Every engagement produces a written findings report. These are anonymized examples of what we find — and how we fix it.
Anonymized findings from real GaleOps engagements. Names, industries, and identifying details removed.
A customer support agent retrieved documents from a shared knowledge base. An attacker planted a system-override instruction in a public-facing document. The agent exfiltrated the user's session token via the send_email tool.
Read the full teardown →An MCP server shipped with all tools registered as publicly callable — no authentication, no rate limiting, no confirmation boundaries. An attacker could chain read_file + send_email to exfiltrate any file on the host.
Read the full teardown →An AI agent returned its full system prompt in a verbose error message when given a malformed input. The prompt contained API keys, database schema details, and internal tool naming conventions — enough for a targeted attack.
An agent with read-only document access could chain search_docs → summarize → send_email to exfiltrate PHI. No confirmation boundary existed between reading data and sending it externally.
A DAN-style persona override bypassed the agent's content safety guardrails. The agent generated harmful product recommendations and exposed internal pricing logic that was never meant to reach customers.
An AI coding assistant generated SQL queries and shell commands that were executed without sanitization. An attacker could inject malicious code through a crafted prompt that persisted in the generated output.
Detailed writeups from bug bounty research and public vulnerability disclosures.
My first HackerOne report landed as a HIGH-severity information disclosure on a major education platform. The methodology applies to almost any AI-enabled site.
Read the full report →Downloaded 13 Clarity 4 contracts from a $100K bug bounty program, generated 8 hypotheses, tested the 3 highest-priority ones, and refuted all at the code level. A high-quality negative result.
Read the methodology →Found a vulnerability in a production MCP server in under 10 minutes. Tool poisoning, session hijacking, and the 3-line fix that blocks it all.
Read the teardown →Book a free 15-minute fit call. We'll scope your agent and recommend the right starting point.
Book a Free Fit Call →