Last week in Agent Security Update 2: Zam-mad Max

Last week in Agent Security Update 2: Zam-mad Max

Last week I’ve been struggling with some kind of illness. My throat was dry and I couldn’t breathe on Friday, so I took a course of pseudoephedrine medication, bought some strepsils, and a nasal spray just to manage it. I was sick the whole weekend and started to recover just in time for Monday! Being an adult is awesome…. Now those of you who are a little too keen for our robot overlords to consume us might point out that agents don’t get sick, but they can be subject to a wide variety of vulnerabilities. Not the greatest segway into this weeks article, but I couldn’t think of anything else. ...

October 5, 2026 · 13 min · Will Velida
Running multiple GitHub Copilot agents in parallel with tmux

Last week in Agent Security Update 1: We are not-a-mused!

Last week I talked at NDC Oslo about the OWASP Top 10 for Agents where I showed folks the different ways that agents can be exploited. If you’ve turned the news on recently, you’ve probably heard about AI will kill us all and how we’re all doomed. Call me optimistic, but I think we’re currently in the middle of a hype cycle where AI labs are overstating the abilities of the models, and we’re at a point where we’ve seen how powerful agents can be, but we need to be more serious about the harms agents can do, and how we can mitigate those risks. ...

September 29, 2026 · 8 min · Will Velida
The Agent Plugins portable package layout: plugin.json, skills/, and mcp.json

What are Agent Plugins?

Implementing Agent Skills and MCP servers as part of my development workflow has been a huge boost to my productivity. Long gone are the days where I’d actually have to leave my IDE to raise a pull request in GitHub, and then manually add that PR to a Jira ticket that’s still impossible to find in 2026. Now it’s just a matter of me asking GitHub Copilot to create the PR using my create-pr Agent Skill, then use the Atlassian MCP Server to link the PR to the appropriate Jira ticket. All of which I can do without ever having to leave my IDE. ...

August 7, 2026 · 8 min · Will Velida
Multi-agent architecture: Chat.Api with Microsoft Agent Framework, Reporting.Api with GitHub Copilot SDK, connected via Entra Agent Identity.

Building a Multi-Agent System in .NET using the Microsoft Agent Framework, GitHub Copilot SDK, and Entra Agent ID

My side project (Biotrackr) started as a Fitbit data tracker and has gradually evolved into a full multi-agent system. Currently, it tracks my health data from Fitbit including sleep patterns, activity levels, food intake, and weight. I’ve recently built a chat agent that allows me to ask questions about my health data through the UI. However, I wanted to take this a step further and use another agent to build charts and graphs to visualize my data. ...

April 8, 2026 · 13 min · Will Velida
Migrating a .NET AI agent from function tools to MCP client integration, showing the architectural shift from duplicated HTTP tool classes to a single MCP Server.

From Function Tools to MCP: Migrating an AI Agent to the Model Context Protocol

When I first built an AI Agent for my personal health platform Biotrackr, I used the Microsoft Agent Framework’s function tool pattern with 12 tools decorated with [Description] attributes, registered via AIFunctionFactory.Create(). This wasn’t ideal as I already had an MCP Server exposing the same 12 tools to VS Code and other MCP clients. The natural approach would have been to make the Chat API another MCP client. But there was a blocker. The Anthropic provider in Microsoft Agent Framework (Microsoft.Agents.AI.Anthropic) didn’t support Local MCP Tools. If I wanted to use Claude as the LLM backend (which I did), function tools were the only option. So I duplicated all 12 tool implementations in the Chat API, complete with their own models, validation logic, and API call code. ...

March 22, 2026 · 16 min · Will Velida