Finding Is Not Exploiting
A technical note on separating vulnerability detection from exploit reproduction and using security AI inside a verified, sandboxed pipeline
Topics
Technology shifts and practical use
A technical note on separating vulnerability detection from exploit reproduction and using security AI inside a verified, sandboxed pipeline
An approachable engineering guide to completion rate, latency, cost, recovery, runtime abstraction, license checks, and guarded agent payments.
A plain-language AI engineering note on separating ads from answers, using local models safely, and issuing short-lived tool credentials
A plain-language engineering note on Meta's local agent model, reporting on Microsoft's custom chip, and the routing and least-privilege lessons from an OpenAI security incident
A plain-language AI technology note on using Google SecOps ingestion activity to separate missing, delayed, and failed logs and build an operational checklist
A plain-language technical note from the August 9, 2026 briefing on open-weight licenses, power and memory, workflow AI, and what I now check before deployment
I looked at where AI charges come from and how to stop them before a small mistake becomes an expensive loop.
A simple way to turn a vague idea into something small enough to test with help from AI.