Investigating boundaries in permissions, inputs, and state. I document implementation and verification, separating observed behavior from inferred impact.
Research within authorized scope, with reproducible conditions and recorded evidence.
I do not stop at looking at an app or an API. I trace which permission, which input, and how far the impact reaches. I reproduce within authorized scope and report confirmed facts separately from assumptions.
Android
IPC, exported components, permission boundaries
Web & API
Authentication, tokens, access control
AI Agents
Prompt injection, tool authorization
ScopeRead the rules and the scope first
ReproduceReproduce with as few assumptions as possible
ReportSeparate evidence from impact in the report
Undisclosed reports and confidential service details are excluded. Tests, real-environment observations, and unverified hypotheses are documented separately.
03 /Engineering projects
Authorized Research Platform
An internal platform for security research within authorized scope. A pre-execution policy check blocks out-of-scope actions, while audit logs preserve decisions and evidence.
TypeScript
Claude MCP
Security
AI Agents
Internal project / Source not published
Attendance System
I built a web and Android tool to make attendance tracking for club activities a little easier. I keep improving it while it is being used.
Python GUI that generates G-code for V-carve CNC engraving from DXF files. Extracts the skeleton with medial axis + distance field to compute per-point carving depth by bit geometry in real time. A 3D simulation replays the exact G-code motion before any real cutting — full pre-flight on the machine.