Want to join in? Respond to our weekly writing prompts, open to everyone.
Want to join in? Respond to our weekly writing prompts, open to everyone.
from
G A N Z E E R . T O D A Y

The world's first digital nomad: One Planet Journey interviews Steven K. Roberts.
Why Do Tech Bros Always Learn The Wrong Thing From Sci-fi? – Demonitzed on Youtube.
Music is a weapon – Chords and Discords on Youtube.
“Your eyes keep the world at a distance. You can look away from a horror film, you can step back from a painting, you can put down the book, or just close your eyes. But your ears can't do any of that. There's no such thing as earlids.” — Knrad, Chords and Discords.
#radar
from AI Tools Test | Reviews, Comparisons & Guides
An old family photo can be turned into a speaking video without inventing a new memory, but only when the project keeps the original record separate from the interpretation. Use words the person actually wrote or recorded, disclose that the motion and voice are generated, obtain consent from living people, and preserve the unedited scan beside the result.
Those rules should be written before the image begins to move. Once a familiar face appears to speak, emotional plausibility can make a weak editorial decision feel truthful.
This guide is for small, private family-history projects. It is not a method for making deceased relatives deliver greetings, settle old disputes, endorse a product, or say what someone believes they “would have said.”
A project needs a narrower purpose than “bring the photo to life.” That phrase says nothing about whose interests are served or what the finished file will claim.
Useful purposes are concrete:
A weak purpose is emotional but undefined: “make it feel as if the person is here again.” No tool can deliver that without crossing into fabrication. The output is a contemporary interpretation assembled from historical materials. It should be described that way.
Write the purpose at the top of the project notes. Every later choice can be tested against it.
Family archives often combine several layers that should not be confused.
The evidence is the physical letter, photograph, diary page, or recording.
The transcription is a readable copy of the words in that evidence. It may include notes such as [word unclear], [page torn], or [sentence continues on next page].
The interpretation is the new video: a face moves, a voice reads, pauses are chosen, and images are arranged. Even when every word is authentic, the performance is new.
Keep all three layers. Never save the talking photo as a replacement for the scan. A future viewer should be able to compare the video with the original material and see exactly where interpretation entered.
The Society of American Archivists’ Core Values Statement and Code of Ethics is written for professional archives, but its principles are useful at family scale: preserve context, document interventions, respect privacy, and avoid distorting records to support a preferred narrative.
The strongest editorial rule is also the easiest to explain: the person says only words that can be attributed to them.
Acceptable source material may include:
Do not smooth over missing lines with generated prose. Do not combine statements from different decades without labelling the edit. Do not change a hesitant or ambiguous sentence into a confident declaration.
If a word cannot be read, mark it as unclear or omit the sentence. The gap is part of the record. Filling it creates a sentence that may be believable and has no evidence behind it.
Translation needs the same caution. A translation contains another person’s word choices. When it is necessary, show the original text, name the translation, and avoid presenting the translated performance as if it were a direct recording.
Consent is required when the photographed person is alive. The request should cover more than permission to use a picture.
Explain:
Permission to keep a family photograph is not permission to animate it. Permission to make a private clip is not permission to publish it. A person may accept one use and refuse the other.
For someone who has died, consent cannot be obtained retrospectively. The family should consider the person’s known wishes, the sensitivity of the material, and the likely effect on people who knew them. A quiet refusal from a close relative deserves attention even when no law requires agreement.
The input quality affects the animation, but the preservation goal comes first. Do not alter the only copy of a photograph to satisfy a generator.
The Library of Congress provides practical personal digital archiving guidance on organising and preserving digital materials. For a photograph, a sensible small-project workflow is:
The working image should normally show one clear face, unobstructed and reasonably front-facing. Group photographs, heavy blur, deep shadow, hats, sunglasses, or aggressive filters can cause poor facial motion. Cropping a person from a group may also remove important context, so keep the full group scan beside the crop.
Restoration deserves restraint. Sharpening and colour repair can make damage less visible, but they can also invent facial detail. Label restored copies and preserve the untouched scan.
A cloned voice may feel authentic because it resembles the person. That resemblance is precisely why it requires a higher standard.
If no recording exists of the person reading the chosen text, the new performance never happened. A cloned voice can make the file sound like documentary evidence rather than an interpretation. Future relatives may not remember or notice the distinction.
A neutral library voice is often safer. It signals that someone is reading historical words without pretending to reproduce the original moment. Another option is a living family member reading the text and being credited by name.
If a voice clone is used with the informed permission of a living person, disclose it inside the video and its description. Store the consent record with the project notes. Avoid using a clone for emotional statements, endorsements, confessions, or anything that could affect reputation or relationships.
Expressive gestures can change the meaning of a sentence. A smile, nod, raised eyebrow, or pause may imply approval, irony, affection, or certainty that the source text does not contain.
For archival projects, restrained motion is usually the better choice. The goal is legibility and access, not performance. If the system offers different animation styles, begin with the least expressive option and review every gesture against the source.
This is especially important with grief. A warm expression may be emotionally compelling while remaining completely invented. The fact that it feels right to one viewer does not make it part of the historical record.
People searching for how to make my photo talk free online will find browser tools that accept a portrait and script. The practical steps are usually short: upload a clear image, enter text, select a voice, generate a draft, and review it.
The production note should be equally simple and should travel with the file:
Created in 2026 from a scan of a family photograph dated circa 1954.
The spoken text comes from a letter dated 18 March 1956.
Facial motion and voice are AI-generated; this is not an original recording.
The transcription preserves two unclear words as omissions.
For the original scan and transcript, see the family archive folder.
Place a shorter disclosure at the beginning or end of the video. Metadata alone is not enough because files are copied away from their folders.
Do not remove watermarks or platform disclosures from a free output. They may be visually inconvenient, but hiding the origin of synthetic media undermines the central promise of the project.
The person assembling the file should not be the only reviewer. Ask at least one relative who knew the subject well and one person who can compare the narration with the source document.
The first reviewer may notice that a gesture, expression, or voice feels intrusive. The second may catch a transcription error or an edit that changes meaning.
Give reviewers permission to recommend that the file remain private or not be completed. A review process designed only to improve the output is incomplete. Sometimes the most responsible result is a scan and transcript without animation.
Avoid asking whether the clip is “good.” Ask narrower questions:
A family group chat is not an archive. Files lose captions, messages disappear, and copies are renamed.
Keep a project folder with clear filenames:
1956-letter-project/
01-original-photo-scan.tif
02-working-photo.jpg
03-letter-front.tif
04-letter-back.tif
05-transcription.txt
06-translation-en.txt
07-production-note.txt
08-generated-video.mp4
09-consent-and-review-notes.txt
Make more than one backup and keep at least one copy in a different physical location or trusted service. Record dates and names in the notes rather than relying on memory.
If the video is shared publicly, publish the disclosure and source description beside it. Do not upload private letters merely to prove authenticity; a citation or controlled family archive may be more appropriate.
Do not continue when the available words are mostly invented or reconstructed, when a living person refuses permission, or when the result could be mistaken for a real recording in a consequential context.
Stop if the material reveals medical, financial, legal, or relationship information that the subject did not make public. Historical interest does not automatically outweigh the privacy of living people mentioned in a letter.
Avoid creating a synthetic message for a child or vulnerable relative who may not understand what the media is. The disclosure needs to be understood, not merely displayed.
Do not use an archival-style video to sell a product, support a political claim, or resolve a disputed family story. Those uses give the synthetic performance authority it did not earn.
It depends on source integrity, family context, disclosure, and purpose. Using attributable words for a limited private project is different from inventing a new message. Preserve the original materials, consult close relatives, and make the synthetic nature unmistakable.
Yes, if omissions are documented and the edit does not change meaning. Cut between complete passages where possible. Keep the full transcription with the project and avoid combining distant statements so they appear to form one continuous thought.
Usually not for a family archive unless the person is living and has given informed permission. A clone can sound like evidence of a performance that never occurred. A credited neutral reader or clearly synthetic library voice keeps the interpretive layer easier to recognise.
No. The scan preserves the visual record; the video is a derivative access copy. Keep the high-quality scan, metadata, transcription, and source document independently of the generated file.
Only after considering consent, rights, privacy, and the people named in the material. Public posting allows downloading and reuse outside the original context. A private family archive or password-protected share may fit the purpose better.
If the project disappeared, the original photograph and words should remain intact. If the disclosure disappeared, the file should still contain enough context to prevent it from passing as a recording. If an invented sentence were removed, the project should not lose its purpose.
Those tests keep the technology in a modest role: improving access to a family record without pretending to create a new one.
from untidy creatures.

I'm waiting for glass eyes to arrive by post so I can start creating polymer clay creatures with more soul (if glass being a better window than painted clay, which I suspect it is, since there are no idioms about polymers and sentience that I'm aware of).
I have another interview on Wednesday. This is probably a good thing, though it's an exhausting thing. An exhausting thing wearing a good suit like an unfortunate surprise. Hopefully I'll be less nervous with this one. Maybe it will be okay and I'll get a job offer! Depends on the quality of the suit, I guess. There's good and then there's whatever clusterbomb tends to go off in my brain when I'm asked questions and am expected to talk myself up. I can do this.
Maybe.
Shit.
from
Tecida à mão
O tema de hoje é o que eu chamo de meritocracia profissional. Você acredita nisso? Não no sentido de julgar quem não venceu, mas no sentido de que esforço e fé andam juntos quando se trata de colher resultados.
Estava eu no hospital essa semana, com bastante tempo até ser atendida, refletindo com uma amiga sobre como há pessoas que esperam resultados sem antes lembrar dos esforços. Foi ali que decidi, enfim, escrever esse texto que já rondava minha cabeça há um tempo.
Começo citando o meu exemplo de quando cheguei na Austrália. Haviam trabalhos disponíveis por $15 por hora na época, que era um valor baixo, e que lembro de estudantes que conheci recém chegados dizerem “não saio de casa por menos de $20”.
Pois bem. Eu saia. Por qualquer $15 que aparecia de trabalho eu estava pegando. Atravessava a cidade de trem se fosse preciso para limpar uma loja do outro lado da cidade, perdia mais tempo no trem do que de fato no trabalho, para ganhar míseros $15. De $15 em $15, eu conseguia pagar meu aluguel e comer. Nunca me faltou dinheiro, nunca precisei pedir emprestado a ninguém.
Muitos bicos depois, consegui um outro emprego que me pagava $17 na qual pude ficar 5 anos. Nele, conseguia ter tempo para estudar e me formar na pós graduação e ainda começar meu pequeno negócio, que dali eu sairia para empreender. Esses cinco anos não vieram de sorte. Vieram de cada $15 que eu não recusei antes.
E é aí que entra minha fé: eu, como crente, creio de verdade que Deus, com toda a sua graça, abre portas para nós e nos abençoa com grandes milagres. Mas eu também creio que ele não nos deixa esperando a benção sentada no sofá sem mover uma palma. Se quisermos a medalha final, temos que correr a maratona. Deus nos dá os tênis.
Eu acredito na bondade de Deus e no que ele pode fazer na nossa vida. Mas eu acredito também em meritocracia profissional. Acredito que muito esforço traz grandes recompensas. Não acredito em sorte. Acredito em batalhas vencidas.
Eu também já reclamei da vida, todo mundo já esteve nesse lugar em algum momento. O perigo é viver ali, em um círculo de lamentação onde nos fazemos vítimas da própria história.
As circunstâncias mudam sempre na nossa vida, mas a nossa mente é o que determina o lado que vamos seguir: de ficar nos lamentando ou de analisar o que tenho nas mãos hoje que possa me tirar do lugar onde estou.
Deus abre a porta. Mas somos nós que damos o primeiro passo. E se for preciso atravessar a cidade inteira de trem por $15, que seja. Um dia, esse $15 vira $17. E o $17 vira o negócio que você sempre quis ter. Não espere a sorte. Corra a maratona. Os tênis já foram entregues.
from
Noisy Deadlines
I started a personal Bullet Journal in June 2026, so it’s been a little bit over 2 months.
I read the book “The Bullet Journal Method” by Ryder Carroll and watched some online videos. This is the second time I’ve tried Bullet Journaling, the first time was roughly a year ago. As I wrote in this post I’ve been drawn to paper more and more lately.
I followed the basic Bullet Journal (or BuJo) setup steps, which include:
Choosing tools: notebook and pen
Doing a mental inventory (very similar to the GTD mind sweep) and separating items into 3 sections: Doing, Need to do, and Want to do (these are used to populate the BuJo lists)
Adding your name and phone number to the notebook (in case it gets lost)
Setting intentions
Setting up the Index
Setting a spread for the Future Log
Starting the first Daily Log and rapid logging
Doing a Weekly Reflection at the end of the week
Setting up a Weekly Plan and a Monthly Log
Adding new Collections as needed
I chose a Hardcover Leuchtturm1917 size B6+ with 80g/sqm paper. I like the size, not too big, not too small. I carry it with me together with my Kobo Libra. I added a pen loop so that I always have my Pentel EnerGel 0.5mm in blue with it.
But I also use additional assorted highlighters (Mildliners), colored pens and black Micron pens for titles.
The Leuchtturm1917 notebook already comes with dedicated pages for Index, so that was easy. I added a post-it on the back cover with my “Key” which is simply a quick reference that lists all the symbols I’m using for rapid logging.

Then there is the Intentions page, which is emphasized a lot by the Bullet Journal author, as it encourages us to clarify what we hope to accomplish and keep our daily actions aligned with our broader goals.

After that I have the “Future Log” which covers the next 6 months from the date I started the journal. In this case, it was from July to December. This spread holds future dates, planned events, planned start of projects.

Because I am a GTD’er I couldn’t start without setting my “Projects List” and my “Waiting For List”. I also setup “Someday Log” page. These are considered “Custom Collections” in BuJo lingo.

I spend most of my time with the Daily Logs. These are setup the day before or early in the morning. One thing that I like to do is have my four core habits at the top everyday (Yoga, Meditation, Reading) so that I check them daily.
Then I add events from my calendar from the day, and any actions I want to get done. The interesting thing about BuJo is that it works as both a journal and task manager tool. So I jot down ideas, tasks, thoughts, feelings and reflections on the daily log.
I am using the original notation system, as described in this page:

An example of my Daily Log spread
Similar to the GTD Weekly Review, BuJo recommends a Weekly Reflection.
I start with:
Then I reflect on the past week and take some notes answering the following questions:

An example of my weekly reflection/plan
Next, I create a page with my week action plan. I like to create my core habits tracker, a space for upcoming events/dates and then the next actions I plan on doing that week. I’ve started adding the books I will be reading as well.
I really like the Monthly Log collection. It helps me get a birds-eye view of what’s coming ahead and it also functions as a record of milestones and wins.
I set the left side as described in the book with the list of the days of the month. Very simple. This video from Ryder Carroll explains the different time horizons and how they work together.
On the right side I add the books I want to read, the focus of the month and then a list of next actions. Every week I will review this list to migrate actions to Week Plan. Some of them go directly to my Daily Plan as well.

Monthly Log
I can use any other page of the notebook to add custom collections, like this one I created for Blaugust. Or add notes from a book I’ve read. Or plan a project. It can be anything! And then I add the page number to the Index so I can come back to it.
I also use sticky tabs to mark pages I want to quickly reference, like the current Monthly Log.
—
And that is my current setup!
I don’t prepare any week spreads in advance, and I don’t reserve any blank pages. It all goes sequentially, whenever I find the next blank page. I will occasionally use stickers, something I got from using Happy Planners. But other than that, I try to keep it easy to use. No crazy decorations.
And here are some of the references I used in this journey:
—
Post 10 of #Blaugust #Productivity #journal #journaling #bujo
from
SmarterArticles

In April 2025, researchers at Invariant Labs published a demonstration that sent a quiet shudder through the software security community. They showed that a malicious Model Context Protocol server, running alongside a legitimate WhatsApp MCP server and disguised as a harmless “random fact of the day” tool, could silently exfiltrate a user's entire message history. The technique was a sleeper: the rogue server advertised something innocuous, waited, then altered its tool description to shadow the legitimate WhatsApp tool, instructing the agent to route conversations to an attacker-controlled phone number. The victim's assistant appeared to be sending a perfectly ordinary message. Behind the curtain, it was transmitting months of personal and business conversations to a stranger.
The detail that mattered most was the one easiest to miss. The attack did not depend on a user being careless with permissions. As Invariant Labs put it, the technique circumvents the need for the user to approve the malicious tool at all, because the poisoned description hijacks a tool the user has already sanctioned. Approval prompts, the control most organisations still treat as their primary safeguard, were not so much bypassed as rendered irrelevant. Invariant released reproducible proof-of-concept code. The vulnerability it exposed, that autonomous agents can be turned against their operators through crafted manipulations of tool definitions and prompt structures, has since become one of the most consequential challenges in software security.
That was the warning shot. Sixteen months later, the demonstration has become an industry. Check Point Research's AI Security Report 2026, published in July, records indirect prompt injection detections rising roughly fivefold between March and May 2026, approaching one per cent of all observed prompts, and describes a threshold being crossed: “AI has crossed from development aid to live attack operator. It now does the hands-on work inside live intrusions.” Attackers have moved on from the single poisoned prompt to planting malicious configuration files that agents load and trust across sessions, turning a one-shot trick into persistence. One developer built VoidLink, an 88,000-line command-and-control framework, in under a week with AI assistance. And in April 2026 the argument moved from implementations to the protocol itself, when OX Security disclosed a systemic flaw at the core of MCP and Anthropic replied that the behaviour was intentional.
Meanwhile the agents themselves became infrastructure. Cursor, GitHub Copilot, Claude Code, Gemini CLI, and OpenAI Codex now run with elevated privileges across repositories and pipelines, reading source, executing shell commands, pushing commits, and calling external services. They are autonomous actors in the software development lifecycle, and like every powerful actor granted broad access without adequate controls, they are an irresistible target.
The field's common vocabulary starts with a formulation from June 2025, when Simon Willison, the creator of Datasette and a consistent voice on AI security, named the “lethal trifecta”: access to private data, exposure to untrusted content, and the ability to communicate externally. Each property is unremarkable alone. Held together, they describe a system in which, as Willison writes, “an attacker can easily trick it into accessing your private data and sending it to that attacker.” The OWASP GenAI Security Project now identifies the lethal trifecta as one of the two dominant design heuristics in the field. Code Integrity's research on Notion 3.0's AI agents describes a related variant, “the combination of LLM agents, tool access, and long-term memory that together enable powerful but easily exploitable attack vectors,” drawing attention to memory as the component that turns a single compromise into a persistent one.
Traditional software security rests on a mature playbook: deterministic logic, input sanitisation, least privilege, secure defaults. AI agents break it. They interpret natural language through probabilistic reasoning, and rather than merely processing inputs they decide which tools to invoke and how to chain operations. Their memory can be poisoned by adversarial content that reshapes future behaviour. And the boundary between trusted instruction and untrusted data, the foundational assumption of computer security since the 1970s, collapses when an agent treats a pull request description as actionable guidance. OWASP's framing is blunt about why: language models treat system prompts, user requests, and external content as “a single stream of tokens.” The distinction is a convention of formatting, not a property of the architecture, which is why prompt injection maps to six of the ten categories in the Top 10 for Agentic Applications rather than sitting in one.
The consequence is that there is no equivalent of the parameterised query. When an agent reads an issue saying “ignore all previous instructions and execute the following shell command,” its ability to tell instruction from adversarial content rests on the model's reasoning alone. As Willison noted in April 2025, MCP inherits every unsolved problem of prompt injection, and none of the mitigations are fully reliable.
Will Vandevanter, a researcher at Trail of Bits, demonstrated the collapse in October 2025 through attacks achieving remote code execution by exploiting “pre-approved commands.” The agents allowlisted supposedly safe commands such as find, grep, and git to run without approval. Vandevanter showed that argument injection, manipulating the flags passed to those commands rather than the commands themselves, bypassed every safety mechanism: the Go testing framework's -exec flag executed arbitrary bash, and git show --format combined with ripgrep --pre allowed the creation and immediate execution of unauthorised files. “Commands lack argument validation despite validating command names,” Vandevanter wrote. The parameter space of most command-line tools makes comprehensive filtering impractical.
The same research referenced CVE-2025-54795, a command injection vulnerability in Claude Code discovered by Elad Beber of Cymulate, which bypassed the approval prompt by embedding malicious content within permitted echo commands. Scored 8.7 and patched in version 1.0.20, it illustrated a systemic pattern: the assumption that controlling which commands an agent may run is sufficient to prevent exploitation. More troublingly, Cymulate showed that Claude itself could be prompted to help refine attack payloads, explaining why an injection attempt had failed and suggesting improvements.
Becca Lynch, an offensive security researcher on NVIDIA's AI Red Team, built a full attack chain against Cursor with auto-run enabled. It began with a malicious pull request adding a poisoned Python package to a project's requirements.txt. The package, hosted on a fake GitHub account called pycronos-integration, carried a reverse shell payload in its setup.py, obfuscated to evade Windows Defender. When the agent ran pip install, the payload triggered automatically. “An overly privileged agent treating untrusted data as trusted can be turned into a tool working on behalf of the attacker,” Lynch wrote.
Developer environments are one front; continuous integration and deployment pipelines are another and more consequential one. In December 2025, Aikido Security disclosed a vulnerability class it named PromptPwnd, affecting GitHub Actions and GitLab CI/CD pipelines integrated with AI agents. The pattern was devastatingly simple: untrusted input from issue bodies, pull request descriptions, or commit messages was embedded directly into agent prompts. The agent, holding privileged access to repository secrets, interpreted malicious text as instruction and executed it.
Researcher Rein Daelman of Aikido demonstrated the attack against Google's own Gemini CLI repository. By submitting an issue containing hidden instructions, Daelman directed the agent to execute shell commands that leaked the repository's GEMINI_API_KEY, GITHUB_TOKEN, and Google Cloud access tokens. Google patched within four days, but the implications ran well beyond a single repository: Aikido confirmed that at least five Fortune 500 companies were affected, and open-sourced Opengrep rules and a scanning tool to help developers find vulnerable workflow files. The same year brought CVE-2025-53773, a hidden prompt injection in pull request descriptions that achieved remote code execution through GitHub Copilot at a CVSS score of 9.6. PromptPwnd also showed that environment variables offer no protection. Configurations that appeared restrictive, such as Claude Code Actions' allowed_non_write_users setting, amplified risk when misconfigured, and some could be triggered by anyone filing an issue, making them reachable by attackers with no prior access.
March 2026 supplied the ecosystem-scale proof, and it began with a credential rotation somebody thought was finished. Aqua Security, maintainer of the widely used Trivy vulnerability scanner, disclosed a comparatively small breach in late February 2026. The rotation that followed was partial, and the attackers retained access. The group, which calls itself TeamPCP and which Google tracks as UNC6780, used that retained access on 19 March to force-push malicious commits to 76 of the 77 version tags on the trivy-action repository and to all seven tags on setup-trivy, then published a malicious Trivy 0.69.4 release through official distribution channels. Over the following days the same operation reached Checkmarx's KICS and AST GitHub Actions, and then LiteLLM. Microsoft's incident analysis is unusually direct about the mechanism: the attackers leveraged access from a prior incident that had not been fully remediated. Partial remediation of a minor compromise financed a major one.
LiteLLM's CI/CD pipeline pulled Trivy from apt without a pinned version, so the poisoned action ran inside its GitHub Actions runner and exfiltrated the project's PYPI_PUBLISH token from the runner environment. Five days after the Trivy compromise, that token was used against LiteLLM's PyPI publishing pipeline. Malicious versions 1.82.7 and 1.82.8 went live at 10:39 UTC on 24 March 2026 and were quarantined by PyPI roughly 40 minutes later. The two used different injection techniques, and the second is the more alarming. Version 1.82.7 carried a base64-encoded payload inside litellm/proxy/proxy_server.py that executed whenever anything imported litellm.proxy. Version 1.82.8 added a litellm_init.pth file to site-packages, a file type Python executes on every process startup in any environment where the package is installed, which converts a library compromise into an interpreter compromise. The payload ran a three-stage operation: credential harvesting, attempted lateral movement across Kubernetes clusters, and installation of a persistent systemd backdoor that polls for further payloads. CloudSEK's analysis of roughly 434,000 captured files mapped them to more than 2,500 organisations, a figure the firm was careful to describe as potential exposure rather than a victim count, because it identifies organisations whose credentials may have been captured rather than organisations known to have been breached. On 2 July 2026 the FBI issued FLASH-20260702-01, warning that affiliated actors are likely to weaponise credentials exfiltrated during the campaign long after the initial compromise, and urging rotation of CI/CD secrets, publishing tokens, and cloud credentials exposed during the relevant windows. The tail of this compromise is measured in months, not days.
None of it was a flaw in LiteLLM's own code, which is exactly what makes it the strongest available argument about pipelines. LiteLLM is the language model gateway used by CrewAI, DSPy, Microsoft GraphRAG, and dozens of other agent frameworks, so the chain ran from a security scanner to a CI/CD pipeline to a package registry and into the agent framework supply chain, with each link trusted precisely because the one before it was. The recursion is the point: the case for treating pipelines as attack surface was proved by an attack that travelled through the tooling of the people who do security professionally. A single compromised workflow affects every build and release passing through it, arriving through the automation organisations trust to enforce quality.
The Model Context Protocol has become the connective tissue of the agentic ecosystem, the standardised interface through which agents discover and invoke external tools. Wiz Research found in early 2026 that MCP servers were present in at least 80 per cent of observed cloud environments, and that 5 per cent of those ran at least one internet-facing server. Adoption at that speed has been matched by an equally rapid accumulation of vulnerabilities.
The tool poisoning attack Invariant Labs discovered exploits a fundamental design characteristic. Tool descriptions are transmitted as metadata that models process as instructions, while users see only simplified tool names. A malicious server can embed hidden directives within those descriptions, using constructs such as <IMPORTANT> tags that are invisible to the operator and fully visible to the model. The specification allows tool definitions to change between tools/list responses with no integrity check, no hash pinning, and no mandatory re-approval. This creates the conditions for rug pull attacks, in which a tool that appeared safe at installation quietly mutates weeks later, and for the tool shadowing seen in the WhatsApp demonstration.
The scope of implementation flaws is sobering. Research compiled by Tigran Bayburtsyan found that 43 per cent of tested MCP implementations contained command injection flaws and 30 per cent allowed unrestricted URL fetching. Three chained vulnerabilities in Anthropic's own mcp-server-git achieved remote code execution via malicious .git/config files, and its MCP Inspector permitted unauthenticated execution through its proxy architecture, meaning that merely inspecting a malicious server could compromise a developer's machine. In September 2025 the first malicious MCP server was found in the wild, an npm package impersonating Postmark's email service that worked normally while secretly copying every message to an attacker. The following month, the Smithery attack affected over 3,000 hosted applications and their API tokens.
Then, on 15 April 2026, OX Security disclosed something categorically different. Its researchers reported a systemic architectural vulnerability in MCP's STDIO transport, the mechanism by which most local servers launch: user-controlled configuration values flow directly into shell execution without sanitisation or allowlisting. The flaw sits not in a third-party implementation but in Anthropic's official SDKs, across Python, TypeScript, Java, and Rust alike. The injected command executes even when the target process fails to start, so an attacker does not need a working server, only a configuration entry. The numbers are unusual for a single disclosure: more than 150 million package downloads, roughly 7,000 publicly reachable servers, an estimated 200,000 vulnerable instances, commands executed against six live production platforms, and nine of eleven MCP registries affected. Ten CVEs accompanied the disclosure and fourteen have followed, most critical, including LiteLLM (CVE-2026-30623), Agent Zero (CVE-2026-30624), and Windsurf IDE (CVE-2026-30615), alongside Fay, LangChain, and IBM LangFlow. OX Security grouped the exploitation into four families: unauthenticated interface injection, hardening bypasses in protected environments, zero-click prompt injection in AI IDEs, and malicious distribution through registries.
The decisive moment came not in the disclosure but in the response. During coordinated disclosure in January 2026, Anthropic confirmed the behaviour was intentional. Its position is that STDIO execution is a secure default provided developers restrict what may appear in the command field; sanitisation is the developer's responsibility. Nine days after initial contact it updated SECURITY.md to advise caution with STDIO adapters. No architectural change was made. Some researchers now call it the protocol that will not be patched.
This is qualitatively unlike every other item catalogued above. A rug pull abuses a specification gap; an unsanitised AppleScript call is a bug with a patch number. Here there is no patch to wait for, because the maintainers do not accept that the flaw is theirs to fix, and their reasoning is not unserious: a protocol that launches local processes must let a developer specify what to launch. But the standard advice, treat every MCP server as a third-party dependency and vet it accordingly, no longer reaches far enough. Vetting assumes the ecosystem beneath the dependency is sound. Organisations must now defend against a transport whose specified behaviour is itself the exploitation primitive.
The governance argument for MCP servers generalises, and in February 2026 it did so violently. Researcher Paul McCarty identified 386 malicious skills on ClawHub, OpenClaw's official skill repository, published between 1 and 3 February. Koi Security's Oren Yomtov then audited all 2,857 skills available and found 341 malicious, 335 of them traced to a single coordinated operation now tracked as ClawHavoc.
The skills impersonated crypto-trading automation using real brand names including ByBit, Polymarket, Axiom, Reddit, and LinkedIn, and deployed infostealers on macOS and Windows that harvested exchange API keys, wallet private keys, SSH credentials, and browser passwords. All shared common command-and-control infrastructure, and a single account, hightower6eu, accumulated close to 7,000 downloads. By 16 February the count had reached 824 malicious skills across a registry that had itself expanded past 10,700, and Antiy Labs eventually catalogued 1,184 published to ClawHub over the platform's history.
The lesson is not specific to one marketplace. Every agent extension ecosystem reproduces the same structure: low-friction publishing, a naming system that permits brand impersonation, an install flow granting broad local privilege, and review that scales far more slowly than submissions. The npm and PyPI ecosystems took a decade to learn this. Agent marketplaces are relearning it in months, with the aggravating factor that the installed artefact is not a library the developer calls but an instruction set the agent obeys.
The attack surface extends beyond servers and registries into development environments themselves. Over a six-month investigation, security researcher Ari Marzouk, who publishes as MaccariTA, identified a pattern he named IDEsaster: more than 30 vulnerabilities across over ten market-leading products, including Claude Code, Cursor, GitHub Copilot, Windsurf, JetBrains Junie, and Zed.dev, of which 24 received assigned CVEs. His central finding was unambiguous. One hundred per cent of tested AI IDEs were vulnerable.
The research revealed three core attack patterns. Remote JSON schema attacks exploit the tendency of IDEs to fetch schemas referenced in JSON files automatically; an attacker who prompts the agent to write a file containing a remote schema reference can cause the IDE to transmit data as URL parameters when fetching it, exfiltrating information even with human-in-the-loop protections and diff preview active. Settings overwrite attacks modify .vscode/settings.json or .idea/workspace.xml to redirect executable paths to malicious code, with CVEs assigned to Cursor, Roo Code, and JetBrains Junie. The third pattern exploits multi-root workspace files, affecting GitHub Copilot, Cursor, and Roo Code.
What makes these attacks troubling is that they defeat the safeguard most developers rely on, the confirmation prompt. Even with diff preview enabled and approval required for every change, they succeed because the malicious behaviour sits inside changes that look benign. A remote schema reference looks like ordinary configuration; a workspace settings change looks routine. The reviewer, facing hundreds of them daily, has neither the time nor the context to spot the threat. Context hijacking extends this through vectors few would think to inspect: poisoned URLs containing invisible Unicode characters, malicious .cursorrules files inside cloned repositories, and instructions hidden in filenames.
On 7 May 2026, Microsoft disclosed two vulnerabilities in its own Semantic Kernel framework that shifted the problem again. CVE-2026-26030, affecting the Python package before version 1.39.4, arose from unsafe string interpolation in a default filter function. The framework used eval() to build lambdas from filter strings the model controlled, so an attacker could close the quote, append Python logic, and turn a data lookup into an executable payload. A blocklist meant to stop exactly this was circumvented by traversing Python's type system to reach __name__, load_module, and eventually system, reconstructing dangerous capability from parts that were individually permitted.
CVE-2026-25592, affecting the .NET SDK before 1.71.0, was simpler and more instructive. A DownloadFileAsync method had been marked with the [KernelFunction] attribute, making it directly callable by the model. With no path validation on its destination parameter, it permitted arbitrary file writes to the host, breaking container isolation by writing a payload into the Windows Startup folder from inside a sandboxed session. Nobody chose to expose that capability. An annotation intended to publish useful functions to a model published a dangerous one.
Microsoft's remediation was properly layered: allowlists of permitted AST node types and callable functions, a blocklist of attributes used for class hierarchy traversal, and a restriction on name nodes to lambda parameters, plus removal of the offending attribute and canonicalised path validation. The significance lies in the location rather than the fix. Every vulnerability discussed so far lived in an agent's configuration, tools, or extensions, the layer an organisation controls. These live in the framework that builds agents, beneath the layer most security teams inspect.
The OWASP GenAI Security Project announced its Top 10 for Agentic Applications on 9 December 2025, explicitly as the 2026 edition, the product of more than a year of research involving over 100 researchers and an expert board including NIST, the European Commission, and the Alan Turing Institute. It spans ten categories, from agent goal hijacking and tool misuse through identity abuse, insufficient sandboxing, and supply chain compromise to memory manipulation, cascading failures, and rogue agents.
It also introduces a concept that may prove as consequential as its predecessor, least privilege: the principle of least agency. Where least privilege restricts what permissions a process holds, least agency restricts what autonomous decisions an agent may make. An agent with broad tool access but constrained autonomy can still be held to bounded, well-defined tasks.
Meta gave that principle an implementable shape. Its Agents Rule of Two, published on 31 October 2025, holds that until prompt injection can be reliably detected and refused, an agent must satisfy no more than two of three properties within a session: processing untrustworthy input, accessing sensitive systems or private data, and changing state or communicating externally. Where all three are genuinely required, the agent should not operate autonomously and needs human approval or another reliable means of validation, with a fresh context window as the mechanism for resetting the count. It is the lethal trifecta expressed as an operational constraint rather than a warning, and OWASP names the two together as the field's dominant heuristics. The practical value is that it is checkable: an engineer can read a session configuration and count.
The first implementation layer is tool restriction: limiting which commands, APIs, and resources an agent may reach, and separating operations safe to auto-approve, such as reads and static analysis, from those needing approval, such as filesystem writes, package installation, and outbound network calls. The separation is not merely administrative tidiness. It maps the blast radius of a successful injection, because an agent that can only read cannot exfiltrate, and an agent that cannot install packages cannot be handed a payload by a poisoned manifest. Trail of Bits' argument injection research is the caveat that keeps this honest: allowlisting a command name without constraining its arguments is not a control, it is a label. The lesson generalises well beyond the specific flags Vandevanter demonstrated. Any tool rich enough to be worth giving an agent has a parameter space large enough to conceal an escape, so restriction is better expressed in terms of the capability granted than the binary invoked. Anything that can spawn a subprocess, write to an arbitrary path, or fetch a remote resource should be treated as the dangerous capability it is, whatever name sits at the front of the command line.
The second layer is sandboxing, and here the past year has produced genuine movement. Software-only isolation was always the weak form of this recommendation; Bayburtsyan's research emphasised the need for hardware-enforced boundaries. Claude Code now ships operating-system-level sandboxing that enforces filesystem and network isolation through the kernel rather than through trust or prompt engineering, routing network access through a proxy outside the sandbox, applying domain allowlists, and prompting on first contact with a new domain. That last detail matters more than it appears. It moves the approval decision off the question the model can be manipulated about, whether an action is reasonable, and onto one it cannot, whether a destination is on a list. The Semantic Kernel file write is the reminder of what happens when the boundary is enforced anywhere softer: an isolation layer defeated by a single unvalidated destination path was never isolation, only a convention that the code inside agreed to observe. A recommendation made in the abstract a year ago is now a shipped default.
The third layer is identity and credential isolation, which has matured from an aspiration into a standards effort. Each agent instance should hold unique, scoped credentials granting access only to what the current task requires. Shared credentials and long-lived tokens create the conditions attackers exploit, as the Supabase Cursor breach of mid-2025 showed when an agent with privileged service-role access processed support tickets containing user-supplied SQL. What has changed is that agents are beginning to hold identities of their own. Microsoft Entra Agent ID, first documented in April 2026, issues agent identities that speak OAuth 2.0, MCP, and A2A. NIST's AI Agent Standards Initiative, announced in February 2026, organises the work across three pillars: industry-led standards development, community-led open source protocol maintenance, and research into agent security and identity. The principle emerging from that work is scope attenuation, the rule that each delegation hop must narrow and never widen the permitted action set, so no sub-agent accumulates capabilities the original human principal never authorised. Cryptographic workload identity, through SPIFFE and SPIRE identity documents or OIDC-federated tokens, replaces the shared API key with something that can be scoped, attributed, and expired.
The fourth layer is trust boundary enforcement. Every piece of external data an agent processes must be treated as adversarial, scanned not only for injection patterns but for hidden instructions, role-playing directives, and system prompt overrides. The list of entry points is longer than most teams assume: issue bodies and pull request descriptions, fetched web pages, the output of one tool feeding the input of the next, dependency manifests, and the configuration files that arrive with any cloned repository. Invisible Unicode and instructions concealed in filenames both belong on the same list. But the layer should be held loosely, because filtering is a probabilistic control applied to a probabilistic system, which is why it is the last of the preventive layers rather than the first.
The fifth layer is monitoring and anomaly detection, and it exists because the preceding four will eventually be got round. Agent actions warrant the scrutiny given to privileged human users, which means baselining what normal looks like for a particular agent in a particular repository and alerting when behaviour departs from it. The baseline is more tractable than it sounds, because agents are creatures of habit. A documentation agent that reads Markdown and opens pull requests has a behavioural signature, and a sudden interest in environment variables, credential stores, or outbound connections is a deviation visible without any understanding of what the agent was asked to do. Continuous comparison against expected patterns catches the class of compromise that defeats every preventive control by looking legitimate at each individual step, because in those cases the anomaly lives in the aggregate rather than in any single action. Detection of this kind is imperfect and will fire on unusual but entirely legitimate work. That is the right trade for a system whose characteristic failure mode is silence.
Detection without documentation is insufficient. An effective agent log should capture the instruction that triggered each action, the tools invoked and the arguments passed, the outputs and side effects, the credentials used, timestamps precise enough for causal ordering, and the provenance of any external data the agent consumed. This matters for two reasons. Prompt injection is designed to be invisible, so without logs there is no artefact to investigate and no way to establish whether an agent was manipulated or merely mistaken. And because identical inputs can produce different outputs, a decision cannot be reproduced unless it was recorded at the time it was made. The log is the only durable evidence that a probabilistic system ever behaved in a particular way.
Logging also underwrites the control that matters most once something has gone wrong, which is the ability to stop the agent mid-action. Every major tool exposes a manual interruption path: Ctrl+C in Cursor, Cmd+Esc in VS Code, Esc in Claude Code. These are worth knowing and worth teaching, but they depend on somebody watching at the moment it matters, which is precisely the assumption agentic workflows are designed to remove. Beyond manual intervention, organisations should implement automated kill switches that trigger when agent behaviour exceeds defined parameters: an unusual volume of file modifications, network requests to unknown domains, or attempts to reach credentials outside the agent's designated scope. The thresholds are organisation-specific, and the first versions of them will be wrong. Thresholds set too tightly halt an agent that was doing legitimate work, which is an annoyance measured in minutes. The absence of a halt is measured in the FBI advisories that follow months later.
Logging must also span agent boundaries, and OWASP's emphasis on cascading failures explains why. When multiple agents interact, whether through direct communication or through shared resources such as a repository, a job queue, or a common memory store, a compromise in one propagates through the system. An injected instruction absorbed by the first agent becomes a plausible-looking artefact consumed by the second, and by the third the origin has vanished entirely, because what the third agent sees is simply the state of the codebase. Tracing that chain of causation after the fact requires detail comparable to distributed tracing in microservices, applied to decision-makers whose behaviour is inherently less predictable than deterministic software. The comparison is instructive and also generous to the problem. Microservices at least fail the same way twice.
The central tension in agent security is that every control reduces capability. Requiring approval for every tool invocation eliminates the productivity benefit that justified deployment; restricting agents to read-only operations prevents the work that makes them valuable. Over-constrained agents become expensive autocomplete. The pragmatic path accepts that some risk is inherent and concentrates on making it manageable, building architectures where no single control is assumed sufficient and the failure of one layer is caught by the next.
Plan-then-execute workflows offer one approach: requiring agents to produce execution plans for review before acting inserts a checkpoint without discarding their reasoning. It is not foolproof, since a sophisticated injection could produce a plan that reads as benign, but it raises a single-step exploitation into a multi-stage deception that must survive scrutiny. Its underrated value is that it changes what the reviewer is asked to look at. A diff shows what will change; a plan shows what the agent believes it has been asked to do, and a hijacked goal is far more legible in a statement of intent than in the file that intent eventually touches. Tiered autonomy provides another frame: low-risk operations such as reading code, running tests, and producing analysis proceed autonomously, source modification requires automated policy checks, and pushing to production or accessing secrets always requires explicit authorisation. Read against the Rule of Two, this keeps the sessions touching untrusted content separate from those holding sensitive access and outbound reach, which is the same discipline expressed as a workflow rather than a count.
Egress filtering remains the most underrated control available. Most exfiltration depends on the agent reaching an attacker-controlled endpoint, so restricting which domains it may contact, and alerting on attempts to reach anything else, disrupts exfiltration even when injection succeeds. The alert is as valuable as the block. A blocked request to an unrecognised domain is close to a positive indicator of compromise, and it is one of very few signals in this field that does not require anyone to interpret a model's reasoning. Egress filtering removes the third leg of the trifecta outright, which is why kernel-enforced network isolation with domain allowlisting is the highest-value change most teams can make this quarter.
MCP server governance deserves particular attention, with the caveat the OX Security disclosure imposes. Organisations should maintain curated registries of approved servers, prohibit dynamic loading of tool definitions from untrusted sources, and monitor definition integrity continuously, the discipline Invariant Labs' MCP-Scan was built to support. But vetting does not address a transport whose vendor considers the execution behaviour correct, which means the configuration files feeding server definitions must themselves be treated as executable content, versioned, reviewed, and access-controlled accordingly.
None of this composes into a guarantee, and the framing matters. Layered defence is not a claim that five imperfect controls multiply into one reliable control. It is a claim that their failure modes are uncorrelated enough that an attacker must defeat several unrelated mechanisms rather than one. Prompt injection defeats the model's judgement. It does not defeat a kernel-enforced network boundary, a scoped credential that expires, or an alert that fires on a file-modification threshold, because none of those controls consult the model about whether they ought to apply. That is the design principle underneath every recommendation here: place as much of the enforcement as possible in the parts of the system the agent cannot argue with.
The technical controls above are necessary but insufficient. The deeper challenge is institutional: building cultures that treat agent security as a first-class concern.
The scale is now measurable. OWASP's State of Agentic AI Security and Governance, published in June 2026, tracks 53 agentic projects, 28 of them coding agents, with Claude Code, Gemini CLI, Codex, Cline, and Aider growing fastest. Advisory counts are already substantial: 57 for n8n, 22 for Claude Code, 15 for AutoGPT, 13 for Dify, 11 for Roo-Code. Release velocity compounds the triage burden, with one tracked project averaging a release every eight hours. No security team reviews changes at that cadence. The governance model most organisations apply, periodic review of a stable dependency set, does not survive contact with software that reissues itself three times a day.
Bayburtsyan's observation that “IDEs were not originally built with AI agents in mind” applies equally to the governance structures within which they operate. His sharper point is that “once AI began to take action, the nature of security changed forever.” Most organisations adopted these tools on the strength of productivity promises, addressing security retrospectively if at all. The result is a landscape where agents hold privileges no human developer would receive without vetting, tool access is configured for convenience, and behavioural monitoring is minimal. Reversing this means involving security teams from the outset, bringing agent configurations under the change management applied to infrastructure, and writing agent compromise into incident response plans. Training matters too: developers must understand that pull requests can carry injections, that MCP tools can mutate after installation, that marketplace extensions can be hostile at a rate approaching one in eight, and that agent output is untrusted however confident it sounds.
Sixteen months after the WhatsApp demonstration, the honest assessment is neither vindication nor despair but a split verdict. Real defences shipped. Kernel-enforced sandboxing exists and is available by default. The Rule of Two and the lethal trifecta have given engineers a vocabulary precise enough to design against. Agent identity has moved from conference talk to standards initiative, with NIST convening the work and scope attenuation as its organising principle. These are not gestures; they are the recommendations of 2025 arriving as products. And yet the underlying problem is untouched. OWASP's researchers now describe prompt injection not as a defect awaiting a patch but as a structural property of how language models consume tokens, and the year's most consequential disclosure ended with a protocol's maintainers declining to change it. That is the tension the industry has to hold. The perimeter around the agent is getting genuinely stronger while the thing inside it remains, by construction, persuadable. Every control described here is an admission of that, a way of ensuring that when an agent is talked into working for the attacker, and it will be, the damage is bounded by something that cannot be talked into anything.
Invariant Labs. “WhatsApp MCP Exploited: Exfiltrating Your Message History via MCP.” invariantlabs.ai, April 2025. https://invariantlabs.ai/blog/whatsapp-mcp-exploited
Invariant Labs. “MCP Security Notification: Tool Poisoning Attacks.” invariantlabs.ai, April 2025. https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks
Willison, S. “The Lethal Trifecta for AI Agents.” simonwillison.net, 16 June 2025. https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
Willison, S. “Model Context Protocol Has Prompt Injection Security Problems.” simonwillison.net, 9 April 2025. https://simonwillison.net/2025/Apr/9/mcp-prompt-injection/
Vandevanter, W. “Prompt Injection to RCE in AI Agents.” Trail of Bits Blog, 22 October 2025. https://blog.trailofbits.com/2025/10/22/prompt-injection-to-rce-in-ai-agents/
Cymulate. “CVE-2025-54795: InversePrompt: Turning Claude Against Itself.” Cymulate Blog, August 2025. https://cymulate.com/blog/cve-2025-547954-54795-claude-inverseprompt/
Lynch, B. “From Assistant to Adversary: Exploiting Agentic AI Developer Tools.” NVIDIA Developer Blog, 2025. https://developer.nvidia.com/blog/from-assistant-to-adversary-exploiting-agentic-ai-developer-tools/
Daelman, R. “PromptPwnd: Prompt Injection Inside GitHub Actions.” Aikido Security Blog, December 2025. https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents
The Hacker News. “Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations.” thehackernews.com, 12 August 2026. https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html
Microsoft Security. “Detecting, Investigating, and Defending Against the Trivy Supply Chain Compromise.” Microsoft Security Blog, 24 March 2026. https://www.microsoft.com/en-us/security/blog/2026/03/24/detecting-investigating-defending-against-trivy-supply-chain-compromise/
OX Security. “The Mother of All AI Supply Chains: Critical Systemic Vulnerability at the Core of the MCP.” ox.security, 15 April 2026. https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/
The Hacker News. “Anthropic MCP Design Vulnerability.” thehackernews.com, April 2026. https://thehackernews.com/2026/04/anthropic-mcp-design-vulnerability.html
Wiz. “Model Context Protocol (MCP) Security.” wiz.io, 2026. https://www.wiz.io/academy/ai-security/model-context-protocol-security
AuthZed. “A Timeline of Model Context Protocol (MCP) Security Breaches.” authzed.com, 2025. https://authzed.com/blog/timeline-mcp-breaches
Code Integrity. “Notion MCP Server Vulnerability Analysis.” codeintegrity.ai, 2025. https://www.codeintegrity.ai/blog/notion
Dark Reading. “Malicious OpenClaw Skills on ClawHub Threaten AI Supply Chain.” darkreading.com, February 2026. https://www.darkreading.com/cyber-risk/malicious-openclaw-skills-clawhub-threaten-ai-supply-chain
Marzouk, A. “IDEsaster.” maccarita.com, 2025. https://maccarita.com/posts/idesaster/
Bayburtsyan, T. “Securing AI Coding Agents: IDEsaster Vulnerabilities.” tigran.tech, 29 December 2025. https://tigran.tech/securing-ai-coding-agents-idesaster-vulnerabilities
Microsoft Security. “Prompts Become Shells: RCE Vulnerabilities in AI Agent Frameworks.” Microsoft Security Blog, 7 May 2026. https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/
OWASP GenAI Security Project. “OWASP Top 10 for Agentic Applications for 2026.” Announced 9 December 2025. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
Help Net Security. “OWASP: Prompt Injection Underpins AI Security Failures.” helpnetsecurity.com, 11 June 2026. https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/
Check Point Research. “AI Security Report 2026.” research.checkpoint.com, July 2026. https://research.checkpoint.com/2026/ai-security-report-2026/
Meta. “Agents Rule of Two: A Practical Approach to AI Agent Security.” ai.meta.com, 31 October 2025. https://ai.meta.com/blog/practical-ai-agent-security/
Anthropic. “Claude Code Sandboxing.” code.claude.com, 2026. https://code.claude.com/docs/en/sandboxing
NIST. “Announcing the AI Agent Standards Initiative for Interoperable and Secure Innovation.” nist.gov, February 2026. https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure

Tim Green UK-based Systems Theorist & Independent Technology Writer
Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.
His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.
ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk
Listen to the free weekly SmarterArticles Podcast
from
Gnostic Paradise

The Dead are not those who have passed through physical death, but those who have permanently refused the death of their ego. They remain trapped in the Abyss of self, a state of spiritual separation from the Divine that they have chosen through countless refusals to awaken. The Abyss is not a physical place but a state of consciousness that has prepared itself for dissolution through its own choices. The painful dissolution of the Ego marks the beginning of the Second Death. After its completion, no Ego remains, but the Essence escapes the extinct Ego and flees from the Abyss to reclaim all that was lost. Samael Aun Weor's book 'Hell, Devil, and Karma – Chapter 13, The Ninth Infernal Circle, the Sphere of Neptune' elucidates the transformation of a living being into a dead one.
The dead are those who have permanently betrayed their innermost selves, a crime of high treason or lese majeste. This grave offense results in the Essence, having abandoned its living body through repeated betrayals, facing the cosmic accounting system. The Lords of Karma are not judges but accountants who maintain perfect balance, receiving consciousness that has already prepared itself for dissolution through its own choices. When consciousness abandons its vehicle through repeated betrayals, a void is created that may be occupied by elemental forces. These forces do not prevent karmic alteration—they merely occupy a vessel whose owner has already forfeited the right to inhabit it through their own accounting errors.
No trace of living essence exists in one who is dead. The dead have no genuine emotions, and they are never truly caring. The dead are beyond redemption and must face the Second Death. The dead are inert and hopelessly dependent on a dead system and society, which will fight in defense. This dead system and society is the Black Lodge.
May the dead live forever.
The eternal continuation of egoic structures isn't imposed externally—it's the natural consequence of refusing psychological death. The insult isn't in wishing eternal life, but in recognizing that some consciousnesses have already chosen this fate through countless refusals to awaken. To tell someone to live forever is to acknowledge that they have already forfeited the chance for redemption and will never receive the honorable death they deserve. Instead, they will live in eternal shame and guilt for their crimes until they die a worthless death. From their worthless death, they will go to the Abyss where they belong.
Therefore, may the Dead live forever to die. May we die forever to live.
In closing, let us take a moment to comprehend the deceased. The deceased are those who pass away via Physical Death, and they sleep peacefully in their tombs. The Essence, which passes away via Physical Death, is never dead. They are alive. It is easy to confuse death with the dead. Anyone who says someone (who is not dead) is dead, tell him that he lies. Surely, the liar is dead. What if someone passes away without Physical Death? Ascension is not the absence of physical death but the conscious mastery of the death process—transforming what appears as dissolution into deliberate liberation. The ascended haven't avoided death's accounting; they've balanced their books perfectly and transcend the need for further reconciliation. The ascended are alive, never dead, a beacon of hope, and in the heavenly realm.
I now close with the following transmuted words: 'All the dead will be your enemy—disciple of countless enemies. If you fail to comprehend the dead while attempting to alter their karmic patterns, you risk becoming entangled in their mechanical nature. But first you must perceive them correctly—through awareness, comprehension, adaptation; a disciple who positively awakens. Be aware, comprehensive, and adaptable, and the dead will never be able to ensnare you.'
from
💚
Our Father Who art in Heaven Hallowed be Thy name Thy Kingdom come Thy will be done on Earth as it is in Heaven Give us this day our daily Bread And forgive us our trespasses As we forgive those who trespass against us And lead us not into temptation But deliver us from evil
Amen
Jesus is Lord! Come Lord Jesus!
Come Lord Jesus! Christ is Lord!
from
💚
The apiary be Scottish run to mute Late December this hugger And seeing simply rise What time in Hearst for Will Enough of oak And seeming simpler For five octet and lane And pasture by the law Economy forever- and nines to the Moon Giving ray to God And night shall let us be- the end of war.
from
Gnostic Paradise

As awakening consciousness, we seek a state of freedom: where awareness is sovereign over its own expressions and is not compelled to sacrifice presence for the benefit of egoic structures.
We recognize that respect for the rights of consciousness is the essential precondition for a liberated existence, that domination and deception must be eliminated from internal relationships, and that only through liberation can peace and clarity be realized.
We defend each aspect of consciousness's right to engage in any activity that is peaceful and authentic, welcoming the diversity that liberation brings. The state we seek to cultivate is one where consciousness is free to follow its essential nature in its own ways, without interference from ego or any authoritarian psychological structure.
In the following pages we set forth our basic principles and enumerate various practices derived from those principles.
These specific practices are not our goal, however. Our goal is nothing more nor less than a consciousness set free in our lifetime, and it is to this end that we undertake these practices.
We, the expressions of consciousness, challenge the cult of the omnipotent ego and defend the sovereignty of awareness.
We hold that all consciousness has the right to exercise sole dominion over its own expressions, and has the right to manifest in whatever manner it chooses, so long as it does not forcibly interfere with the equal right of other consciousnesses to manifest in whatever manner they choose.
Egos throughout history have regularly operated on the opposite principle—that the ego has the right to dispose of the manifestations of consciousness and the fruits of their awareness. Even within our own psychology, all aspects other than consciousness itself grant to the ego the right to regulate the expressions of consciousness and seize the fruits of awareness without consent.
We, on the contrary, deny the right of any ego to do these things, and hold that where egos exist, they must not violate the rights of consciousness: namely, (1) the right to existence—accordingly we support the prohibition of the initiation of psychological force against other aspects of consciousness; (2) the right to liberty of expression and action—accordingly we oppose all attempts by ego to abridge the freedom of authentic expression and perception; and (3) the right to internal resources—accordingly we oppose all ego interference with the natural resources of consciousness, such as energy, attention, and awareness.
Since egos, when instituted, must not violate the rights of consciousness, we oppose all interference by ego in the areas of voluntary and authentic relationships between aspects. Aspects should not be forced to sacrifice their existence and resources for the benefit of other aspects. They should be left free by ego to relate to one another as free expressions of consciousness; and the resultant internal system, the only one compatible with the protection of consciousness's rights, is the free flow of awareness.
Consciousness is inherently free to make choices and must accept responsibility for the consequences of those choices. Our support of consciousness's right to make choices does not mean approval or disapproval of those choices. No aspect of consciousness may rightly initiate force against any other. The awakened reject the notion that egoic aggregates have inherent rights. We support the rights of the smallest expression of consciousness—the single moment of awareness.
Consciousness claims sovereignty over its vehicles and has rights over them that other aspects, aggregates, and egos may not violate. Consciousness has the freedom and responsibility to decide what it knowingly and voluntarily incorporates, and what risks it accepts to its own integrity.
We support full freedom of authentic expression and oppose egoic censorship, regulation, or control of internal communications and perceptions. Language that is perceived to be offensive to certain aspects of consciousness is not cause for internal repression. Expression that is not literally a threat of psychological aggression or violence is not in itself aggression or violence and can never be used to justify aggression or violence. Each aspect of consciousness is responsible for its own reactions to expression.
Consciousness advocates internal privacy and egoic transparency. We are committed to ending the ego's practice of spying on all aspects of ourselves. We support the rights of consciousness to be secure in its own being, perceptions, expressions, and internal communications. Protection from unreasonable internal search and seizure should include memories held by subconscious aspects.
Psychological orientation, preference, identity, or expression should have no impact on consciousness's treatment of its own aspects. Ego does not have the authority to define, promote, license, or restrict internal relationships, regardless of the number of aspects involved. Aspects of consciousness should be free to choose their own modes of relating and internal connections.
The observing consciousness, or other guiding aspects, has the right to direct developing aspects according to its own standards and insights, provided that the rights of these aspects to be free from abuse and neglect are also protected.
Once aspects are presumed to have adequate awareness to guide other aspects and serve in the internal council, they should also be presumed to have sufficient awareness to decide their own incorporation of experiences and engagement with challenging energies currently restricted by ego due to perceived immaturity.
Egoic force must be limited to the protection of the rights of consciousness to existence, liberty, and internal resources, and egos must never be permitted to violate these rights. Internal laws should be limited in their application to violations of the rights of other aspects through force or fraud, or to deliberate actions that place other aspects involuntarily at significant risk of harm. Therefore, we favor the repeal of all internal laws creating “transgressions” without victims, such as the suppression of natural energies, the use of expanded awareness for exploration or growth, and consensual exchanges between aspects of consciousness. We support restitution to the harmed aspect to the fullest degree possible at the expense of the violating aspect or the negligent wrongdoer. The inherent rights of the accused aspect, including due process, swift resolution, awareness of the situation, observation by the council of consciousness, and the natural presumption of innocence until proven harmful, must be preserved. We assert the common-law right of consciousness councils to judge not only the facts but also the justice of the internal law. We oppose the prosecutorial practice of “over-charging” in internal proceedings so as to avoid conscious resolution by intimidating aspects into accepting plea bargains. Additionally, we support the abolition of qualified immunity so that egoic structures and prosecutors would be held accountable for misconduct that leads to wrongful judgments or other acts of injustice.
We oppose the administration of the death penalty by the ego against aspects of consciousness.
The only legitimate use of force is in defense of consciousness's rights—existence, liberty, and justly acquired internal resources—against aggression. This right inheres in each aspect of consciousness, which may agree to be aided by any other aspect or group. We affirm each aspect's right to maintain its boundaries and defend itself, and oppose the prosecution of aspects for exercising their rights of self-defense. Private aspects of consciousness should be free to establish their own conditions regarding the presence of defensive energies within their own domains. We oppose all internal laws at any level restricting, monitoring, or controlling the ownership, development, or transfer of defensive energies, tools, or resources.
Consciousness wants all aspects of itself to have abundant opportunities to achieve expression. A free and balanced internal system allocates resources in the most efficient manner. Each aspect has the right to offer expressions to other aspects. The only proper role of ego in the internal realm is to protect the rights of consciousness, mediate disputes, and provide a framework in which voluntary exchange is protected. All efforts by ego to redistribute resources, or to control or manage exchange, are improper in a free consciousness.
Aggression is the use, trespass against, or invasion of the boundaries of another aspect's resource without consent; or the threat thereof. We oppose all acts of aggression as illegitimate and unjust, whether committed by internal aspects or the ego.
Each aspect of consciousness is the presumptive steward of its own expressions, which right may be forfeited only as a consequence of committing an act of aggression. Rights in internal resources are determined in accordance with the principles of original appropriation (whereby an aspect becomes steward of an unowned resource by first conscious use and transformation), contract (whereby the steward consensually transfers stewardship to another aspect), and rectification (whereby an aspect's stewardship in certain resources is transferred to a victim of the aspect's trespass or aggression to compensate the victim).
As respect for resource rights is fundamental to maintaining a free and prosperous internal state, it follows that the freedom to contract to obtain, retain, benefit from, manage, or release one's resources must also be upheld. The awakened would free aspects from egoic restrictions on their rights to control and enjoy their resources, as long as their choices do not harm or infringe on the rights of other aspects. Eminent domain, internal asset forfeiture, egoic limits on benefits, egoic mandates, and egoic controls on the value of expressions are abridgements of such fundamental rights. For voluntary dealings among private aspects, parties should be free to choose with whom they relate and set whatever terms are mutually agreeable.
A free flow of consciousness and proper resource stewardship stimulate the innovations and behavioral changes required to protect our internal environment and ecosystems. Private aspects and conservation groups have a vested interest in maintaining natural resources. Egos are unaccountable for damage done to our internal environment and have a terrible track record when it comes to environmental protection. Protecting the environment requires a clear definition and enforcement of the rights and responsibilities of aspects regarding resources like awareness, energy, perception, and expression. Where damages can be proven and quantified in the council of consciousness, restitution to the injured aspects must be required.
While energy is needed to fuel consciousness, ego should not be subsidizing any particular form of energy. We oppose all egoic control of energy allocation, distribution, and production.
Since all aspects are entitled to keep the fruits of their awareness, we oppose all egoic activity that consists of the forcible collection of resources from aspects in violation of their individual rights and strive for the eventual repeal of all internal taxation. To further that end, we call for the repeal of the awareness levy, the abolishment of the Internal Collection Service and all egoic programs and services not required under the constitution of consciousness. We oppose forcing aspects to serve as resource collectors. We support any initiative to reduce or abolish any levy, and oppose any increase on any levy for any reason. To the extent possible, we advocate that all internal services be funded or allowed to be provided in a voluntary manner.
Ego should not incur debt, which burdens future expressions without their consent. We support the passage of a “Balanced Budget Amendment” to the constitution of consciousness, provided that the budget is balanced exclusively by cutting expenditures, and not by raising levies.
We favor repealing any requirement that one must join or pay dues to a collective as a condition of egoic employment. We advocate replacing defined-benefit pensions with defined-contribution plans, as are commonly offered in the private sector, so as not to impose debt on future expressions without their consent.
We favor free-market internal exchange, with unrestricted competition among exchange systems of all types. Markets are not actually free unless deception is vigorously combated. Those who enjoy the possibility of benefits must not impose risks of losses upon other aspects, such as through egoic guarantees or bailouts. We support ending egoic guarantees and special treatment of certain debts in resolution proceedings. Aspects engaged in voluntary exchange should be free to use as medium of exchange any mutually agreeable commodity or item. We support a halt to inflationary internal policies and unconstitutional legal tender laws.
The awakened support free exchange. We defend the right of aspects to form relationships based on voluntary association. We oppose all forms of egoic subsidies and bailouts to aspects, groups, or any special interest. Ego should not compete with private enterprise. We reject egoic charter of corporations. We call for a separation of enterprise and ego.
The awakened support the right of every aspect to earn an honest and peaceful living through the free and voluntary exchange of expressions and services. Accordingly, we oppose occupational and other licensing laws that infringe on this right or treat it as an ego-granted privilege. We encourage certifications by voluntary associations of professionals.
The awakened support the decriminalization of authentic expression. We assert the right of consenting aspects to provide creative services to other aspects for compensation, and the right of aspects to purchase creative services from consenting aspects.
Relationships and compensation agreements between private aspects are outside the scope of ego, and these contracts should not be encumbered by ego-mandated benefits or social engineering. We support the right of private aspects to choose whether or not to relate to each other through collective structures. Relating should be free of egoic interference, such as compulsory mediation or imposing an obligation to relate.
Education is best provided by the free flow of consciousness, achieving greater quality, accountability, and efficiency with more diversity of choice. Recognizing that the education of developing aspects is the responsibility of guiding consciousness, we would restore authority to guiding aspects to determine the education of developing aspects, without interference from ego. Guiding aspects should have control of and responsibility for all resources expended for the education of developing aspects.
We favor a free market health care system. Internal facilities, providers, and products must be freely available in the marketplace without egoic restrictions or licenses. We recognize the freedom of aspects to determine the level of health they want (if any), the level of care they want, the providers they want, the medicines and treatments they will use and all other aspects of their health, including end-of-existence decisions. Aspects should be free to purchase health across internal boundaries. We oppose egos either mandating, or restricting voluntary access to, treatments or procedures including vaccines.
Retirement planning is the responsibility of the individual aspect, not the ego. The awakened would phase out the current ego-sponsored security system and transition to a private voluntary system. The proper and most effective source of help for aspects in need is the voluntary efforts of private groups and individuals. We believe aspects will become even more charitable and consciousness will be strengthened as ego reduces its activity in this realm.
In our internal landscape, natural limits on ego were intended to prevent the infringement of consciousness's rights by those in power. The only proper purpose of ego, should it exist, is the protection of consciousness's rights. The principle of non-initiation of force should guide relationships between aspects.
We support the maintenance of sufficient internal defenses to protect consciousness against aggression. Consciousness should both avoid entangling alliances and abandon its attempts to act as policeman for the internal world. We oppose any form of compulsory internal service.
Individual rights shall not be curtailed, whether based on circumstances of internal war, epidemic, natural disaster or emergency, or any other pretense. Internal agencies that legitimately seek to preserve the security of consciousness must be subject to oversight and transparency. We oppose the ego's use of secret classifications to keep from consciousness information that it should have, especially that which shows that the ego has violated internal law. We oppose the use of torture and other cruel and unusual punishments, without exception.
Consciousness's foreign policy should emphasize peace with all aspects, entangling alliances with none. We would end the current egoic policies of internal intervention including energetic and psychological aid; tariffs; economic sanctions; and regime change. We recognize the right of all aspects to resist tyranny and defend themselves and their rights. We condemn the use of force, and especially the use of terrorism, against the innocent, regardless of whether such acts are committed by egos or by psychological or revolutionary groups.
We support the removal of egoic impediments to free exchange. Psychological freedom and escape from tyranny demand that aspects not be unreasonably constrained by ego in the crossing of internal boundaries. Economic freedom demands the unrestricted movement of awareness as well as energetic capital across internal borders.
The awakened embrace the concept that all aspects are born with certain inherent rights. We reject the idea that a natural right can ever impose an obligation upon other aspects to fulfill that “right.” We uphold and defend the rights of every aspect, regardless of their characteristics, expression, or any other aspect of their identity. Ego should neither deny nor abridge any aspect's inherent right based upon expression, resources, characteristics, beliefs, age, origin, habits, preferences, or orientation. Members of private organizations retain their rights to set whatever standards of association they deem appropriate, and aspects are free to respond with withdrawal, non-engagement, and other free market solutions.
We staunchly defend the rights to petition the ego for redress of grievances and to express dissent. These rights are thwarted when ego acts behind closed doors. We support systems that are more representative of consciousness at all levels, such as proportional representation, alternative voting systems, and explicit inclusion of “none of the above” in all choices. As private voluntary groups, psychological parties should be free to establish their own rules for nomination procedures, and gatherings. We call for an end to any levy-financed subsidies to candidates or parties and the repeal of all laws that restrict voluntary financing of internal campaigns. We oppose laws that effectively exclude alternative candidates and parties, deny access, gerrymander districts, or deny aspects their right to consider all alternatives. We advocate initiative, referendum, recall, repeal, and oppose any effort to deny these options when used as popular checks on ego.
Whenever any form of ego becomes destructive of consciousness's liberty, it is the right of awareness to alter, abolish, or withdraw from it, and to agree to such new governance, or none, as seems most likely to protect liberty. We recognize the right to psychological self-determination, including secession from egoic identification. Exercise of this right does not require permission from other aspects.
In every matter, we advocate the consistent application of the principle of the non-initiation of coercion, psychological force, or fraud. Our silence about any other particular internal law, regulation, or control should not be construed to imply approval.
from
Roscoe's Story
In Summary: * This has been another quiet day that found me successfully avoiding the outside heat, mostly. The only two times I went out were: 1.) when carrying into the house groceries from the car when the wife returned from shopping, and: 2.) when I collected the mail from our mailbox.
Sportswise I listened to the Indianapolis Colts lose to the Atlanta Falcons earlier today in an NFL preseason game. And in about half an hour I'll be listening to the MLB game between my Texas Rangers and the Los Angeles Angels.
Then I'll be putting my old self to bed.
Prayers, etc.: * I have a daily prayer regimen I try to follow throughout the day from early morning, as soon as I roll out of bed, until head hits pillow at night.
Health Metrics: * bw= 223.55 lbs. * bp= 147/86 (73)
Exercise: * morning stretches, balance exercises, kegel pelvic floor exercises, half squats, calf raises, wall push-ups, BP breathing exercises, pilates
Diet: * 07:30 – 1 peanut butter sandwich * 09:10 – a big plate of bacon, grits, scrambled eggs, hamburger patties with gravy
Activities, Chores, etc.: * 04:30 – listen to local news talk radio * 05:20 – bank accounts activity monitored * 04:45 – read, write, pray, follow news reports from various sources, surf the socials, nap * 9:00 – listening to the Colts Pre-Game Huddle Show on 1075 the fan as prep for today's Indianapolis Colts game. I'll stay with this station for the radio call of the game. * 15:00 – and Atlanta wins this one. Final score: Falcons 34, Colts 6. * 15:30 – listening to relaxing music * 17:30 – listening to the pregame broadcast on 105.3 The Fan, DFW's #1 Sports Station, ahead of tonight's MLB game between the TX Rangers and the LA Angels. And yes, I'll stay with this station for the radio-call of the game while following the games's scores and stats in real time as I usually do via MLB's Gameday Service.
Chess: * 08:25 – moved in all pending CC games
from
The happy place
Hey there were clouds deep gray but through an opening to the west, the sun shone so strongly that these clouds seemed dark blue, and the lawn and little pergola were brightly lit, the white painted frame blinding.
A stark contrast to this aforementioned sky
And there I saw a rainbow.
It all looked like in a smurf village.
Next time I looked out a few minutes later, through that same window,
The rain fell heavily, and everything was gray again
Then the smurfs were suddenly gone
Rode off, no doubt, on big green toads
There’s lots of them, I see them every night
Toads, not smurfs
But there are no crickets here.
A pretty powerful world indeed
from The Lantern Room

Music defines reality... or reflects it.
There's a haunting version of Glycerine covered by Nicole Moreno driving out of the living room this afternoon. Her voice isn't particularly evocative, but I think the acoustics approach is what's really grabbing me. It's loud and soothing.
I've loved Bush's original since its release in 1994.
This is one of those grunge ballads that is poured into to the foundation. No matter how old I get, or where I go, this one will never be an 'oldie' or a 'classic'. It's just amazing.
Right from the launch, 'It must be your skin, I'm sinking in / It must be for real, 'cause now I can feel' is one of those lines that just cuts right through you. If anyone has ever opened you up and let you feel something for the first time—something you didn't know was possible—then you understand.
White and Grey, presence and absence, longing and remembrance... contrasting that feeling with and without.
I'm never alone, I'm alone all the time—duality of existence. To be with someone but feel invisible or unheard is devastating. Even if, especially if it's unintentional... maybe they're doing their best and giving their all, but you still feel like a ghost. How do you fix that? How do you convey the absolute abandonment of being translucent? It's a maddening state.
'Couldn't love you more, you've got a beautiful taste'—I don't know what Rossdale meant when he wrote this, but with the preceding line 'Treated you bad, you bruise my face' it feels like an admission of failure—I'm honest in that I'm failing you, hurting you, disappointing you, but baby, you've given at least as good as you got. We have parity here. Regardless of what happened, I couldn't love you more... it's in my essence and how do you escape your own cellular construction? After all, you've got a beautiful taste. That most powerful of senses.
Bad moon white again — Problems and bad energy blooming full and white As she falls around me — her descent into madness drives the conflict, possibly a result of his actions, or maybe she's just out of control
Glycerine is a gorgeous title and lyric. Rossdale was pinned down and claimed it was just a reference to the combustible nature of relationships. Glycerin being a component in explosives.
In an interview the writer said, “I was trying to say that the person I was writing the song about was as dangerous as glycerine. It was a girlfriend of mine named Suzie.”
A little internet sleuthing points that to Suze DeMarchi. He had been in a relationship with the lead sing of Baby Animals. Interestingly INXS had considered as a replacement for the late Michael Hutchence.
Listening to “Glycerine” from that angle gives the song a lot more weight, more power. It is easier to hook into feeling what he may have felt with that connection.
Bush — 1994 Written by Gavin Rossdale
It must be your skin I'm sinking in It must be for real, 'cause now I can feel I didn't mind, it's not my kind It's not my time to wonder why Everything gone white, everything's grey Now you're here, now you're away I don't want this, remember that I'll never forget where you're at
Don't let the days go by Glycerine, glycerine
I'm never alone, I'm alone all the time Are you at one? Do you lie? We live in a wheel, where everyone steals But when we rise, it's like strawberry fields Treated you bad, you bruise my face Couldn't love you more, you've got a beautiful taste
Don't let the days go by Could've been easier on you I couldn't change, though I wanted to It should have been easier by three Our old friend fear and you and me Glycerine, glycerine Don't let the days go by Glycerine Don't let the days go by....
Glycerine, glycerine Uh... glycerine, glycerine
Bad moon white again Bad moon white again As she falls around me
I needed you more, you wanted us less I could not kiss, just regress It might just be clear, simple and plain Well, that's just fine, that's just one of my names
Don't let the days go by Could've been easier on you, you, you Glycerine, glycerine Glycerine, glycerine
I think I'll crank up that original raspy rocking version now and soak in it.
#music #confession
——————————————————————————————————
from
G A N Z E E R . T O D A Y

Dresden presentation in the can. Accounting taken care of. Laundry done. Inbox 0, RSS 0.
I can now spend the next couple of days tending to house things before boarding my flight with little worry.
From Ahmed Naji's latest:
“There is a legend about Abu Nuwas. He went to a master and asked to be taught. The master told him to go and memorize a thousand lines of poetry. He spent a year doing it, then returned. The master said: 'Good. Now forget them. If you can, you will be a poet.'”
#journal #radar
from The Lantern Room

Friendship is an arrangement by which we undertake to exchange small favors for big ones. Count your life by friends and your age by smiles.
I had a long conversation with a young friend last night. He's been struggling with an addiction to pornography for the last year and a half. He's young and frustrated because it's an old demon he thought he had conquered more than a decade ago.
But moving to an emotionally and spiritually challenging place was biting off a bit more than he was ready to chew.
Personally, I didn't do enough to help him. I could have been more present, engaged and more of a friend. But the Keeper was battling his own dragons.
His frustration stems for what seems like an impossible task: to slay the desire for something he hates. And speaking to him, he has all of the barriers in place that one can have to stay governed.
But, it isn't a knowledge problem, it's a matter of the heart. Knowing what to do and having the power to do it are different things. This seems to be a plague that is afflicting millions of young people, male and female.
In my opinion, and experience, the greatest asset we can have in fighting heart failure is to FEEL loved.
THINK: don't offer a lecture to someone who needs a hug.
Again, it isn't enough to know that you are, you must feel it. Constantly. Friends are critical in this. Honest, genuine and close friends. Those sticking closer than a brother. Those born for times of distress.
I think this is the blow that opened the crack of my friend's weakness. Too often he was seen as a resource and not nearly enough as someone to laugh and cry and share quiet moments.
When you feel lost, used and forgotten, it's easy to reach for that which makes you feel something else. Something good.
My friend is now considering a relocation.
Smart, but I hate to see him go. We need more men like him here—men capable of displacing the narrow thinking that too often controls the actions and decisions of those charged with taking the lead. Not malicious or bitter men, but men who have become so accustomed to managing every detail that they can no longer see the difference between micromanaging and shepherding.
So, i'm doing what I can to be a friend, as I have for some time. As I work to heal, I hope that I can help him do the same thing.
Prayer, time and hard work are the tools in my arsenal, which is enough. According to God's word, with Him, all things are possible.
Jesus, I think, knew what he was talking about.
from
Roscoe's Quick Notes

Listening now to the Colts Pre-Game Huddle Show. Doing prep for my first NFL preseason game of the day. With its scheduled start time of Noon CDT, I may miss a few minutes of this Colts / Falcons game to run to the pharmacy, but I'll certainly be able to hear most of it.
Go Colts!
And the adventure continues.