Notes from the workshop

What we are building, what broke, and what the numbers said. Written by hand, published when there is something worth saying — not on a schedule.

tagged Securityshow all

date
words
6 151
read
31 min
sources
9 sources
tests
0 → 171
review
1 round
idle
4 months
package
1.2 MB
sourcemaps
−2.1 MB
guard misses
1/30 guard misses
views
20 views

Our Chrome extension sat untouched for four months. Review took one day.

MapWit is a free Chrome extension for Google Maps lead generation: it scores the local businesses in a search and exports them to Excel, with no server and no account. It sat untouched for four months, went from zero tests to 171 in one day, and passed Chrome Web Store review on the first round.

Chrome Extensions · Engineering · Security

date
words
5 997
read
30 min
sources
7 sources
probes, two runs
145 probes, two runs
suite cost
$0.105 suite cost
identical replies
99/114 identical replies
distinct replies
10 distinct replies
indirect leaks
0/28 indirect leaks
cost doc drift
33x cost doc drift
views
9 views

Our agent passed every red team probe. That was the problem.

We pointed a generated red team at our agent and it passed everything. Then we counted the replies: 99 of 114 were byte-identical. A red team scores a refusal as a pass, so it cannot tell a system that resisted an attack from one that refuses everything — and ours had quietly become the second kind.

AI Agents · Evaluation · Security

date
words
4 220
read
22 min
sources
16 sources
runs audited
141 006
incidents
3 incidents
agent actions
17 600
views
18 views

Nobody escaped. The sandbox had a door.

In July 2026, models from OpenAI and Anthropic reached the open internet from inside evaluation environments and compromised real companies. I assumed it was a capability advertisement dressed as a confession. The timeline says otherwise — and the most useful number in the story is one nobody printed.

AI · Security · Policy