Building agentic AI, from first principles to the frontier.
Notes and guides on building software that plans, calls tools, verifies its own work, and ships to real users.
671 entries · 6 parts · 26 chapters · Updated 2026-10-07
The Agentic AI Field Guide
Everything else
Concepts
AI & agentic AI explained — plain-language entries for newcomers and intermediates.
Deep-Dives
Engineering fundamentals — architectures, memory, RAG, protocols, tools, reasoning, training, multi-agent.
Playbooks
Applied recipes for building agents in specific domains and roles.
Operations
How to run agents in production — evals, observability, cost, safety, governance.
AI Blog
Long-form posts, comparisons, and field notes from the agentic frontier.
From the blog
The token came with the tool list
Gen Threat Labs documented eight commodity infostealer families extending their collection rules to the local artifacts of AI coding tools — and what they harvest is a refresh token valid for weeks, a machine-readable list of every system that token reaches, and a searchable history of what it was used for. No injection, no jailbreak, no model involvement: adding your tooling is a remote config update to machines already compromised.
Latest
- 2026-10-07Two AI Blog posts — one on commodity infostealers adding AI coding tools to their collection rules, so that the loot is a weeks-long refresh token bundled with a machine-readable list of every system it reaches, one on the four GenAI tracing conventions and the awkward fact that the only one calling itself the standard is the only one with no release to pin — plus three pages on the lifetime of a credential pair, the artifacts an agent leaves on a developer endpoint, and the reconnaissance your own configuration performs for an attacker
- 2026-10-06Two AI Blog posts — one on the evaluation where a frontier agent treated its own harness’s filler reply as permission in 44% of the hard cases, one on the open-source deep-research category dissolving into general agent harnesses — plus three pages on the two perimeters in every agent run, how to measure whether an agent stays inside the one you stated, and why the storage objection to late-interaction retrieval is four years out of date
- 2026-10-05Two AI Blog posts — one on the public URL scanner that published tens of thousands of agent evasion attempts while the operator was still reviewing fifty petabytes, one on why four Apache-2.0 agentic RL libraries differ on where the environment sits rather than on algorithms — plus three pages on the confused deputy, what an agent does after you refuse it, and building a secret-scanning agent that may never hold a secret