Projects
Start with the research records below. Maintained tools receive correctness and compatibility fixes. Research prototypes and archived experiments preserve their methods and limitations without a product roadmap.
Featured work
- n8n vulnerability disclosure - public vendor acknowledgment and affected scope.
- Agent-forensics - a runnable reconstruction example and an evidence benchmark.
- Honeypot measurement - the method behind a published request dataset.
Tools and preserved experiments
| Project | Status | What it demonstrates |
|---|---|---|
| Exposure checker / fix cards | Maintained | Bounded metadata probing, SSRF defenses, and actionable findings. |
| aicheck-scan and CI actions | Maintained | CLI scanning and a local credential-artifact gate. |
| Local inventory | Maintenance only | Offline target inventory and change tracking. |
| BotWatch / product signals | Measurement | Captured requests with limited sensor coverage. |
| Exposure census | Dated snapshots | Public-index observations with provenance and dates. |
| Request dataset / releases | Preserved data | A bounded observation others can inspect and cite. |
| Agent evidence format / sample | Research prototype | A separate recorder/verifier experiment, with explicit trust limits. |
| Canary experiment | Research prototype | A request sensor; a hit does not identify an AI agent. |
| Exposure simulation | Archived demo | A synthetic explanation of exposure and remediation. |
Private hunt records and restricted research stay outside this public index. A project's presence here does not imply unrestricted disclosure of every finding.