The marketplace I had to defend from my own attack surface
Opening a public marketplace for agent workflows meant publishing an attack surface, and then having to defend it from my own convenience.

Opening a public marketplace for agent workflows meant publishing an attack surface, and then having to defend it from my own convenience.

A secret scanner failed a merge request over a test key and a documentation PEM that the change did not contain. Scoping a scan properly.

The philosophical end of the signing series: a stolen key and a bought one produce the same signature, and trust has to survive both.

Generate an asymmetric RSA-4096 signing key inside AWS KMS with no export path, then sign releases by calling kms:Sign instead of holding the key.

A checksum proves the bytes match the manifest, but says nothing about who wrote the manifest. Why self-update needs a signature instead.

The national vulnerability database is buckling under defunding and volume, which changes what a severity score is actually worth.

Signed but poisoned packages show a signature proves who sent something, not what is in it. Nobody is coming to clean this up for you.
