The Lab
What's cooking
Some of the most interesting security work happens when nobody's waiting on a deliverable. This is where I take the problems I can't stop picking at and build toward real answers. No client is driving it and there is no investor deck, just the problem and enough obsession to actually see it through. Some of what comes out of here becomes a tool you can use. All of it feeds back into how I work.
On the bench
Closed betaWyrmSight watches every third-party script, tracker, and API your web apps actually load, then tells you the day one of them changes. The vendors you approved have a habit of pulling in vendors you didn’t.
It’s in closed beta now: free, participants picked by hand, and early enough to have rough edges. Details and the application are at wyrmsight.com.
On the bench
Active researchAI-Directed Pentesting
Frontier models are getting genuinely capable at offensive security tasks, and fast. I’m running them through real test scenarios to understand what they can actually do, where they still need a human making decisions, and what the trajectory means for how security testing works. Active research, not a packaged service.
On the bench
Active researchScanners grade a Content Security Policy as present or absent, which treats a useless policy and a strong one as the same result. This is a scoring model that puts a number on the difference, plus a calculator you can paste a policy into.
More to come on each of these. Check back as they take shape.
Working on a security problem that doesn't fit a standard engagement? That's usually the most interesting conversation I have. Bring it. I won't take everything on, but you'll get a straight answer either way.
Tell me what you're solving