↓ Skip to main content

AI & security

Tools, experiments, and opinions on using AI for security research.

2026

patrik.re

Where was Mythos when WordPress fell?

On marketing claims nobody checks, the 1,000 projects Anthropic never listed, and why an industry full of experts followed along.

patrik.re Archive

Teaching Claude Everything You've Hacked

h1-brain is an MCP server that gives Claude your HackerOne bounty history and a database of public disclosures. Setup and first sync.

patrik.re Archive

What h1-brain Actually Does

Every tool in h1-brain, explained. Your reports, public disclosures, and the hack() briefing that ties them together.

patrik.re Archive

Replaced by a Goldfish

Opus 4.6, the pentesting hype, and why most of the AI discourse around security is just noise.

patrik.re Archive

Daily Workflows with the Email Agent

Real usage patterns for an AI email agent — morning triage, thread summaries, draft replies, and where the human stays in the loop.

patrik.re Archive

Gmail API Credentials the Paranoid Way

Setting up Google Cloud OAuth credentials with minimal scopes for an AI email agent — because 'full access' is never the right default.

patrik.re Archive

Guardrails That Actually Work

A four-layer defense model for AI email agents — because no single safety measure is enough when your inbox is on the line.

patrik.re Archive

Wiring Gmail into OpenClaw

Installing the Gmail MCP server, configuring agent tools, and filtering down to only the operations you actually want.

patrik.re Archive

Writing a SOUL.md for Email

Defining hard rules, tone guidelines, and PII handling for an AI email agent — because 'be helpful' isn't a security policy.

patrik.re Archive

Connecting Claude Max and Telegram

Using OAuth credentials from a Claude Max subscription to power OpenClaw agents, and wiring up a Telegram bot for mobile access.

patrik.re Archive

Securing the Dashboard with Nginx Proxy Manager

Putting the OpenClaw Control UI behind HTTPS with basic auth, WebSocket passthrough, and a proper Content Security Policy — all through Nginx Proxy Manager.