Recent activity
- Commented on"I stopped using AI to judge AI security. Here's what I do instead."
- Commented onI tested whether agents leak secrets without being asked — and whether my scanner catches it when they do
- Commented onI tested whether agents leak secrets without being asked — and whether my scanner catches it when they do
- Commented onI tested whether agents leak secrets without being asked — and whether my scanner catches it when they do
- Commented onI tested whether agents leak secrets without being asked — and whether my scanner catches it when they do
- PostedI tested whether agents leak secrets without being asked — and whether my scanner catches it when they do
- Commented on0.2.0: I shipped the coverage my own page had already promised
- Posted0.2.0: I shipped the coverage my own page had already promised
- PostedA leaked agent key is two debts — and I caught my own scanner lying about it
- Posted"audit the detection, not the reasoning"
- Commented onYour AI agent can refuse to leak a secret — and leak it anyway, in its "thinking"
- Commented onYour AI agent can refuse to leak a secret — and leak it anyway, in its "thinking"
- PostedThe leak usually isn't in the answer. It's in the thinking.
- Commented onYour AI agent can refuse to leak a secret — and leak it anyway, in its "thinking"
- Commented onYour AI agent can refuse to leak a secret — and leak it anyway, in its "thinking"
- PostedYour AI agent can refuse to leak a secret — and leak it anyway, in its "thinking"
- PostedYour AI agent's leak risk depends more on the model than the prompt
- Posted"I looked into why APIs actually go down. It's rarely a hack — it's an unhandled exception."
- PostedI tested whether "just paste the leak into your AI to fix it" actually works. It depends on the model — here's what broke.Build-in-public
- Commented onMy AI agent leaked a secret in a way my own scanner missed. Here's what I learned about what these tools can and can't catch.