CirriusTech
  • Home
  • Tech
  • Projects
  • Personal
  • Fiction
  • About
  • Certifications
☕ Enjoying the content? Consider supporting me on Ko-fi

Projects & Research

Tools, Research & Open Source

Security research, open source tooling, and experimental projects. Built to explore, understand, and solve real problems.

🔬

cARL

Cognitive Agent Runtime Layer: a version-controlled governance layer for AI coding agents inside a repository.

GitHub
🔬

CopeLimit

A GitHub Copilot quota dashboard and iOS Scriptable widget, shipped as a Netlify PWA with serverless functions.

GitHub
🔬

SpecRecon (SpecQL + APISpy)

An API spec and API request reconnaissance suite for Azure REST surfaces, combining static analysis with live request visibility.

GitHub
🔬

CSPeek

A defensive CSP auditing tool that inspects response headers and reports deterministic configuration-hygiene findings.

GitHub
🔬

UndREST-SpecQL

An API spec query and analysis engine for Azure REST definitions, powering the UndREST APISpy ecosystem.

GitHub
🔬

UndREST-APISpy

A Chrome and Edge DevTools extension for real-time Azure and Microsoft API request inspection.

GitHub
  • ««
  • «
  • 1
  • 2
  • 3
  • 4
  • »
  • »»
Recent Posts
Continuous Access Evaluation: Is it really tho?
Continuous Access …

This is a personal blog and all content herein is my own opinion and not that of my employer. Background Continuous Access Evaluation, or CAE, is one of those security controls with a wonderfully descriptive name. Access is not supposed to be evaluated only when you first authenticate. It is …

September 16, 2026 Read
Daddy Issues: When APIM Workspaces Inherit the Parent Identity
Daddy Issues: When APIM …

This is a personal blog and all content herein is my own opinion and not that of my employer. Introduction Sometimes security research starts with an exploit. Sometimes it starts with a much more boring question: “Where is the actual security boundary?” This one started with the latter. …

September 14, 2026 Read
What The Entra Fudge?! Tenant Restrictions v1 Doesn't Mean What You Think It Means
What The Entra Fudge?! …

If you implemented Tenant Restrictions v1 and only validated Restrict-Access-To-Tenants, you may only have implemented half the control you think you have.

August 19, 2026 Read
We Automated Dave: Security Debt at Machine Speed
We Automated Dave: …

This is a personal blog. All opinions are my own - not my employer’s. There’s apparently a new category of security incident called AI escape. Except there isn’t. That phrase might be useful shorthand for headlines, and some of the incidents behind it are genuinely serious, but I think …

August 8, 2026 Read
Prompting Was Never the Control Plane
Prompting Was Never the …

This is a personal blog. All opinions are my own - not my employer’s. At some point over the last few months, I accidentally built a control plane for coding agents. This was not the plan. The plan, to the extent that there was one, was much smaller and much more normal. I wanted coding agents to …

July 1, 2026 Read
 Beyond The Door #1: The Illusion Of The Locked Door
Beyond The Door #1: The …

We keep acting like doors are portals into trust and expected good behaviour. That was never true, but has never been more dangerous an assumption than it is now.

June 14, 2026 Read
Footer logo
© 2026 All Rights Reserved