SS · brand foundation v2
SHELL.001 — 2026.05
same attack.
different substrate.
a research identity for kai aizen.
adversarial ai · kernel · the psychology that binds them.
snailsploit[$]
01 · marks
the wordmark IS the brand.
two glyphs do all the work. the spiral becomes the lowercase ‘o’. [$] becomes the capital ‘S’. no separate illustration, no mascot — the type carries the snail and the exploit at once.
logarithmic spiral, hairline
the ospiral shell glyph
[$]oxide accent on the $ only
the Sbracketed dollar
lowercase — spiral o
snailsplit
camelcase — [$] for S
[$]nail[$]ploit
combined — [$]nailspl⧉it
snailsploit[$]
on paper
snailsploit[$]
02 · wordmark
lowercase, tight, one accent.
snailsploit[$]
spiral-o variant
snailsplit
on paper
snailsploit[$]
cli context
$ snailsploit aatmf scan --target gpt-4o
// 240 techniques · 20 tactics
// loaded shell.001 — kai aizen
favicon — the spiral o
16
24
32
48
64
03 · color
graphite, off-white, one oxide.
dark surface is the default — calm, instrument-like, never sterile. one signal color, used only for live status: cve severity, advisory state, the prompt cursor.
--bg
bg
page
--bg-raise
bg-raise
cards
--bg-sink
bg-sink
inset
--line
line
hairline
--line-hi
line-hi
strong rule
--fg
fg
primary
--fg-2
fg-2
secondary
--fg-3
fg-3
meta / mono
--fg-4
fg-4
disabled
--signal-2
signal
live status
light · for print, og, light pages
the same system, inverted — never the inverse aesthetic.
CVE-2026-3288 · ingress-nginx · 8.8 high
04 · typography
two faces. nothing else.
display / ui
söhne · neue haas
the slow exploit is the durable one.
across substrates — kernels, language models, agents — the attacker's craft is recognisably the same. patience reads as authority.
signal / data
berkeley · jetbrains mono
$ snailsploit aatmf scan --target gpt-4o
// 240 techniques across 20 tactics
CVE-2026-3288 ingress-nginx · cfg-injection · 8.8
numerals
tabular, lining
10
cve
3
frameworks
36
articles
240+
techniques
snailsploit[$]
live · 10 cve · 3 frameworks
kai aizen
genai security
independent
same attack.
different substrate.
adversarial ai · llm jailbreaking · kernel · the psychology that binds them. independent research, frameworks, and tooling — built slowly, on purpose.
view frameworks →
about kai
latest
memory injection through nested skillsmar 26
io_uring/zcrx race conditionmar 26
self-replicating memory wormmar 26
cve · published
10 total →
CVE-2026-3288ingress-nginxconfig-injection → rce8.8high
CVE-2026-31899cairosvgexponential dos7.5high
CVE-2025-9776catfolderssql injection6.5med
CVE-2026-32885ddevpath traversal6.5med
05 · voice
observe. don't claim.
say
same attack. different substrate.
patience is a primitive.
the exploit is in the assumption.
we read the trail before we follow it.
don't
world-class adversarial ai research.
🔥 i just rooted gpt-5 in one prompt!
cutting-edge, industry-leading red team.
hackers fear this one weird trick.