WebCook Labs research

Field notes for people building and reviewing connected products.

Practical writing on attack surfaces, test design and the evidence needed to make a security decision.

Our first articles focus on AI-enabled products, one area within the broader WebCook Labs testing practice.

Editorial standard

Specific systems. Bounded claims.

We name the trust boundary, separate unexpected behavior from demonstrated impact and state what the available evidence does—and does not—prove.

Frameworks are useful starting points. The final advice still has to fit the architecture, permissions and real workflows of the system under review.

Need evidence?

Some questions require a test.

Send the system, workflow or release decision and we will help define an appropriate scope.

Request an assessment