cybersecurity / AI agents / local tools

AI agents that do real work.
Without hidden surprises.

I’m Sean McQuilling. I build and test AI agents that work with real files and tools. I write about what works, what breaks, and how to keep the risks under control.

Main topic
Agent security
How I work
Build + test
Preference
Local first
trace_004.runverified

08:41:02 working folder confirmed

08:41:04 proposed change ready

08:41:07 final check passed

now / july 2026

Working on safer ways to give agents access to real tools.

Right now I’m testing access rules, jobs that can resume after a stop, and logs that show what the agent actually did.

Read the current note

how I work

Keep it clear.
Check the result.

An agent should have only the access it needs. Important actions should be obvious, and the final result should be checked instead of taken on faith.

01

Look before changing anything

Check the files, current state, and local instructions before making a change.

02

Limit access

Give the agent only the files and tools it needs for the current job.

03

Check the work

Run a test or inspect the result. Do not rely on the agent saying it worked.

recent writing

Notes and articles

Browse all notes

get in touch

Building something similar? I’d like to hear about it.

hello@seanmcquilling.com
~/

↑↓ move enter run help commands ⌘K toggle