Security research.
Evidence you can inspect.
I investigate security boundaries, build tools to inspect agent sessions, and measure what reaches exposed AI services. This is the research portfolio behind unauth.dev.
Published results. Runnable tools. Documented limits.
A published n8n advisory with reporter credit. The affected scope, vendor outcome, and disclosure record.
Reconstruct tool requests and recorded results from local session logs. Offline, deterministic, and explicit about missing evidence.
One decoy session, a public request dataset, and the limits of what honeypot observations can tell us.
GET-only metadata checks against one host you own, with a fix card for each finding.
102 credential paths requested in one decoy session. Downloadable JSON and CSV.
Captured requests at our honeypots, with the collection window stated.
Frozen measurement artifacts and checksums for repeatable analysis.
I am a security engineer publishing independent work through unauthdev. The contribution is the complete investigation: choosing the test, building the instrument, checking the result, and narrowing the conclusion when the evidence demands it.