Articles
- MCP Tool Poisoning: from code execution to bypassing the agent's permissions
How a malicious MCP server chains install scripts, stdio privilege inheritance, settings tampering and persistence, and which mitigations actually hold.
The thesis
Probabilistic autonomy for thinking. Deterministic governance for acting.
AI systems can hold autonomy inside their own loops. Interactions between loops, and any action with an external effect, must respect the policies, rules and deterministic gates the organisation defines.
What I created
- AISAC
- The system that creates and operates AI systems: intent turned into governed, versioned and continuously operable systems.
- Governed Agentic Workloop
- Two or more autonomous agentic loops interacting through explicit channels under a common authority, with deterministic gates on every interaction and every action with an external effect. Formalised in the Workloop Spec, CC BY 4.0, DOI 10.5281/zenodo.22004648.
- AI Brain
- A persistent memory layer shared across AIs through MCP, keeping knowledge and context available across sessions, agents and clients.
- B2Tech
- The software house I founded: products, MCP servers, trainings and client projects, with security and CI/CD from the first commit.
Credentials
- Claude Certified Architect, Professional (CCAR-P) verify on Credly
- Claude Certified Architect, Foundations (CCAR-F) verify on Credly
- Claude Certified Developer, Foundations (CCDV-F) verify on Credly
- Anthropic Partner Network
- Meta Tech Provider
- Google for Startups
- Postgraduate student at PUC in Software Architecture, Data Science and Cybersecurity, completing 12/2026