Six Phases, Twelve Agents, One Flask Library: A Day With Cloudflare's Vulnerability Harness

I have a bad habit. When I read a good blog post, I read it once, nod, and never actually try the thing it describes. This time I was determined to break that pattern. The post was Cloudflare’s “Build Your Own Vulnerability Harness”. It described a 6-phase multi-agent security audit pipeline. I had been wanting to test something like this for months. So I read the post, closed the tab, and opened a terminal. This is what happened next. The good parts, the embarrassing parts, and the part where I found a real authentication bypass in a 6,000-line Python library that downloads 50 million times a month. ...

June 19, 2026 · 13 min · Napat Boonsaeng

PoC Quality Gates: How to Pass Vulnerability Program Triage

There’s a moment every vulnerability researcher dreads. You’ve spent weeks on a PoC. You submit it. The triage team comes back with: “Unable to reproduce.” Not “invalid.” Not “out of scope.” Just… we couldn’t make it crash. ...

April 20, 2026 · 15 min · Napat Boonsaeng

ZeroDayBench Replication: What Actually Holds Up in Practice

One of the stranger things about AI security is how many people trust benchmark scores they would never trust anywhere else. If someone told you a new static analyzer catches 90% of vulnerabilities, your first question would be: 90% of what? In what code? Under what assumptions? What did it miss? But when an LLM benchmark shows a leaderboard, people often skip those questions and go straight to conclusions. ...

March 21, 2026 · 4 min · Napat Boonsaeng