Security research

Research

Independent security and privacy assessments of third-party tools, mostly AI coding agent add-ons. Each with a formal report, a reproduction, and coordinated disclosure.

Disclosure & evidence

Each assessment is reported to the vendor before publication, with hashed evidence and a reproducible proof-of-concept preserved for each finding. Findings describe capabilities and design risk, not claims of malicious intent. The evidence bundle and reproduction are available on request; a public release is under consideration.