Jordan Calhoun

Route WPT 02 SECRV · Client work · self-initiated review

Security review of a live AI portal

Before the portal handled sensitive records, I tried to break it. Nine real issues, each fixed and locked with a test that fails the build if it returns.

9issues

fixed and locked with a CI test

Before: 12

0deps

known-vulnerable dependencies

17pages

redacted sample report

The operations portal reads inbound email, fetches documents, and runs AI features on real records. I reviewed it from the position of a hostile user and a hostile email.

The sample report is redacted. It names the vulnerability classes and the fixes, not the client.

  1. A finding that is fixed once can quietly come back in a later change.

    Choice
    Every finding gets a regression test in CI that reproduces the original attack.
    Tradeoff
    The test suite grows with every finding, which is the point.
  2. AI features open new ways in: hostile instructions inside email, and model output that fetches URLs.

    Choice
    Treat every model output as untrusted input, and limit what it can reach.
    Tradeoff
    Some convenience features got narrower on purpose.
  • Prompt injection through inbound email that could steer an AI reply.
  • Server-side request forgery through an AI document reader that fetched URLs.
  • Broken authorization: an email endpoint any signed-in user could send from.
  • An assistant that trusted the browser to report the user's role.
  • Webhooks that would accept a replayed request.
  • AI routes with no rate limit, open to running up the API bill.
  • Privilege-escalation paths between roles, closed with database invariants.
  • A missing content security policy, added as defense in depth.
  • No supply-chain gate: known-vulnerable dependencies went from 12 to 0, and CI now blocks new ones.
  • All nine issues were reproduced, fixed, and covered by a test that fails the build if the issue returns.
  • The same review is now a fixed-price service for other teams shipping AI features.

Threat modeling · Next.js · Supabase · Vitest · GitHub Actions · npm audit · gitleaks

Want this kind of work on your product?

Email me