Abracadabra Labs / resource directory

About

What this is, and what it is not

A curated, annotated directory of publicly available material on three subjects and the places they overlap. It is a finding aid. It contains no original research, no argument, and no thought leadership.

136 links 62 attackers 58 deception 30 quantum cognition 14 cross-topic

Who runs this

I am Michael Senft, and I compile and maintain this directory under the name Abracadabra Labs. I work in cyber security and I built it because I kept losing track of which paper actually supported a figure I had seen quoted. The selection, the annotations and the flags are my judgement, and where I am unsure the entry says so. There is no team, no funding behind it, and no institution reviewing it.

Corrections are the most useful thing you can send me: michael.senft@abracadabralabs.org. If something here is wrong, I would rather know.

How entries are chosen

An entry earns a place if someone working in the area would be worse off not knowing it exists. In practice that means foundational work, current work, the surveys that get you into a literature quickly, the standards and frameworks people actually cite, tools you can run, and the critical literature that argues the rest of it is wrong.

Things I deliberately leave out: secondary coverage that summarises a primary source you could read instead; retail book listings, in favour of publisher pages; PDF mirrors where a canonical landing page exists; personal social media accounts standing in for a researcher's body of work; and marketing pages with no research content behind them. One exception is flagged where it occurs — a single encyclopaedia entry is listed as an orientation link for quantum cognition, with a note saying to read it alongside the critical literature.

How entries are verified

I open every page and read enough of it to describe it before I write the annotation. Where a publisher refuses automated access I open it in a browser instead. Where a canonical version is unreachable and an open version is not, I either link the reachable one and say so in the annotation, or I leave the entry out. I do not reconstruct a DOI from memory, and where I have taken an author list or a reference from a listing page rather than the source itself, the annotation says that too.

The initial 136 entries were compiled and checked in one pass on 2026-09-18, which is why they share a checked date. As entries are re-verified those dates will spread out. Each entry carries both the date it was added and the date it was last checked, and both are in the dataset.

What this gets you: the link resolved when I checked it, and the description matches the page I read. What it does not get you: any guarantee the link still resolves today, that the claims in a listed source are true, or that a paper has not since been retracted or superseded.

Flags

A directory that flags its own weak entries is more useful than one that does not. 19 entries are vendor-authored, 16 are preprints, 11 are contested, over-read or unreplicated, 13 are dated, 19 are paywalled, and 40 are continuously updated and so carry no publication year. Flags are my judgement and some of them will be wrong. Tell me which.

Offensive tooling and authorised use

Some of what is listed here is offensive by design: autonomous exploitation frameworks, penetration-testing agents, prompt-injection payloads, LLM vulnerability scanners. They are catalogued for research, defensive evaluation and authorised testing.

Running any of it against systems you do not own or have documented written permission to test is illegal in most jurisdictions, and nothing on this site constitutes that permission. The deception material carries its own caveat: decoys and honeytokens deployed on infrastructure you do not control, or in ways that capture third-party data, raise legal questions well beyond the technical ones.

Listing is not endorsement

Including a source does not mean its claims are endorsed, and several entries are listed precisely so that a widely quoted figure can be read next to its caveat. Vendor-authored material is flagged because the author has a commercial interest in the conclusion, not because it is wrong.

No resource listed here is affiliated with Abracadabra Labs, and none of the listed organisations has reviewed or approved this directory. Nothing on this site implies government affiliation or official endorsement. Government publications are listed because they are public documents, not because their authors were consulted.

Suggesting an entry, or reporting a dead link

Email me at michael.senft@abracadabralabs.org. For a dead link, the entry id and what you saw — a 404, a redirect somewhere unrelated, a paywall that was not there before — is enough. For a suggestion, send the URL and a line on why it earns a place; I will open it and read it before adding it, which is the one rule here with no exceptions.

For anything about the security of this site rather than its contents, see /.well-known/security.txt.

Using the data

The dataset is a public endpoint at /assets/data/resources.json, served with permissive CORS so it can be read from other origins. The field definitions live in taxonomy.json. Every entry also has a permalink on the full index, so you can cite one directly.

The compilation — the selection, the annotations and the taxonomy — is licensed CC BY 4.0. The code that builds the site is MIT. The linked resources belong to their authors and publishers and are not redistributed here.

Privacy

There is no analytics, no tracking, no cookies, and no form on this site that submits anywhere. Nothing is loaded from any other origin: no fonts, no scripts, no embeds. The only thing stored in your browser is your light or dark theme preference, in localStorage, which never leaves your device. Server logs are whatever Cloudflare keeps by default for a static site; I do not read them.

Keeping it current

A link check runs monthly and on every change to the data, and it fails loudly on dead links. A passing check only proves a URL returns 200, not that the content behind it is unchanged, so it is a floor rather than a guarantee. Academic publishers that refuse automated clients are reported separately and checked by hand, not treated as dead.