephrasing the alert. Published on arXiv.
ThreatForest
A multi-agent system that turns source repositories into TTP-mapped attack trees and evidence-based mitigations across adversary frameworks. Published on arXiv and selected for a Black Hat USA 2026 briefing.
AI Leak Watch
Public dashboard tracking potentially exposed AI provider keys and AI-era secret leakage risk.
Latest writing
Balancing speed and safety: A control framework for AI coding agents
A tool-agnostic AppSec framework that pairs author-time guardrails with build-time verification and risk-based human review.
It’s 2025. Why Are We Still Pushing API Keys to GitHub?
Why hardcoded AI keys keep leaking, why agents widen the blast radius, and how teams should respond.
Subscribe
Get the next practical security lesson.
For builders and security teams working through AI security, cloud security, AppSec, open-source tooling, and career growth.
// no employer endorsement implied — opinions are my own