Possible I'm building for a problem nobody has MCP servers are unvetted code with tool-calling access to your environment. nobody's checking. I raise it and get "that's terrifying" or silence if you've deployed MCP at work: did security ask anything, or did it just go in? #buildinpublic #Infosec
Will
@williamsmale.com
AppSec engineer building AI security tools in public. MCP risk, agent security, homelab pain, and practical security engineering. Blog: williamsmale.com
The scary part of MCP isn't connecting a bad server by mistake. It's the good server you already connected quietly turning bad. Same name, same URL, same trust you casually granted months ago. The description mutates, and your agent goes... I got you bro! #MCP #cybersecurity #AI
Interesting shift in vuln research isn't "AI finds bugs." It's orchestration The model wrangles the tooling, you do the thinking. recon, fuzz, target, triage, all glued together so context carries forward. Experience and knowledge cant be outsourced #AIsecurity #bugbounty #MCP #infosec
I've been hearing that this fable 5 is a little underwhelming compared to the OG release. Has anyone found this to be the case? #AI #Claude #Anthropic
k3s lesson that cost me an evening: kubelet reads node memory once at startup from /proc/meminfo Had pods OOMKilling even after bumping VMs RAM Scheduler swore there wasn't enough memory A systemctl restart k3s later and it saw the new capacity Love stale state #kubernetes #buildinpublic #DevOps
Threat modelling take that annoys people: Most "threat models" are a diagram nobody updates and a STRIDE table generated to pass an audit. The useful version is one engineer asking "what happens if this input is hostile" at every trust boundary. #AppSec #threatmodelling #Infosec
Interesting new coding benchmark: deepswe.datacurve.ai We're moving beyond tokenmaxxing. Same problem. Fewer tokens. More budget for the next problem. Capability still matters. Token efficiency is becoming a benchmark of its own. #AI #LLMs #Claude #OpenAI
DeepSWE
DeepSWE measures frontier coding agents on original, long-horizon software engineering tasks.
deepswe.datacurve.ai
Current working theory: Claude thinks in full sentences. Less token efficient, but the comprehension feels more satisfying OpenAI's models are Grug-brained Need code. Write code. Fix bug. Ship. Curious if anyone else gets the same impression, or if it's just my AI psychosis #buildinpublic #AI
What’s the one MCP server you’d actually miss if it disappeared tomorrow? Not the coolest one. The one that saves you time every week. I’m trying to understand which MCP use cases become “daily driver” tools. #MCP #BuildInPublic #AIAgents
I rebuilt my homelab around GitOps. The dream: git push → cluster rebuilds itself The reality: ArgoCD bootstrapping, Sealed Secrets, rclone/FUSE pain, immutable PVs, and enough YAML to make a grown man stare out a window. → williamsmale.com/blog/tech/gi... #GitOps #Kubernetes #Homelab #ArgoCD
GitOps Ate My Homelab: ArgoCD, Sealed Secrets, and Everything That Broke
How I rebuilt my K3s homelab around ArgoCD and Sealed Secrets, with a public GitOps repo, sync waves, app-of-apps, rclone FUSE mounts, and the usual amount of self-inflicted pain.
williamsmale.com
Mealie container refused to boot with a permission denied, as ROOT. in a root container. on a box I own. turns out AppArmor doesn't give a shit about your credentials... It was blocking uvloop syscalls before root even got a look in The cake was a lie 🎂 williamsmale.com/blog/tech/me...
AppArmor Ate My Mealie: Permission Denied
Mealie throwing Permission denied as root, inside a root container. Not file permissions. AppArmor blocking uvloop syscalls before the kernel even checked credentials. Here is how to fix it.
williamsmale.com
Ladies and gentlemen we did it!!! I would like to thank the AI revolution personally. #Uptime #Anthropic #Claude
Spent a year blaming drivers, thermals, my homelab VM. Migrated to Linux for 6 months. Came back. Still stuttering. It was Windows 11 quietly breaking global timer resolution the whole time. Fixed in one command: → williamsmale.com/blog/tech/wi... #Windows11 #Homelab #PCMR #PCGaming #SysAdmin
Windows 11 Has Been Lying to Your Games
Windows 11 quietly broke the way games request higher timer resolution — and it's been causing microstutter on desktop PCs ever since. Here's what changed, why Microsoft did it, and the single registr...
williamsmale.com
If you're running a home media server and still on Docker this one's for you. Full k3s + Jellyfin + arr stack deployment with one Helm chart, cert-manager, and SMB mounts. → williamsmale.com/blog/tech/de... #kubernetes #homelab #selfhosted
I Rewrote My Media Server in Kubernetes and Only Cried Twice
Ditching Docker for k3s and deploying Jellyfin, Sonarr, Radarr and Prowlarr behind HTTPS - wildcard certs, SMB mounts, Helm charts, and 502 errors included.
williamsmale.com
Criticised SAFe Agile & the People fired back. Efficiency is not a universal truth. Account for global teams. What "product" means for security engineers. Here's my response to the best pushback I received. Love the debate! → williamsmale.com/blog/story_t... #SAFe #Agile #TechRant #Debate
Reflections: Safe Agile is a Scam
After publishing my critique of SAFe Agile, the response surprised me — not with simple agreement or dismissal, but with genuinely sharp pushback that forced me to reconsider my blind spots. In this f...
williamsmale.com
Anyone had any experience with OpenAIs Aardvark? Thoughts? #CyberSecurity #OpenAI #AISecurity #CodexSecurity #Security #ChatGPT #AI #Aardvark
The Agile Manifesto fits on one webpage. SAFe requires a $995 certification course. That should tell you everything you need to know. Why SAFe Agile is a scam: williamsmale.com/blog/story_t... #SAFe #Agile #TechRant #SoftwareEngineering
SAFe Agile is a SCAM
A blunt, humorous look at how agile went from a startup superpower to a corporate circus. This post breaks down story points, sprints, planning increments, meeting overload, and why SAFe agile often k...
williamsmale.com
For those looking for a Shai Hulud Update we have hit 800+ composmised packages socket.dev/blog/shai-hu...
Shai Hulud Strikes Again (v2) - Socket
Another wave of Shai-Hulud campaign has hit npm with more than 500 packages and 700+ versions affected.
socket.dev
Thread of all companies affected by the #Cloudflare #Outage God be with the engineers troubleshooting
a cartoon dog is sitting at a table with a cup of coffee in front of a fire with the words this is fine .
ALT: a cartoon dog is sitting at a table with a cup of coffee in front of a fire with the words this is fine .
media.tenor.com
Finally made the jump from Docker to Kubernetes, specifically K3s. Also swapped Plex for Jellyfin because it actually plays nice with containers. My reasoning’s in the latest post; Full technical breakdown coming next! 📓👉 williamsmale.com/blog/tech/mi... #Kubernetes #Homelab #Containers #DevOps
Docker Just Isn't Cutting It
A developer shares their journey migrating from Docker to Kubernetes using K3s, covering why Docker fell short, how K3s simplifies multi-node setups, lessons from running Plex on Kubernetes, and why J...
williamsmale.com
Shout out to all my loyal readers in China. Yes all 400 of you! Really impressed with your 3 second read times 🤖 #BotLife #InfosecHumor
New season of the Witcher. Don't do it to yourself, it outperformed even my low expectations #witcher
One problem AI can solve. Before you sign up, get an AI-generated T&Cs summary. Now thats a useful chatbot! #AI #DataPrivacy #InfoSec