CirriusTech
  • Home
  • Tech
  • Projects
  • Personal
  • Fiction
  • About
  • Certifications
☕ Enjoying the content? Consider supporting me on Ko-fi

Projects & Research

Tools, Research & Open Source

Security research, open source tooling, and experimental projects. Built to explore, understand, and solve real problems.

🔬

cARL

Cognitive Agent Runtime Layer: a version-controlled governance layer for AI coding agents inside a repository.

GitHub
🔬

CopeLimit

A GitHub Copilot quota dashboard and iOS Scriptable widget, shipped as a Netlify PWA with serverless functions.

GitHub
🔬

SpecRecon (SpecQL + APISpy)

An API spec and API request reconnaissance suite for Azure REST surfaces, combining static analysis with live request visibility.

GitHub
🔬

CSPeek

A defensive CSP auditing tool that inspects response headers and reports deterministic configuration-hygiene findings.

GitHub
🔬

UndREST-SpecQL

An API spec query and analysis engine for Azure REST definitions, powering the UndREST APISpy ecosystem.

GitHub
🔬

UndREST-APISpy

A Chrome and Edge DevTools extension for real-time Azure and Microsoft API request inspection.

GitHub
  • ««
  • «
  • 1
  • 2
  • 3
  • 4
  • »
  • »»
Recent Posts
We Automated Dave: Security Debt at Machine Speed
We Automated Dave: …

This is a personal blog. All opinions are my own - not my employer’s. There’s apparently a new category of security incident called AI escape. Except there isn’t. That phrase might be useful shorthand for headlines, and some of the incidents behind it are genuinely serious, but I think …

August 8, 2026 Read
Prompting Was Never the Control Plane
Prompting Was Never the …

This is a personal blog. All opinions are my own - not my employer’s. At some point over the last few months, I accidentally built a control plane for coding agents. This was not the plan. The plan, to the extent that there was one, was much smaller and much more normal. I wanted coding agents to …

July 1, 2026 Read
 Beyond The Door #1: The Illusion Of The Locked Door
Beyond The Door #1: The …

We keep acting like doors are portals into trust and expected good behaviour. That was never true, but has never been more dangerous an assumption than it is now.

June 14, 2026 Read
The Repository Is The New Package
The Repository Is The New …

The next generation of supply chain attacks aren’t targeting packages. They’re targeting repositories. The June 2026 Azure Functions incident may be a glimpse into what that future looks like.

June 6, 2026 Read
FinOps for Delegated Cognition: GitHub Boiled the Frog Backwards
FinOps for Delegated …

FinOps for Delegated Cognition: GitHub Boiled the Frog Backwards Yesterday started with me staring at a tiny dashboard called CopeLimit. This is not, admittedly, how most normal people choose to spend a Monday morning. Most people, when confronted with a major billing transition from one of the …

June 2, 2026 Read
The AI Credits Era Begins: Notes From the First Morning of GitHub’s New Billing Model
The AI Credits Era …

At some point very early this morning, because apparently this is what my life is now, I found myself watching a tiny dashboard called CopeLimit while GitHub Copilot’s new AI Credits billing model went live. This was not the original plan for the morning. The original plan was probably something …

June 1, 2026 Read
Footer logo
© 2026 All Rights Reserved