WebCook Labs research
Field notes for people building and reviewing connected products.
Practical writing on attack surfaces, test design and the evidence needed to make a security decision.
Our first articles focus on AI-enabled products, one area within the broader WebCook Labs testing practice.
Latest
Guides and field notes
Updated July 2026
What an AI penetration test should cover in 2026
How to scope the model, application, data, tools, identities and ordinary attack surface as one system.
Updated July 2026
Testing AI across mobile and desktop clients
Native storage, deep links, IPC, update trust and the backend paths a browser-only review cannot reach.
Updated July 2026
AI security for retail, fashion and destination brands
How customer journeys, connected actions and third-party services change the threat model.
Editorial standard
Specific systems. Bounded claims.
We name the trust boundary, separate unexpected behavior from demonstrated impact and state what the available evidence does—and does not—prove.
Frameworks are useful starting points. The final advice still has to fit the architecture, permissions and real workflows of the system under review.
Need evidence?
Some questions require a test.
Send the system, workflow or release decision and we will help define an appropriate scope.
Request an assessment