Skip to main content
CryptoFlex// chris johnson
Shipping
Series

Security Engineering

9 posts in this series

1

A security professional audits his own code: blog posts leaking private repo names, query-string secrets in browser history, SSRF vectors, and error messages handing attackers the database schema. 19 findings and the journey to fix every one.

Chris Johnson··14 min read
2

I've managed firewalls for years. When it came time to add WAF protection to my own site, I evaluated Cloudflare's free tier against Vercel's built-in WAF. Here's the comparison, the implementation, the config that broke the build, and the curl tests that proved it all works.

Chris Johnson··12 min read
3

I tasked four AI agents with auditing my production site for OWASP vulnerabilities. They found 16 findings, fixed 6, and wrote 37 tests in under 30 minutes. Traditional pentesting may never be the same, but red teamers shouldn't worry.

Chris Johnson··18 min read
4
Infographic: Guarding the Gateway, security risks of community MCP servers versus the secure alternative, with a five-point security checklist

How a routine search for blog content tools led to discovering critical security risks in a popular MCP server, and why I built my own secure alternative.

Chris Johnson··14 min read
5

A pairing/admin-approval privilege escalation CVE hit OpenClaw. My security agent ran a threat hunt, my builder agent implemented a Security Panel on the Mission Control dashboard, and 15 files later the system can see itself. Here is the full story.

Chris Johnson··18 min read
6
AI-Assisted Security Remediation infographic summarizing the fourth-party Vercel breach chain, the 60-minute rotation ladder, and the Vercel plus Google Workspace hardening checklist.

A fourth-party supply-chain breach prompted Vercel to flag nine of my production credentials for rotation out of an abundance of caution. Twenty minutes after reading the disclosure I was rotating keys, and sixty minutes later I had a full audit and a hardened account. Here is how Claude Code turned a day of incident response into an hour, and why the chain that got here should change how you pick vendors.

Chris Johnson··20 min read
7

A red dns_bypass card on my home dashboard sat at 0.667. Closing it took two ZBF rules, a deliberately incomplete remediation on the Default subnet, and a new traffic_rules surface in the chris2ao/unifi-mcp v0.4.0 release. Here is the full walk.

Chris Johnson··16 min read
8
The same question asked from two sides. On the left, building with AI, agents that read and act on their own across custom MCP servers, multi-agent pipelines, and a RAG memory store. On the right, defending an enterprise adopting AI as fast as it can, where slowing the innovation down is not the assignment and securing it while it moves is. Underneath, the closing line that security knowledge has a shelf life, the people attacking these systems are not waiting, and that is why the learning does not stop.

I build with AI every day, and I help keep an enterprise secure while it adopts AI as fast as it can. Both jobs punish stale knowledge, so I worked through TryHackMe's AI Security path and sat the AI1 certification. Here is what the exam actually tests and what carried back into my own code.

Chris Johnson··19 min read
9
Dark editorial cover for Security Review: Round Two, part 9 of the Security Engineering series. Two chips read Security Engineering and Part 9, Biannual Site Review, above a kicker reading 6 Agents, 1 Rule, Nothing Ships Without Consensus. Below, two side-by-side terminal-style code panels contrast a safe frontmatter fence against a dangerous one: the left, green-bordered panel labelled Data, Renders Fine shows a plain --- fence with an ordinary title and date, captioned Plain frontmatter fence, always just data; the right, red-bordered panel labelled Code, Would Execute shows a ---js fence with its payload marked omitted, captioned One labelled fence, now rejected before parsing, every push. Beneath the panels, the title reads Security Review: Round Two, with Round Two in teal. A mono deck line beneath the title reads The worst finding was hiding in the content folder, caught by consensus, not a scanner. A row of six chips names the review team: AppSec Pentester (Captain, Audit Lens), Red Teamer (Exploit Lens), Sec. Researcher (Novel Bugs), Threat Intel (OSINT and CVEs), Sec. Engineer (Fix Design), and an amber-accented Advocate chip (Cost vs. Risk Veto). An italic closing line reads Five lenses find it, the advocate weighs what it's worth to fix. The footer shows the Cryptoflex LLC, From the Workshop brand strip and the text Fixed and Deployed, Round Three in 6 Months.

A team of six agents, five security specialists plus an advocate representing the site owner, ran a consensus-driven security review of cryptoflexllc.com. The standout finding: an ordinary-looking blog draft that could have been parsed as executable code instead of data.

Chris Johnson··16 min read

Navigation

Blog Posts

↑↓ navigate openesc close