Everything here is free
Free Resources
Everything here is free. No email gate, no upsell. Just stuff I built that might help you.
Last updated: April 11, 2026
Security Series
An ongoing series on AI security, local deployment, and enterprise reality. Start here.
Want the full MCP arc in one place? The MCP Security Hub has every episode, the defense framework, and free governance templates.
View the MCP Security HubThe Week Anthropic Leaked. The Internet Met an Owl.
Two incidents in one week. Anthropic's system prompt leaked. Then the source code. The internet met Zornix. Here's what operators actually need to know.
The Blueprints Are Public Now.
Anthropic fought the Pentagon in court to protect its architecture. Days later, a missing .npmignore line published the entire blueprint to NPM. The fortress fell to a config file.
Anthropic Did It Again.
A missing .npmignore line exposed 512,000 lines of Claude Code source. An intern found it. Then axios got hijacked. One config file, two incidents, zero excuses.
Anthropic Didn't Get Hacked. It Still Had a Security Problem.
A CMS misconfiguration exposed roughly 3,000 unpublished assets. One described a model nobody was supposed to see yet. That was enough.
MCP 201: The Governance Deficit
Shadow IT at scale. Audit trails that don't exist. Seven governance frameworks launched in sixty days.
Your Policy Isn't Ready: Everything Anthropic Shipped in March 2026
Anthropic shipped Claude 3.7, Claude Code, and an updated usage policy in the same month. Your governance docs didn't keep up. Here's the gap.
How I Turned a Gaming PC Into a Sovereign AI Server
The Nuclear Option. Why local AI on gaming hardware beats cloud for sensitive work.
Read on Substack EP.2Fear is Fake: Why You're Still Not Running Local AI
I waited 14 days to do a 20-minute task. Here's what I learned about overthinking the setup.
Read on Substack EP.3The Fifth Party Problem: Who Pays When AI Agents Go Rogue?
AI agents are making decisions in your name. The liability chain is longer than anyone admits.
Read on Substack EP.4Your Local AI Agent Is a Security Risk
Local does not mean safe. The Lethal Trifecta that makes local agents a problem nobody is talking about.
Read on Substack EP.5The Clean Room Method
Five steps to stop AI tools from leaking your information. Practical and repeatable.
Read on Substack EP.6Your Boss Just Saw What Goldman Did With AI. Here's What Happens Next.
Goldman automated back-office work with Claude. Your leadership team saw the headline. Here is what actually happened.
Read on Substack EP.7MCP 101: I Read the Documentation So You Don't Have To
Everyone is talking about MCP. Almost nobody has read the actual spec. I did. Here is what it says.
Read on Substack EP.8MCP 102: Claude Already Knows
MCP 101 was the spec. MCP 102 is the behavior. What actually happens when you flip the switch.
Read on Substack EP.9Your AI Vendor Just Became a Defense Contractor. Now What?
Anthropic refused five words in a Pentagon contract and got designated a supply chain risk. What that means for your enterprise stack.
Read on Substack EP.10Your AI Vendor Just Became a Defense Contractor
Anthropic refused five words in a Pentagon contract. Got treated like Huawei. OpenAI signed hours later. This is what it means when your AI vendor picks a side.
Read on Substack EP.11MCP 103: I Gave Claude Code Someone Else's Tools
Community MCP servers work perfectly. Claude chained three of them without being asked. Nobody approved any of it. That's the problem.
Read on SubstackStandalone Episodes
One-off deep dives that don't fit a series. Worth reading anyway.
Gaming x AI
What persistent AI memory in games tells us about AI memory everywhere else.
Prompt Packs
Copy-paste ready. Tested in real workflows.
Free Tools
Things I built that you can use right now.
Deep Dives
Long reads on what's actually happening under the hood.
The Plumbing Behind the Hype: Visa's AI Agents
What actually happens when AI agents interact with payment infrastructure.
Read the deep diveThe Plumbing Behind the Hype, Part 2: The Fifth Party Problem
Visa answered the liability question. The answer isn't reassuring.
Read the deep diveThe Algorithm Behind Your $90 Roast
How pricing algorithms and AI intersect at the grocery store. A real-world breakdown.
Read the deep diveThe Nuclear Option: How I Turned My Gaming Rig Into a Sovereign AI Server
What happens when you stop renting AI and start owning it. A full walkthrough.
Read the deep diveMore where this came from.
New resources, reviews, and deep dives every week. Subscribe on Substack and never miss one.
Subscribe on SubstackFree. No spam. Unsubscribe whenever.