[ Blog ]
Notes from the lab.
Method, mostly. What we can publish about how the agents work, how findings get proved, and the mistakes that turned into rules — while the findings themselves are still under coordinated disclosure.
- 6 min read
A finding without a proof-of-concept is a guess
The failure mode of AI-assisted security work is not missing bugs. It is producing confident, well-written reports for bugs that were never there.
- method
- agents
- disclosure
- 5 min read
Prove the scanner fires before you trust a clean result
A tool that reports nothing and a tool that is silently broken produce identical output. The only way to tell them apart is to plant something it must find.
- method
- tooling
Findings under embargo are not written up here until the vendor has shipped a fix. See the disclosure policy.