RESEARCH & NOTES

Questions worth investigating.

Threat models, AppSec writeups, experiments, and AI-security research. A place to document the reasoning as carefully as the result.

On the research agenda

Outlines only · No findings published yet
THREAT MODELINGPlanned

Mapping trust boundaries

A future exploration of data flows, trust boundaries, and abuse cases in a small web application.

  • Data-flow diagrams
  • Abuse cases
  • Risk analysis
AI SECURITYPlanned

When AI can call tools

An experiment outline for prompt injection, untrusted content, and tool permissions in AI-assisted workflows.

  • Prompt injection
  • Tool permissions
  • Trust boundaries