Skip to main content

Talks

Decks and deep dives on the engineering behind rfxn. Each talk ships with an overview, the key takeaways, and the original slide deck. The deck is the payload; the overview is the share-link.

Featured Talk · Engineering

Prompts to Pipelines v3: Five Model Generations Later

The foundational rework of the Claude Code harness talk. Three claims: the model is rented, the plumbing is shipping into the harness, and the discipline layer, standards, evidence, evals, enforcement, is the only part you own. Proven with 19 weeks and 28 releases of governance receipts.

45 min talk37 slidesView talk
Security||Ryan MacDonald

Project Blacklight: An Agentic Defense Layer for the Open-Source Linux Stack

The pitch from the Anthropic Built with Opus 4.7 x Cerebral Valley Hackathon. Six days, 296 commits, one scorched-earth pivot, and an agentic defense layer that uses what most operators already have: ModSecurity, Apache, iptables, and a shell script. Built on Opus 4.7 + Anthropic Managed Agents.

blacklightagenticclaudemanaged-agentslinux-securityhackathon
View talk
Engineering||Ryan MacDonald

Prompts to Pipelines v1.5: Stop Vibing, Start Engineering

The iterated version of the Claude Code harness talk. Five plagues of agentic development, four primitives (memory, hooks, subagents, settings) that fix them, and the fixtures to wire a CLAUDE.md, settings.json, and adversarial reviewer in an afternoon. The through-line: the model is capable, the instructions are the product.

claude-codeagenticharnessengineering-practicesrdf
View talk
Security||Ryan MacDonald

Linux Malware Detect 2.x: From Zero to Protected in 28 Seconds

A deep dive on the maldet 2.x rewrite: 348K+ deployments, a bash-native scan engine that beats ClamAV on memory by 22x, and the architecture decisions behind a pure-shell malware scanner that ships on everything from CentOS 6 to Ubuntu 24.04.

maldetbashmalwaredetectionarchitecture
View talk
Security||Ryan MacDonald

sigforge: Signature Intelligence for Malware Defense

The pipeline behind LMD's signatures: nine stages from raw feed samples to deployed signature packs, a six-stage classification cascade with LLM triage as the backstop, four validation gates including a 142K-file false-positive gate, and a canary/stable rollout channel with per-IP pins.

sigforgemaldetsignaturesmalwarepipeline
View talk
Engineering||Ryan MacDonald

The rfxn Ecosystem: Two Decades of Linux Security, Rebuilt AI-Native

A snapshot of the whole stack at the end of Q1 2026: 16 projects, 2,302 commits, 4,597 tests across an 8-OS matrix, and the governance framework and 27-role AI workforce that produced a two-decade codebase's fastest quarter since 2002.

rfxnecosystemgovernanceai-nativelinux-security
View talk