
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>ApFramework</title>
      <link>https://apframework.com/blog</link>
      <description>Shoukai 技术博客，软件架构、AI、领域驱动、开源软件、阅读笔记</description>
      <language>zh</language>
      <managingEditor>huangshoukai@yeah.net (Shoukai Huang)</managingEditor>
      <webMaster>huangshoukai@yeah.net (Shoukai Huang)</webMaster>
      <lastBuildDate>Sat, 23 May 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://apframework.com/tags/architecture/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://apframework.com/blog/essay/2026-05-23-agent-security-2026</guid>
    <title>AI Agent 安全最佳实践 2026：从业界共识到工程落地</title>
    <link>https://apframework.com/blog/essay/2026-05-23-agent-security-2026</link>
    <description>2026 年的 AI Agent 安全，已经不能只靠 Prompt Guardrail。Agent 一旦具备工具调用、MCP、记忆、工作流编排和外部系统访问能力，本质上就是一个会行动的软件主体。本文从业界共识出发，拆解 Agent 的七层攻击面，归纳六个工程控制点，并给出业务服务+智能体服务的双层安全架构和落地要点。</description>
    <pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate>
    <author>huangshoukai@yeah.net (Shoukai Huang)</author>
    <category>AI Agent</category><category>Security</category><category>MCP</category><category>Agentic AI</category><category>OWASP</category><category>Architecture</category>
  </item>

    </channel>
  </rss>
