Haruka Kaya / Technical journal

Security research.Systems engineering.

Investigating boundaries in permissions, inputs, and state. I document implementation and verification, separating observed behavior from inferred impact.

01 /Technical writing

All 8 articles →
  1. Building a calendar and email assistant, then getting stuck on permissions and schemas

    Lessons from connecting Google services to a personal AI assistant, including renewed OAuth consent and a missing items field in an array schema.

  2. Binding email approval to a version of its recipients, body, and attachments

    Invalidating old approval and pending delivery when content changes. Implementation notes on defining exactly what was authorized.

  3. My dashboard was fetching the same data three times

    Consolidating the data behind overview, insights, and progress, while keeping measured results separate from expected performance improvements.

  4. The engraving preview looked right, but the toolpath was flipped

    Notes from a Python V-carving tool, covering coordinate mismatches, slider updates, and why displaying the input does not validate the output.

02 /Research & disclosure

Research within authorized scope, with reproducible conditions and recorded evidence.

I do not stop at looking at an app or an API. I trace which permission, which input, and how far the impact reaches. I reproduce within authorized scope and report confirmed facts separately from assumptions.

Android

IPC, exported components, permission boundaries

Web & API

Authentication, tokens, access control

AI Agents

Prompt injection, tool authorization

  1. ScopeRead the rules and the scope first
  2. ReproduceReproduce with as few assumptions as possible
  3. ReportSeparate evidence from impact in the report

Undisclosed reports and confidential service details are excluded. Tests, real-environment observations, and unverified hypotheses are documented separately.

03 /Engineering projects

Authorized Research Platform

An internal platform for security research within authorized scope. A pre-execution policy check blocks out-of-scope actions, while audit logs preserve decisions and evidence.

  • TypeScript
  • Claude MCP
  • Security
  • AI Agents

Internal project / Source not published

Attendance System

I built a web and Android tool to make attendance tracking for club activities a little easier. I keep improving it while it is being used.

  • Python
  • Flask
  • Flutter
  • SQLite
  • GitHub Actions
View project ↗

Agent Governance Toolkit

A fork of Microsoft's Agent Governance Toolkit used for learning and evaluation.

  • Python
  • Security
  • AI Agents
  • OWASP
View project ↗

V-carve Engraver

Python GUI that generates G-code for V-carve CNC engraving from DXF files. Extracts the skeleton with medial axis + distance field to compute per-point carving depth by bit geometry in real time. A 3D simulation replays the exact G-code motion before any real cutting — full pre-flight on the machine.

  • Python
  • CNC
  • GRBL
  • tkinter

Internal project / Source not published