Skip to content
06Writeups

Notes from breaking things, then fixing them.

How the systems were built, how the tools were measured, and what my own tools got wrong. Benchmarks and dead ends included.

5Writeups
19Minutes of reading
23Topics
5 of 5 shown
  1. AppSec

    authzscan on Real Code: What a 100% Benchmark Score Failed to Predict

    The live eval landed at 100% recall and precision. Then I pointed the scanner at a real open-source repo and it found one genuine bug in eleven candidates. The gap was in my benchmark, not the model.

    #idor#bola#agents#llm#nextjs#evals#benchmarks#appsec
    7 minhard
  2. AppSec

    Building authzscan: Agent-Driven IDOR Detection You Can Actually Measure

    Why pattern-matching SAST misses broken access control, how a four-phase Claude agent pipeline finds it, and the seeded benchmark that keeps the whole thing honest.

    #idor#bola#agents#llm#nextjs#sast#evals#appsec
    4 minhard
  3. Research

    Ghost AI: Architecture-First Engineering in the Age of AI Agents

    A real-time collaborative workspace where you design systems instead of typing them, and the context-managed workflow that built it. Notes on what senior engineering looks like when implementation becomes a commodity.

    #ai#architecture#nextjs#prisma#postgres#typescript#tailwind#liveblocks#react-flow
    4 min
  4. AppSec

    Building jwt-scan: A CLI That Hunts the Five JWT Bugs From My Lab

    Turning a vulnerability lab into a shippable scanner. From research artifact to npm package, with token-only and live-endpoint modes, in one weekend.

    #jwt#cli#tooling#appsec#node#typescript
    3 minmedium
  5. AppSec

    JWT alg=none Bypass: When the Token Trusts Itself

    How a one-line algorithm header turns authentication into security theater, and why allowlisting is the only fix.

    #jwt#auth#owasp#appsec
    1 mineasy