New: Claude Code Security Benchmark v1.0

Tom Mooney / Agentic security

Secure the systems that can act.

Independent research and practical field notes for the people accountable for autonomous AI — written by security leader and Agentic AI Security author Tom Mooney.

7 layers

security model

15 yrs

security practice

Weekly

one useful brief

Explore the new benchmark
New publicationSecurity benchmark · 32 min read

Turn Claude Code hardening into an auditable standard.

An independent, CIS-style baseline for developer workstations and managed fleets. Every recommendation includes a rationale, operational impact, audit procedure, remediation steps, default value and authoritative references.

15

auditable controls

2

security profiles

26

official references

Read the benchmark

Benchmark contents

  1. 01Permissions & trust
  2. 02Sandbox & egress
  3. 03Secrets & credentials
  4. 04MCP & extensions
  5. 05Hooks & CI execution
  6. 06Telemetry & governance

Independent publication · not an official CIS Benchmark or Anthropic certification

02 / The threat model

Why agents change the security game.

01

An agent acts — it doesn’t just answer.

A manipulated chatbot writes a bad sentence. A manipulated agent executes a bad action — at machine speed, with real credentials. Autonomy is blast radius.

02

It’s a new attack surface.

Agents can be hijacked by instructions hidden in the data they read — an email, a doc, a ticket. No breach, no alert, no CVE.

03

Your existing stack wasn’t built for it.

Firewalls inspect traffic, IAM governs access, pentests check code. None of them ask what an autonomous actor will do under adversarial pressure.

Agentic AI Security book cover

03 / The book — Coming soon

The playbook, in print.

Agentic AI Security — threats, controls, and governance for autonomous systems. Written for both security leaders and the engineers shipping agents.

OWASP Agentic Top 10 · MITRE ATLAS · NIST AI RMF · ISO 42001 · EU AI Act

Free with the newsletter — be first to hear the publication date

Tom Mooney

04 / The author

Fifteen years at the sharp end of cloud, data & AI security.

Tom Mooney leads cloud, data and AI security for a global financial services group, after national-security architecture for the UK government and global cloud transformation at a leading technology firm. Executive MBA, University of Cambridge.

This site and Agentic AI Security are where that experience meets the new problem: controlling what autonomous systems are allowed to do.

The weekly field briefing

One useful brief.
No noise.

News, new attacks, and practical guidance for defending AI agents — written for security leaders and the engineers shipping them. Free, and the first three chapters of Agentic AI Security (draft) land in your inbox when you confirm your email.

NO SPAM. UNSUBSCRIBE ANYTIME.

  • First 3 chapters of the book, free
  • New threats & incidents
  • Defensive patterns & checklists
  • Tooling and research worth your time