About the research

I am a security engineer publishing independent work through unauthdev. This site is my research and engineering portfolio.

What I build and investigate

Security boundaries in real software, offline tools for inspecting agent-session records, and measurements from infrastructure I operate. The project index distinguishes maintained tools from research prototypes and archived demonstrations.

How the work gets done

I use coding agents to assist with implementation and investigation. My responsibility is the question, the experiment, the evidence review, and the final claim. Vulnerability reports require local verification, a negative control, and an adversarial review against the actual scope. A model's agreement is not a test result.

Tool requests are distinct from observed effects. Honeypot requests are distinct from successful exploitation. Unknown collection coverage stays unknown. Each public project should make those limits inspectable.

Public records

Correspondence

Corrections and research feedback: hello@unauth.dev. Security reports about these tools: security policy.