Cup'n'String
Join Waitlist

© 2026 Cup'n'String

Insights

Technical perspectives on AI agent security

Opinionated, practical writing for CISOs, security architects, platform engineering, and AI governance teams adopting AI coding agents, MCP, and local runtimes.

For Security Teams·8 min read
What Security Teams Need to Know About MCP ServersMCP servers are becoming the tool layer for AI agents. They need inventory, approval, policy, least privilege, and audit — the same disciplines security teams already apply to every other integration.
For Platform & Security Engineers·7 min read
From Shadow Docker Containers to Governed Developer ServicesContainers quietly expose databases, APIs, queues, and dashboards on developer machines. As AI agents learn to reach them, discovery and controlled exposure become essential security work.
For Security Architects·8 min read
AI Agent Egress Control: Why DNS and API Gateways Are Not EnoughDNS filtering and cloud API gateways are useful but incomplete for AI agents. Controlling where agents can send data requires local enforcement, attribution, and telemetry on the workstation itself.
For AI Governance Teams·7 min read
Securing Ollama and LM Studio in Enterprise Developer EnvironmentsLocal model servers are powerful and increasingly common — and almost always unmanaged. OpenAI-compatible local endpoints can bypass your standard controls. Here is how to bring them under governance.
For Platform & Security Engineers·7 min read
The Problem with Localhost in the AI Agent EraLocalhost used to be the developer's private sandbox. AI agents changed that. Local databases, APIs, dashboards, and containers are now reachable by autonomous tools — and almost nobody is governing them.
For Security Leaders·8 min read
How to Govern Cursor, Claude Code, Cline, and Copilot Without Blocking DevelopersBanning AI coding tools fails. The durable approach is role-based policy, credential shielding, approved model access, and audit — so developers keep their velocity and security keeps its visibility.
For Platform & Security Engineers·8 min read
Why AI Coding Agents Need Local Firewall EnforcementSaaS gateways cannot see everything that happens on a developer machine. As AI coding agents operate next to source code, secrets, and local services, policy has to be enforced closer to the endpoint.
For Security Teams·7 min read
MCP Is Becoming the New Shadow IT SurfaceThe Model Context Protocol turns developer workstations into integration hubs for AI agents. Without discovery, policy, and audit, MCP becomes the fastest-growing shadow IT surface in the enterprise.

Secure your AI coding workstations with Cup’n’String

Put the ideas in these articles into practice with discovery, policy, shielding, and audit.