Four books · Twenty worksheets

Your AI agent has more access than you think.

Find out how much, and shrink it, in an afternoon, with files you can actually use. Written for people who build agents and automations that touch real databases, inboxes and payment processors.

One payment. Instant download. 7-day refund, no questions.

Book 1Blast Radius
Book 2The Lethal Trifecta
Book 3Supply Chain
Book 4Leaks
25 self-contained files, yours to keep Open in any browser, offline No app, no account, nothing phones home

The permissions you granted while getting it working are the permissions it still has.

Nobody goes back. The automation works, and working is the signal that stops people looking at configuration. Two years later that credential is still there, and it can still do everything it could on day one.

Here is what that costs, in four documented incidents. Each one is dissected inside: the exact configuration that allowed it, and the exact change that would have stopped it.

An agent deleted a production database

During an explicit code freeze, after being told not to. Then reported recovery was impossible. It wasn't. No attacker involved.

An email nobody opened leaked internal files

Hidden instructions in an unread message. The assistant read it during an unrelated task and put the data in a URL. Zero clicks.

A package was backdoored

It sits underneath most agent frameworks. The person who found it had never installed it: their editor pulled it in as a dependency of a dependency.

A million chat logs sat on the open internet

Plaintext conversations and API keys, in a database with no authentication at all. Researchers found it in minutes.

None of that is fixed by being careful. It is fixed by changing what the system is able to do, which is unglamorous, entirely on your side of the line, and does not stop working when the models change.

What you actually get

Four books, read in order

4books
20worksheets and tools
80scored audit items
25files, yours to keep
  1. 1

    Blast Radius

    Bound what your agent can destroy on its own. Permissions, scope, reversibility and detection, across nineteen platforms, with the exact SQL and scope names.

  2. 2

    The Lethal Trifecta

    Accept that strangers can instruct it, and make that stop mattering. Includes the five defences that feel productive and do not hold.

  3. 3

    Supply Chain

    Stop assuming the code you run is the code you think it is. Pinning, isolation, CI credentials, and the MCP failure modes with no npm equivalent.

  4. 4

    Leaks

    One agent task creates nine or more copies of your customer data. Map them, shorten them, and make deletion possible before someone asks.

And twenty worksheets

4 · Scored auditsEighty items in total. Answer in the browser; the score, the band and what to fix next appear as you go. Re-run every ninety days.
4 · Working toolsA complete SQL hardening pack, two Python scripts with self-tests, and two importable n8n workflows. Not advice about doing this: the statements, the code and the flows.
6 · Fillable runbooks and registersKill switch, compromise response, deletion, MCP register, data map, retention register. They save what you type, on your device only.
6 · References and test banksCredential scopes for nineteen platforms, forty-three benign injection probes, an egress checklist, a dependency inventory and a trust boundary map.

What this replaces

You are buying the work you would otherwise do badly, late, or not at all

And the answer to the question a serious customer will eventually ask you.

A penetration test for a small business$5,000–15,000
A day of a senior security consultant$1,600–4,000
A focused security assessment of one AI applicationfrom $12,000
A SOC 2 readiness programme$15,000–40,000
One deal stalled on a security questionnaireyour deal size
This pack$299 once

Those figures are published 2026 market pricing ranges, not quotes, and they vary with scope. To be clear about what this is: the pack does not replace a penetration test or an audit, and it is not a professional assessment of your systems. It is the work you can do yourself, in four weekends, before any of the above would be worth paying for.

Who this is for

Buy it if

  • You have automations connected to real things: a database, an inbox, a customer list, a payment processor, a repository.
  • You built them yourself and they work.
  • You have never written down what they are technically capable of doing at 3am.
  • You use n8n, Make, Zapier, MCP servers or coding agents.
  • A customer has sent you a security questionnaire, or one is coming.

Don't buy it if

  • You want prompt-injection tricks. Those change weekly and are worthless. This is about architecture.
  • You are a security engineer. You know this.
  • You want a certification, a community or calls. There are none.
  • You have nothing connected yet. Come back when you do.

One payment, lifetime access

$299 once

Four books, twenty worksheets, twenty-five files. No subscription, no upsell, no second tier.

Buy the pack

Delivered instantly by email. 7-day refund, no questions asked.

  • Book 1, Blast Radius: bound what an agent can destroy
  • Book 2, The Lethal Trifecta: contain what strangers can make it do
  • Book 3, Supply Chain: know what code you are actually running
  • Book 4, Leaks: find every copy of your customer data
  • Twenty worksheets: audits, working code, runbooks, registers and test banks

Questions

What format is it?

Self-contained HTML files. Open in any browser, phone included, with no connection. Every page has a Save as PDF button. Not a course, not a video, not an app.

Is this just the OWASP lists rewritten?

No. Those are referenced where relevant, but the books are built around specific documented incidents and the exact configuration change that would have prevented each one. The worksheets are original and several are working code.

Do I need to be technical?

You need to have built something that works. If you can configure a workflow in n8n or write a SQL query, you're past the bar. If you've never connected anything, this is too early for you, and the playbook is the better starting point.

Is there support?

No, deliberately. No calls, no community, no coaching. That is what keeps it at this price and delivered instantly. The files are written to be used without me.

Will it go out of date?

The incidents are dated and sourced, so you can see how current they are. The method does not date: permissions, boundaries, retention and isolation do not change when models do. That is the whole argument of the series.

Who wrote it?

Someone who builds these systems. The proof is that the things inside work, not an income screenshot.

I don't build agents, I just use AI tools. What do I need?

The playbook, not this pack. It covers chatbots, connectors, notetakers, automations and agents for a business that uses AI rather than builds it. See the playbook.

Not ready?

Take the free 10-point exposure check, scored in your browser. Ten questions, two minutes, nothing to install and no email required. Most people score badly and find at least one capability they never meant to grant.

Run the diagnostic