Route WPT 02 SECRV · Client work · self-initiated review
Security review of a live AI portal
Before the portal handled sensitive records, I tried to break it. Nine real issues, each fixed and locked with a test that fails the build if it returns.
fixed and locked with a CI test
Before: 12
known-vulnerable dependencies
redacted sample report
01Context
The operations portal reads inbound email, fetches documents, and runs AI features on real records. I reviewed it from the position of a hostile user and a hostile email.
The sample report is redacted. It names the vulnerability classes and the fixes, not the client.
02Key decisions
A finding that is fixed once can quietly come back in a later change.
- Choice
- Every finding gets a regression test in CI that reproduces the original attack.
- Tradeoff
- The test suite grows with every finding, which is the point.
AI features open new ways in: hostile instructions inside email, and model output that fetches URLs.
- Choice
- Treat every model output as untrusted input, and limit what it can reach.
- Tradeoff
- Some convenience features got narrower on purpose.
03The nine issues
- Prompt injection through inbound email that could steer an AI reply.
- Server-side request forgery through an AI document reader that fetched URLs.
- Broken authorization: an email endpoint any signed-in user could send from.
- An assistant that trusted the browser to report the user's role.
- Webhooks that would accept a replayed request.
- AI routes with no rate limit, open to running up the API bill.
- Privilege-escalation paths between roles, closed with database invariants.
- A missing content security policy, added as defense in depth.
- No supply-chain gate: known-vulnerable dependencies went from 12 to 0, and CI now blocks new ones.
04Results
- All nine issues were reproduced, fixed, and covered by a test that fails the build if the issue returns.
- The same review is now a fixed-price service for other teams shipping AI features.
05Stack
Threat modeling · Next.js · Supabase · Vitest · GitHub Actions · npm audit · gitleaks
Want this kind of work on your product?
Email me