Enterprise AI Guardrails: How to Build Policy Enforcement That Actually Works

The rapid adoption of Generative AI, which has evolved from experimentation to enterprise-wide use, has revealed a critical reality: most organizations have AI policies, but few enforce them effectively. Policies such as an AI acceptable…

MCP Security in AI Integration Protocols, Package Ecosystems, and External Tool Connections

The rapid adoption of Model Context Protocols (MCPs) and AI integration technologies that standardize communication between models and external systems has led to new security…

Continuous Monitoring: Security Visibility Across AI Systems and Pipelines

Introduction Artificial intelligence (AI) systems are rapidly becoming foundational infrastructure across many modern enterprise environments. Unlike traditional applications, these systems introduce dynamic execution paths, probabilistic…

VS Code Security Risk from Malicious Extensions and Remote Code Execution

Modern software engineering teams increasingly rely on Visual Studio (VS) Code as the primary development environment for cloud-native engineering, DevSecOps workflows, infrastructure-as-code (IaC), and AI-assisted…

What Is Vibe Coding? Meaning, Origins, and Use Cases

Introduction Software development is undergoing a significant transformation driven by large language models (LLMs), autonomous agents, and natural language interfaces. One notable paradigm in this…

Is Vibe Coding Safe? What You Need to Know About Vibe Coding Security

AI-assisted coding is becoming more widespread, with developers increasingly relying on large language models (LLMs) to perform a variety of tasks. This trend is often…

AI Supply Chain Risk: What Developer Data Reveals About the Real Threats

From code-generation assistants to autonomous development agents, AI systems are increasingly being embedded across the entire software lifecycle. As organizations integrate AI capabilities into development…
How-to guides

Harden the AI tools you already run

Step-by-step configuration guidance from Pluto Research for Claude, Copilot Studio and Codex.

  • Securing Claude Cowork: What Security Teams Actually Need to Know

    Claude Cowork is Anthropic’s autonomous desktop agent. Unlike a chatbot that responds to prompts, Cowork takes a goal, then independently reads files, writes code, browses…
  • Securing Claude Managed Agents: What You Need to Know Before Going to Production

    Claude Managed Agents is Anthropic’s hosted agent runtime – a platform where Claude runs autonomously in cloud containers with bash access, file I/O, web browsing,…
  • Securing Claude Tag: A Practical Hardening Guide

    Claude Tag’s security comes almost entirely from configuration – who can invoke it, what each channel and connected repo can reach, where its data can…
  • Securing Copilot Studio: A Practical Hardening Guide

    Copilot Studio has gone from “we’re experimenting” to “we have agents in production” in a lot of organizations – and the security work hasn’t kept…
  • Securing OpenAI Codex: What You Need to Know Before Rolling It Out

    Securing OpenAI Codex: What You Need to Know Before Rolling It Out The short version: OpenAI Codex is no longer a passive code-completion tool –…
  • Skills, Connectors, Plugins, Oh My: A Security Practitioner’s Map of the Claude Extension Ecosystem

    Three primitives, one trust radius. Skills, Connectors (MCP), and Plugins look like distinct architectural units but are effectively a bundle. A single plugin installation activates…