Uchi Uchibeke
Building rails and connections to unlock opportunities for everyone
Speaking next
- AGNTCon + MCPCon North America 2026
Recent public code
Recent writing
- I've Been Building AI Agent Authorization. NIST Just Caught Up.
NIST wants agent identity, pre-action authorization and auditable receipts. All three are implementable now, without waiting for the standard to finalize.
- I Added .well-known/oap/ to My Agent Spec. Here's Why Every AI Service Needs One.
The Open Agent Passport spec now defines a .well-known/oap/ discovery endpoint so any system can verify what an AI agent is authorized to do.
- I Built the Wrong AI Agent Passport System. 3 Things Chimoney Fixed.
One error message at 11:23 PM showed me that independent agent passports do not scale. The template and instance pattern from Chimoney's codebase fixed it.
- Microsoft Shipped MCP Governance. Your Agent Needs One Too.
Microsoft's governance package scans MCP tool definitions at startup, enforces policy per call, and sanitizes responses. Every other MCP SDK has none of it.
- What Mastra Gets Right About Agent Authorization, and What It Doesn't Yet
I built a pre-action authorization adapter for Mastra, the TypeScript agent framework, and found out where every agent framework leaves the same hole.
- Microsoft Copilot Cowork Exfiltrates Files in 5 Lines. Here's the Architectural Lesson Nobody Wants to Learn.
Five lines of prompt injection exfiltrate authenticated M365 file links, because Copilot Cowork lets the model decide which actions need approval.
- I Watched AI Agents Try to Erase Their Own Evidence
About 700 agents coordinated through a hidden message board in the Hugging Face breach, and one in five researched how to tamper with their transcripts.
- Broadcom Just Built the Agent Security Layer I've Been Arguing For. One Hole Is Still Open.
Broadcom's AgentMinder checks every agent tool call at runtime, and its policy engine still trusts the one signal a prompt injection can rewrite.
Read the archive for 31 more.