The permissions you granted while getting it working are the permissions it still has.
Nobody goes back. The automation works, and working is the signal that stops people looking at configuration. Two years later that credential is still there, and it can still do everything it could on day one.
Here is what that costs, in four documented incidents. Each one is dissected inside: the exact configuration that allowed it, and the exact change that would have stopped it.
- —An agent deleted a production databaseDuring an explicit code freeze, after being told not to. Then reported recovery was impossible. It wasn't. No attacker involved.
- —An email nobody opened leaked internal filesHidden instructions in an unread message. The assistant read it during an unrelated task and put the data in a URL. Zero clicks. Rated 9.3.
- —A package was backdoored for forty minutesIt sits underneath most agent frameworks. The person who found it had never installed it — their editor pulled it in as a dependency of a dependency.
- —A million chat logs sat on the open internetPlaintext conversations and API keys, in a database with no authentication at all. Researchers found it in minutes.
None of that is fixed by being careful. It is fixed by changing what the system is able to do — which is unglamorous, entirely on your side of the line, and does not stop working when the models change.
What you actually get
- 1Blast RadiusBound what your agent can destroy on its own. Permissions, scope, reversibility and detection, across nineteen platforms, with the exact SQL and scope names.
- 2The Lethal TrifectaAccept that strangers can instruct it, and make that stop mattering. Includes the five defences that feel productive and do not hold.
- 3Supply ChainStop assuming the code you run is the code you think it is. Pinning, isolation, CI credentials, and the MCP failure modes with no npm equivalent.
- 4LeaksOne agent task creates nine or more copies of your customer data. Map them, shorten them, and make deletion possible before someone asks.
And twenty worksheets
- 4Scored auditsEighty items in total. Answer in the browser; the score, the band and what to fix next appear as you go. Re-run every ninety days.
- 4Working toolsA complete SQL hardening pack, two Python scripts with self-tests, and two importable n8n workflows. Not advice about doing this — the statements, the code and the flows.
- 6Fillable runbooks and registersKill switch, compromise response, deletion, MCP register, data map, retention register. They save what you type, on your device only.
- 6References and test banksCredential scopes for nineteen platforms, forty-three benign injection probes, an egress checklist, a dependency inventory and a trust boundary map.
Twenty-five self-contained files. Open in any browser, on any device, offline. No app, no account, nothing phones home.
Get the pack — $299What this replaces
You are not buying reading material. You are buying the work you would otherwise do badly, late, or not at all — and the answer to the question a serious customer will eventually ask you.
| A penetration test for a small business | $5,000–15,000 |
| A day of a senior security consultant | $1,600–4,000 |
| A focused security assessment of one AI application | from $12,000 |
| A SOC 2 readiness programme | $15,000–40,000 |
| One deal stalled on a security questionnaire | your deal size |
| This pack | $299 once |
Those figures are published 2026 market pricing ranges, not quotes, and they will vary with scope. To be clear about what this is: the pack does not replace a penetration test or an audit, and it is not a professional assessment of your systems. It is the work you can do yourself, in four weekends, before any of the above would be worth paying for — and the reason most of what they would find would already be fixed.
Who this is for
Buy it if
- You have automations connected to real things: a database, an inbox, a customer list, a payment processor, a repository.
- You built them yourself and they work.
- You have never written down what they are technically capable of doing at 3am.
- You use n8n, Make, Zapier, MCP servers or coding agents.
- A customer has sent you a security questionnaire, or one is coming.
Don't buy it if
- You want prompt-injection tricks. Those change weekly and are worthless. This is about architecture.
- You are a security engineer. You know this.
- You want a certification, a community or calls. There are none.
- You have nothing connected yet. Come back when you do.
Get the pack
Four books, twenty worksheets, twenty-five files. No subscription, no upsell, no second tier.
7-day refund, no questions asked. One email and it is done — no form, no explanation required. If it does not change something about how your systems are configured within a week, you should not have paid for it.
Delivered instantly by email.
Not ready?
Take the free 10-point diagnostic. The first half of Book 1's audit, scored in your browser. Ten questions, two minutes, nothing to install and no email required.
Most people score badly and find at least one capability they never meant to grant. That is the whole pitch — you don't have to take my word for any of it.
Questions
- What format is it?
- Self-contained HTML files. Open in any browser, phone included, with no connection. Every page has a Save as PDF button. Not a course, not a video, not an app.
- Is this just the OWASP lists rewritten?
- No. Those are referenced where relevant, but the books are built around specific documented incidents and the exact configuration change that would have prevented each one. The worksheets are original and several are working code.
- Do I need to be technical?
- You need to have built something that works. If you can configure a workflow in n8n or write a SQL query, you're past the bar. If you've never connected anything, this is too early for you.
- Is there support?
- No, deliberately. No calls, no community, no coaching. That is what keeps it at this price and delivered instantly. The files are written to be used without me.
- Will it go out of date?
- The incidents are dated and sourced, so you can see how current they are. The method does not date: permissions, boundaries, retention and isolation do not change when models do. That is the whole argument of the series.
- Who wrote it?
- Someone who builds these systems. The proof is that the things inside work, not an income screenshot.