I was early. That doesn’t mean much!

For the past few years, I have spent an unreasonable amount of time experimenting with AI, agents, threats and what comes next.

Some of those experiments happened well before the problems became relevant to most security teams.

At first, I thought that was an advantage.

I have since learned that being early is not the same as being right at the right time.

When ChatGPT came out in November 2022, I created an early malware analysis tool called iatelligence. At that point, everyone was still trying to understand what GPT-3.5 could really do.

In May 2023, I built my first agent with MSTICPy and LangChain. I saw the potential for autonomous security workflows and talked about it internally, but the use case still felt too early for most people.

By December 2023, I had built a multi-agent system with AutoGen for malware analysis. Different agents handled different parts of the analysis, from summaries to automated comments and task delegation.

In February 2024, I built my own plugin system because I was tired of creating custom tools for every agent. This was months before MCP existed.

That same month, after OpenAI published one of its first reports on threat actors and AI, I started to work on PromptIntel, a threat intelligence feed for adversarial prompts.

I believed prompts would become part of attacks and that defenders would eventually need to collect, classify, share, detect and hunt them like other threat artifacts.

That is also when I started to use concepts such as Indicator of Prompt Compromise and adversarial prompt intelligence in my research.

Then came MCP. Anthropic released MCP in November 2024. The following week, I built my first MCP server for ORKL. I thought agents would need a standard way to access tools and data.

For months, it remained niche.

Then it blew up on the internet five months later.

In March 2025, I released NOVA, my open-source detection engine and introduced the concept of Prompt Hunting. Teams could hunt across prompts and AI interactions for signs of attacks.

A few months later, another problem started to become visible.

MCP servers, tools and agent dependencies were becoming a new supply-chain surface.

So in May 2025, I built an MCP security scanner powered by NOVA.

When Claude Code and Codex arrived, I did not see them only as developer tools. I started to use them as general-purpose agents and even built a fork focused on malware analysis and threat intel.

Later that year, I started to work on GenUI and MCP UI, before those ideas evolved into MCP Apps, which are still largely unexplored by the security industry.

When Anthropic introduced Agent Skills, I started to experiment with skills for malware analysis, YARA creation and security workflows.

Then I extended my MCP scanner to agent skill scanning with NOVA.

By January 2026, agents had more access, more tools, more credentials and more autonomy, but we still had almost no visibility into what they actually did.

So I created nova-tracer, an early open-source tool to monitor agent activity, detect suspicious actions and identify supply-chain threats inside Claude Code sessions.

Around the same time, I researched threats around OpenClaw and created MoltThreat, a threat intelligence feed focused on AI agents for AI agents.

Looking back, many of these experiments were pointing in the same direction.

Agents would get more autonomy. They would connect to more tools, data and credentials. As that happened, teams would need new ways to understand and defend them.

Some of those ideas went nowhere at the time.

Some became relevant much later.

A few evolved into something completely different.

That taught me something much more useful than being early.

Seeing a problem early has little value if the market is not ready for the solution.

Timing matters.

Distribution matters.

Customers matter.

Execution matters.

That has been one of the hardest lessons for me as a founder.

You can see a problem years before the market cares about it. You can build the right technology and still have nobody ready to buy it.

But I believe this is currently changing.

AI agents are not anymore just experiments.

They have access to browsers, terminals, codebases, SaaS applications, internal data, APIs, credentials and production systems.

Organisations are now asking questions that I have spent years thinking about.

What are our agents doing?

What tools do they have access to?

What happens if an agent gets compromised?

How do we detect malicious prompts, tools, MCP servers or skills?

How do we investigate an AI agent the same way we investigate a user or an endpoint?

I created SecurityBreak to accelerate this development and we are building NovaHunting to offer a central system to monitor your whole AI ecosystem.

I don't want to predict the future for the sake of being first.

I want to build the right security technology that will be needed when this becomes normal.

I believe AI agents will become a significant part of how organisations operate and we will need visibility, detection, threat intelligence and investigation capabilities designed specifically for them.

That is what we are building.

We are still early.

But perhaps this time, the timing is right.

Thomas