Insights
Working notes on security research and system design.
Practical writing about adversarial evaluation, authorization, AI-enabled products, and the methods used to turn testing into useful evidence.
AI security · 8 min
Evaluating tool-use risk in agentic systems
A practical framework for reviewing authority, instructions, data flow, and failure containment when models can take actions.
Read research note →Application security · 7 minAuthorization boundaries in modern APIs
Why object-level checks are only one part of a broader identity, workflow, and state-management problem.
Read research note →Evaluation · 6 minDesigning reproducible security evaluations
How to turn open-ended adversarial testing into evidence that can support engineering and release decisions.
Read research note →These articles are general research perspectives, not claims about a specific product or client. They should not be treated as legal advice, certification, or a substitute for testing a real system.