Blog
Writing published before Salmon, from Archipelo's earlier work on developer security posture management. It is kept as it was written and does not describe Execution Verification Infrastructure.
DevSPM: Unifying Vulnerability Detection and Creation-Origin Context in Software Security Application security platforms detect vulnerabilities in software artifacts. But when teams investigate risk, they must also understand how those artifacts were created. Connecting detection with development-origin context provides that missing perspective.
Why Moltbot Demonstrates Security Must Move Upstream—From Code to Actors Recent attention around autonomous AI assistants such as Moltbot (formerly known as Clawdbot, but renamed to OpenClaw) has surfaced important questions about security, memory, and agency in modern software systems. Moltbot’s design—persistent memory, broad tool access, delegated credentials, and autonomous execution—makes visible a class of risks that many organizations are only beginning to confront.
The OWASP Agentic Top 10 Risks and the Emergence of Developer Security Posture Management (DevSPM) The OWASP Top 10 for Agentic Applications (2026) marks a quiet but consequential shift in how modern software security risk is being defined. Rather than focusing primarily on code artifacts, infrastructure configuration, or isolated model outputs—the framework surfaces a structural visibility gap in today’s security stacks: the lack of continuous observability into developer and autonomous agent behavior as it unfolds across tools, identities, memory, delegation, and execution over time.
The Missing Control Plane in AI-Native Software Security Software security has historically begun after code exists: after commit, after build, after deploy. That assumption no longer holds.
Vibe Coding Without Vibe Collapse: Why AI-Augmented Software Development Needs a DevSPM Control Plane Vibe coding is now mainstream. The missing piece is not another model — it is identity, action visibility, and telemetry across human and AI development actors.
AI Security Has Two Perimeters: The Model and the Coder Hyperscalers lead model security because they control the research, training pipelines, and AI development environments.
As AI Agents Take Action, Execution History Becomes Foundational Infrastructure.
Salmon establishes cryptographically verifiable execution history and state lineage across humans, agents, and automation.