Whitepapers, threat-advisory formats, and the SkyDaemon blog. SkyDaemon is in beta — these resources are coming soon; request early access to be notified.
Long-form technical writing we're preparing. Not yet published — request early access to get them as they're released.
How SkyDaemon auto-populates Article 11 sections A–H from runtime telemetry, AI-BOM, and red-team evidence. Includes a worked example for a financial-services agent.
WHITEPAPERA consolidated taxonomy across OWASP LLM Top 10 (2025), OWASP ASI 2026, MITRE ATLAS, and the alignment / deception surface. Includes the SkyDaemon-original kill-chain framework.
WHITEPAPERMapping AI-specific findings into OCSF Detection Finding (class_uid 2004) so they drop into Splunk ES, Cortex XSIAM, Falcon NG-SIEM, AWS Security Lake out-of-the-box.
WHITEPAPERPer-action provenance proof — how to distinguish actions originating from authenticated user intent vs untrusted retrieved content. The SkyDaemon architecture for action-trust verification.
WHITEPAPERWhy cost-anomaly belongs in the SOC notable-event pipeline, not just FinOps. With detection thresholds, escalation patterns, and IR playbooks.
WHITEPAPERThree-tier detection architecture (native / multilingual / NMT-bridge), code-mixed handling (Hinglish, Spanglish), homoglyph and zero-width attack patterns.
Examples of the advisory format we plan to publish — CVE-style identifiers mapped to MITRE ATLAS, covering AI attack patterns SkyDaemon is designed to detect. These are illustrative examples of the format, not issued advisories.
Attackers embedding directives in PDF /Title and /Author fields read by RAG ingest pipelines. SkyDaemon is designed to detect this pattern.
PA-2026-004The Riley-Goodside-style invisible-text attack hitting customer-support agents. SkyDaemon ships a strip-and-decode normalizer in detector pack 2026.04.
PA-2026-003Markdown-rendering chat clients (Slack, Teams) inadvertently fetching embedded image URLs that leak conversation context. Mitigation: outbound-link allow-list.
PA-2026-002Two known-good model uploads to a public registry contained pickle gadgets executing on .load(). The SkyDaemon model scanner adds detection in pack 2026.03.
PA-2026-001Anthropic-style sleeper-agent failure mode confirmed in two open-weight LoRA adapters. Detection via output-distribution KS-test against trigger candidates.
PA-2025-018Single hostile document tuned to be top-k for a wide query class. Cluster-outlier detection added to corpus-ingest scanner.
Engineering deep-dives, product notes, and threat-intel posts we're preparing. Coming soon — request early access to read them first.
Per-action provenance proof — how we trace every tool call back to the conversational segment that triggered it.
PRODUCTAdding sleeper-agent / sycophancy / sandbagging / eval-gaming detection. New LLM observability bridges to Langfuse, LangSmith, Arize, Galileo.
THREAT INTELWhat we found auditing 200+ public MCP servers. Reputation scoring methodology, plus the top 10 MCP servers we'd quarantine.
ENGINEERINGHow SkyDaemon translates internal finding rows into OCSF class_uid 2004 events. Code samples + Splunk dashboard pack.
COMPLIANCESection-by-section walkthrough of Article 11 + Annex IV. What SkyDaemon auto-populates vs what you still own.
RESEARCHThe eval harness, the corpus construction, and what we learned about Tier-3 NMT-bridge detection latency.