nulltrace labs · ai security research

Find it. Prove it. Publish it.

Labs is the research arm of NullTrace. We break AI systems on purpose — agent loops, MCP servers, the seams between models and the tools they hold — then disclose responsibly and publish what we learn, so the fix outruns the exploit.

How we disclose

The rules we hold ourselves to, stated before the first advisory rather than after.

Coordinated disclosure, 90 days, no surprises. Vendors hear from us before anyone else does, with a working proof of concept and a suggested fix. The clock is firm but the conversation is human — a vendor who's shipping a fix gets the time the fix needs.

We publish the technique, not the ammunition: enough for defenders to test their own systems, never a turnkey kit. And findings from client engagements stay client confidential — Labs publishes only what we discover on our own time, our own systems, or with explicit permission.

What we break

The same surfaces the consulting side tests every week — studied until they give something up.

Agent loops

Goal hijack, memory poisoning, and how far one sentence of untrusted text travels.

MCP & connectors

Server auth patterns, tool schema abuse, and the trust seams between servers.

Tool-holding models

Function-call abuse, excessive agency, and identity for non-human callers.

Guardrails

Bypass patterns and what filtering actually holds up under an adaptive attacker.

Retrieval pipelines

Indirect injection through documents, embeddings, and everything agents are asked to read.

Multi-agent trust

Inter-agent boundaries, cascading failures, and who believed whom first.

Publications

Advisories and techniques land here. Working notes land on Prompts & Payloads.

> first advisories in the pipeline_

Until they clear disclosure, the working notes are at promptsandpayloads.com — the publication we run and sponsor.

Talk to Labs

Research collaboration, a system you want studied, or a finding you think we should look at — all welcome. If you're reporting a vulnerability in something we built, use this address too; we hold ourselves to the same 90 days.

labs@nulltracesec.com

Helpful in the first email
  • The system or pattern you think is interesting
  • What you've already observed, if anything
  • Whether there's a disclosure clock already running