I trust boundaries I can inspect, automation I can audit, and claims I can reproduce.
blog/ · research/ · disclosures/ · htb/
Most of my public work sits at the security-plus-AI-agents seam: isolated runtimes, explicit trust boundaries, capability-gated tools, and automation that leaves evidence behind. The pinned repositories are different implementations of that idea.
Strata preserves the life of durable architecture decisions; Cairn disciplines the implementation work around them. Together they keep design authority and execution evidence inspectable without collapsing design history into session state.
curl -fsS https://foobarto.me/profile-signals.json | jq -c '.signals|sort_by(.date)|reverse[]'2026-08-28writing— Ignorance Is a Security Boundary2026-08-18disclosure— Remote-controlled VS Code command execution via an unsigned announcement feed in jlcodes.antigravity-cockpit2026-05-26research— Fluency as Attack Surface2026-05-17htb— atlas — HTB machine writeup
I take on focused security work: threat modeling, product and code review, AI-system review, and deep analysis of complex systems. See consulting and contact details.





