About the research
I am a security engineer publishing independent work through unauthdev. This site is my research and engineering portfolio.
What I build and investigate
Security boundaries in real software, offline tools for inspecting agent-session records, and measurements from infrastructure I operate. The project index distinguishes maintained tools from research prototypes and archived demonstrations.
How the work gets done
I use coding agents to assist with implementation and investigation. My responsibility is the question, the experiment, the evidence review, and the final claim. Vulnerability reports require local verification, a negative control, and an adversarial review against the actual scope. A model's agreement is not a test result.
Tool requests are distinct from observed effects. Honeypot requests are distinct from successful exploitation. Unknown collection coverage stays unknown. Each public project should make those limits inspectable.
Public records
- n8n disclosure record - vendor advisory and reporter credit.
- Nuclei Milvus fingerprint contribution - the upstream review record.
- AI-Infra-Guard contribution - the upstream contribution record.
- Agent-forensics and measurement study - runnable tools and public data.
Correspondence
Corrections and research feedback: hello@unauth.dev. Security reports about these tools: security policy.