Writing

Technical investigations.

Clear technical writing for recruiters and practitioners: the investigations, methods, and engineering reports that show how I reason, verify results, and communicate limitations.

Articles and reports

2026-08-23 Inside Assertion Desk 1/2

The Wrong Claim

My own limitations file said injection resistance rested on one live path into a model prompt. Reading the code that builds that prompt found a second one, and a bug inside the fix while I re-measured it honestly.

2026-08-23 Inside Assertion Desk 2/2

A Support Answer You Can Prove

Eight different SAML failures can all look like "SSO is broken." A recorded case shows a confident, well-formed model draft rejected by a gate that checks claims against evidence, not fluency.

2026-08-03 Inside MCP Detect 3/3

The Handler Deleted the Only Field That Mattered

A synthetic cross-tenant request looked valid in telemetry. The source showed that the handler had discarded authenticated identity and trusted caller-controlled tenant selection.

Sample report MCP-DETECT

Agentic Detection Readiness Assessment (opens in a new tab)

A sample deliverable for a fictional organization: observed MCP servers, trust boundaries, findings, detection coverage, and blind spots, written for a human reviewer. The environment and events are synthetic and labeled as such.

Approach

Methods and sources included.

Method

I separate tool output from interpretation, name what was observed, and say when the evidence cannot support attribution or a broader claim. If you cannot audit the reasoning, it is not a finding.