Raise the Floor
You can't finish securing yourself. You can finish finding out.
Rahul Govind·May 30, 2026·9 min read
Security
What we're working on and what we're thinking about
One line of code introduces an SSRF. Fixing it correctly requires aligning URL parsing, DNS resolution, redirect handling, HTTP client behavior, and network policy—all at once, without missing a single edge case.
AI agent misbehavior isn't a sandbox problem—it's a permissions problem.
How Tachyon's autonomous security researcher found an authorization bypass in the open-source MLflow tracking server by reasoning across protocols and surfaces—and why this class of bug is so hard to catch.