André Silva
andresilvalab.com
André Silva
@andresilvalab.com
AI agent security and observability: prompt injection, MCP servers, red teaming agents in production. Lab notes with data at andresilvalab.com. Based in Portugal.
Measured it: an LLM supervisor spends 69% of tokens on routing, not work. 3.23x amplification vs a state machine. Nobody in the biggest industry thread could show more than 6 agents in real production.
Multi-agent workflows in production: who is actually running thousands of agents (and who is pretending)
49 independent publications in three days say everyone wants multi-agent. The real question: when does it work, and how much does the supervisor cost that nobody measures.
andresilvalab.com
September 29, 2026 at 1:13 PM
Mapped OWASP's 10 agentic risks to a real stack. 7/10 have partial coverage. The 3 that don't need architecture, not config. 43% of MCP servers tested had command injection flaws.
OWASP Agentic Top 10 mapped to a real stack: what each ASI demands from those who run agents
I took the ten OWASP risks for agentic applications and mapped each one to a concrete piece of a production stack. The table, the incidents, and the config that is missing.
andresilvalab.com
September 28, 2026 at 7:44 PM