What we found, written down.
Vulnerabilities with proof-of-concept and the fix, and research with the numbers behind it.
5 CVEs, 4 writeups, 9 talks.
Two sides of the same coin
Offensive Security
Finding the cracks before the bad actors do. We research attack vectors, test guardrails, and publish what we find so the community can learn.
Defensive Security
Building resilience into AI systems. We study detection, guardrail architectures, and monitoring strategies that actually work in production.
Technical writeups
Do You Trust the Model: Supply Chain RCE in Axolotl
Fine-tuners pull base models off the Hugging Face Hub the way apps pull packages off npm. Axolotl checks the one flag that keeps a pulled model from running code the wrong way, so a poisoned model on the Hub is remote code execution on every machine that trains on it.
Your First Agentic SOC Without the GPU Bill: Local LLM Triage on Apple Silicon
A 12B model on a 24 GB laptop can triage SOC alerts if you constrain it instead of scaling it. We benchmarked eighteen local models, and the assumptions that bigger, more reasoning, and cheap screening are better all failed.
Ask and Receive: SSRF and Identity Spoofing in the Headroom LLM Proxy
Headroom reads where a request should go and who is making it from headers the caller sets, and it checks neither. That's enough to reach cloud metadata, steal the API key, and read or write another user's memory.
From Notepad to Notebook: Config Injection to Zero-Click RCE in marimo
Opening a marimo notebook can run an attacker's command with zero clicks, and the same config-injection flaw can leak the operator's API key. Two CVEs, one root cause.