Reports
-
WebCheckup Report: External Check-Up of juribuora.com, With Fixes and a Re-Test
I ran my own website check-up service against my own site. It found nine things. Six were fixed and one partly fixed the same day, and re-checked. Two are still open, and the tool got two things wrong.
-
Risk Assessment of My AI Agent Workstation Using NIST SP 800-30
A qualitative risk assessment of the system I run: twelve risks identified, scored for likelihood and impact, ranked, and paired with a treatment. Likelihood is grounded in incidents that actually happened here.
-
Incident Report: An Exposed Bot Token, and a Rotation That Reported Success While the Service Was Down
A chat-bot credential was sitting in an automation workflow. This report covers containment, why deleting it was not enough, the rotation, and a second failure where the rotation tool said it had worked and had not.
-
Test Report: Restoring an Encrypted Backup of My AI Agent's Data on a Second Machine
A restore drill, written up as a test report. The backup was encrypted and kept off the main machine, then restored elsewhere and checked: 2,606 files, 21 database tables, 64,977 rows, without touching the live service.
-
Incident Report: A Chat Message Powered Off My Computer and Nothing Could Say Who Did It
A post-incident report on an unexplained remote shutdown in my AI agent setup: what was ruled out, the path that allowed it, the fixes, and how both fixes were nearly lost in a merge the next day.
-
Vulnerability Report: DNS-Rebinding SSRF in a Web-Reading Tool for an AI Agent
A formal write-up of a server-side request forgery flaw in a tool I built so an AI agent could read web pages. Four independent review rounds found five ways past its protections. All five are fixed and regression-tested; one transport remains untested.
-
Audit Report: Dependency Vulnerabilities in My Self-Hosted AI Agent Gateway, From 76 Findings to Zero
A dependency security audit of the agent gateway I run on my own machine. 76 known-vulnerability findings were reduced to 2 in a first pass and to 0 in a second, without hiding any behind a version number.
-
Incident Report: A Service Stopped Answering Because It Never Closed Its Database Connections
A root-cause report on a local web service that degraded until it refused connections. One helper function leaked a file handle on every call. The report covers the diagnosis, a one-place fix, and a test that could have failed.
-
Audit Report: Security and Quality Review of My iPhone App for Controlling AI Agents
An audit of the iPhone app and the service behind it that let me run AI agents remotely. It found an unauthenticated service, a command filter that could be bypassed, and tasks marked done that were not. All were fixed and re-audited the same week.
subscribe via RSS
