Evidence before publication
WAL Research brings together hands-on vulnerability investigation, AI-assisted code review, triage, and validation. The emphasis is on understanding a failure well enough to explain and reproduce it.
Areas of work
- WordPress access control and authorization boundaries.
- Application behavior across users, roles, and object ownership.
- AI-assisted investigation and the reliability of generated hypotheses.
- Clear reporting that separates observations, assumptions, and verified impact.
From lead to reviewed finding
| Stage | Evidence required to move forward |
|---|---|
| Hypothesis | A bounded question, affected feature, and reason to investigate |
| Source review | Relevant entry point, code path, permissions, and assumptions |
| Lab reproduction | Exact version, environment, account role, and observed behavior |
| Human review | Supported impact, repeatability, and alternate explanations |
| Remediation review | Proposed change and comparison with the original behavior |
| Disclosure decision | Confirmed publication status and an appropriate report audience |
Rejected and inconclusive leads belong in the record too. They explain false positives and prevent unsupported claims from repeatedly entering the queue.
A reproducible report
- Scope and provenance: component, exact version, source origin, and test environment.
- Prerequisites: account role, configuration, and required application state.
- Expected versus observed behavior: a precise description of the boundary and result.
- Reproduction: ordered steps and relevant evidence from the controlled lab.
- Impact: what was demonstrated, with assumptions and limits made explicit.
- Remediation and retest: proposed correction and behavior after a fix.
What distinguishes a lead from a finding?
A lead suggests behavior worth investigating. A finding has evidence supporting a specific claim. An AI review, pattern match, or unusual response alone does not establish reproducibility or impact.
The connected workflow
AnchorScope focuses the research queue. WAL-0.1 assists investigation. WAL Research decides what the evidence supports and how to communicate it. Discovery rankings and model confidence do not replace human review.
Responsible disclosure
Detailed vulnerability write-ups are published only when disclosure is authorized. Unreleased findings, affected targets, and reserved identifiers are intentionally excluded from this overview.
Read the field notes
The WAL Research app provides private reports with scope, prerequisites, observed behavior, reproduction, evidence, impact, remediation, and disclosure notes. Create a report directly or from a WAL-0.1 lead, edit its review stage, archive and restore it, and export Markdown or JSON backups. Saving does not send or publicly publish a disclosure.
The research archive includes the site’s existing notes on agent security, model evaluations, and untrusted context. These educational notes are separate from vulnerability advisories.
Next research outputs
Useful next public artifacts include a documented methodology, a reviewed reference dataset, comparative evaluation results, and disclosure-ready case studies when available. Performance numbers should include their sample, method, and limitations. No verified advisory count is claimed by this portfolio.