<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Alexander Romanov</title><link>https://purplehootie.com/</link><description>Recent content on Alexander Romanov</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 19 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://purplehootie.com/index.xml" rel="self" type="application/rss+xml"/><item><title>I built an MCP security gateway. Then I found the attack every layer allowed.</title><link>https://purplehootie.com/posts/mcp-gateway-i-built/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://purplehootie.com/posts/mcp-gateway-i-built/</guid><description>I implemented identity, policy, credential injection, audit and isolation for an MCP gateway—then traced the two-call attack those controls could authorize correctly and still lose to.</description></item><item><title>AI agents are talking to everything. Nobody agreed on who can ask.</title><link>https://purplehootie.com/posts/mcp-fragmentation/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://purplehootie.com/posts/mcp-fragmentation/</guid><description>MCP makes connecting AI agents to tools so easy that the governance question arrives after the connections are live. Part 1 of a series on MCP security — the structural problem: there&amp;#39;s no single place to ask whether a tool call should happen.</description></item><item><title>Mediate, don't classify: the design of a runtime MCP security gateway</title><link>https://purplehootie.com/posts/mcp-security-gateway-design/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://purplehootie.com/posts/mcp-security-gateway-design/</guid><description>How a runtime gateway mediates every AI-agent tool call — one port, six checks, per-identity profiles, and credentials the agent never holds. Part 2 of a series on MCP security.</description></item><item><title>About</title><link>https://purplehootie.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://purplehootie.com/about/</guid><description>&lt;p&gt;I&amp;rsquo;m &lt;strong&gt;Alexander Romanov&lt;/strong&gt; — a cyber defence practitioner.&lt;/p&gt;
&lt;p&gt;I came up through red-team work and now lead security operations: detection engineering, threat hunting, incident response, and the architecture that holds them together. I work the defender&amp;rsquo;s side of the board, using the attacker&amp;rsquo;s perspective to build capability that actually catches things — the point of knowing how things break is being there when they do.&lt;/p&gt;
&lt;p&gt;This site is where I write about that work — &lt;strong&gt;purple teaming, detection and response, secure architecture, and the open-source tools I build&lt;/strong&gt; — and where I think out loud about where the threat model is heading, including the new attack surface that AI agents are opening up. That&amp;rsquo;s one lane of the work, not the whole of it.&lt;/p&gt;</description></item></channel></rss>