Selected work
AI Security · Browser automation

AIMoat

A scanner that inspects how AI chat products are configured in the browser, runs targeted probes, grades findings, and produces remediation-oriented evidence.

StatusWorking engine
Period2025–26
My scopeSecurity research · Scanner architecture · Browser automation · Reporting
01 / Context

The system behind the interface.

AI security claims are easy to overstate. A useful scanner has to distinguish public configuration evidence from platform vulnerabilities and present reproducible findings.

02 / Decisions

Architecture choices that shaped the product.

Inspect the public surface

The scanner focuses on what a browser and an unauthenticated visitor can observe instead of claiming access to private model or platform internals.

Keep evidence attached

A grade is never the only result. Findings retain the request, response, browser signal, or configuration detail that produced them.

Mix static and dynamic checks

Headers and exposed data need deterministic inspection; model-behaviour risks need carefully scoped interaction probes.

03 / Evidence

What exists beyond the concept.

  • Static checks across scripts, browser storage, headers, and exposed endpoints
  • Dynamic prompt-injection and prompt-extraction probe corpus
  • Severity scoring with masked and full-evidence report modes
FastAPIPlaywrightPythonOpenAIPydanticNext.js
04 / Outcome

A production-minded result.

A working scanner engine tested against public chatbot integrations, with platform detection, multiple check modules, attack probes, and report generation.

Have a system like this to build?

Let’s turn the hard parts into a dependable product.

Start a conversation