AI agent security
Where an autonomous agent's tool-calling meets a real internal system. We study how prompt context, tool schemas and trust assumptions combine into reachable attack paths.
- Agents
- Tool invocation
- Trust boundaries
[ Labs ]
Labs are the standing research tracks we run between engagements — the surfaces we keep pressure-testing because the trust models are still being written. Some are active, some exploratory. None of it is a product claim.
Where an autonomous agent's tool-calling meets a real internal system. We study how prompt context, tool schemas and trust assumptions combine into reachable attack paths.
Renderer isolation, IPC surfaces and the assumptions a sandbox makes about the content it contains. Memory-safety and logic bugs at the boundary.
White-box review of widely deployed dependencies, reading each security fix for the variant it left behind and the callers the patch never reached.
Identity chains, over-scoped roles and metadata exposure — turning a cloud misconfiguration inventory into the two or three paths that actually reach data.
The bugs no scanner models: state machines, multi-step flows and authorization that is correct per-request but wrong in sequence.
Firmware, devices and new consumer platforms where the trust model is still being written and the tooling barely exists yet.
If one of these tracks overlaps a system you own or maintain, we would like to hear about it — collaboration and coordinated disclosure both start the same way.