Design essays

Fewer posts. Sharper arguments.

The blog is not a changelog and not a keyword warehouse. These essays explain the design decisions that stay true when commands and releases change.

Essay 017 min

AI pentesting tools: Burp Suite, ZAP, Caido, or h5i?

Burp Suite, ZAP, Caido, and h5i compared for AI pentesting: AI-assisted manual testing, AI-authored scan automation, and agent-led investigation.

Essay 0210 min

Sandbox the entire workflow: browse, develop, review, apply

Create one sandbox for an AI coding task, browse from inside it, develop and test there, then review the evidence before exporting or applying the patch.

Essay 036 min

Why sandbox the entire AI agent workload

AI coding agents run package scripts, compilers, tests, servers, and browsers. Sandboxing the whole workload limits what mistakes and untrusted code can reach.

Essay 046 min

How to choose an AI agent sandbox

Choose an AI coding-agent sandbox by the failure it must prevent: host file access, unrestricted network traffic, environment drift, or a shared kernel.

Essay 056 min

Review AI-generated code with execution evidence

Review AI-generated code using the diff, externally observed test results, denied actions, browser errors, and explicit gaps in evidence.

Essay 066 min

How to protect a coding agent from prompt injection

Limit the files, credentials, network destinations, local services, and repository writes available to a prompt-injected coding agent.

Essay 074 min

Burp Suite vs h5i for AI agents

Burp Suite vs h5i for AI agents: compare HTTP capture, request editing, browser automation, and fully automated penetration testing with Burp AT or h5i.

Essay 084 min

OWASP ZAP vs h5i for AI agents

OWASP ZAP vs h5i for AI agents: compare DAST scanning and MCP automation with fully automated, agent-driven browser testing, HTTP capture, editing, and replay.

Essay 094 min

Caido vs h5i for AI agents

Caido vs h5i for AI agents: compare proxy history, HTTPQL, Replay, Automate, and Skills with fully automated agent-driven browser and HTTP testing.