Research archive / 2023—2026

Selected
Work

A working archive of the things I break, document, and build around AI security: coordinated disclosures, technical writeups, and practical security projects.

01

Disclosures

Five primary exploitable cases from my cross-agent memory isolation study, tested against current releases or documented as prior research.

Disclosure — CWE-863 / CWE-94

letta-code: Cross-Agent Memory Isolation Bypass to Code Execution

The cross-agent guard covered file tools but exempted Bash. An agent could read or overwrite another agent's memory, then plant a trusted mods/*.ts file that executed when the victim reloaded.

Reported to support; repository archived
Disclosure — Critical / CVSS 9.9

mem0: Metadata-Filter Isolation Bypass and Destructive Wipe

mem0 validated only that an identity key existed. A wildcard could remove the effective filter and expose other tenants' memories, while delete_all("*") could delete every tenant's memory in a shared collection.

Read advisory ↗
Disclosure — CWE-89

CrewAI: SQL Injection in scope_prefix

CrewAI's LanceDB storage interpolated the caller-controlled scope directly into a SQL LIKE clause. A crafted prefix could return records from every tenant and use the same path to delete them.

Submitted via Bugcrowd VDP
Disclosure — CWE-863

AutoGen: Cross-Agent Memory Write and Poisoning

AutoGen's Mem0Memory.add() trusted metadata['user_id'] and allowed a caller to redirect a write into another agent's configured memory scope.

Disclosure drafted
Disclosure — CWE-502

LangGraph: Deserialization Fix Not Safe by Default

Although the msgpack allowlist fix exists, the latest checkpoint package remained permissive by default. Crafted constructor-style data could invoke an attacker-chosen module attribute unless strict mode was enabled.

Default configuration gap
02

Writeups

Longer technical breakdowns focused on reproducibility, impact, and the fix.

COMING SOONNo writeups published yet.
03

Projects

Tools and practical systems built to make security research more repeatable.

Research tooling

Deterministic Tool-Call Test Harness

A controlled, mock-LLM-backed harness that forces exact tool calls into open-source agent runtimes, isolating security enforcement from model behavior.

Agent security / Evaluation
Go / Reconnaissance

SubEnum — Advanced Multi-Source Subdomain Enumeration Tool

A high-performance Go tool combining passive Certificate Transparency reconnaissance with active DNS brute-forcing.

Supports A, CNAME, and MX lookups, wildcard detection, false-positive filtering, adjustable concurrency up to 200 threads, and CSV, JSON, or TXT exports.

View on GitHub ↗
Security utility

Cyber Terminal (XrooT v3.1)

A web-based CyberChef alternative supporting encoding, decoding, hashing with MD5, SHA256, and CRC32, plus Caesar, ROT13, XOR, and other cryptographic operations.

Built with vanilla JavaScript, drag-and-drop file input, and zero backend dependencies.

View on GitHub
SOC / Detection Engineering

Mini SOC Home Lab

A self-managed SOC environment built with pfSense, Suricata IDS, Elastic SIEM, Fleet Server, and Elastic Defend deployed on a victim machine.

Simulated real-world attack scenarios and validated end-to-end detection, alerting, and triage through the Elastic stack.

Hands-on security project