Post-Hoc Recovery Evaluation: Measuring Agent Recovery After Unsafe Tool Execution
A research project that makes recovery a first-class evaluation object: injecting controlled, sandboxed unsafe-execution events into agent benchmarks and measuring...
Build a fully offline password-strength analyzer that estimates entropy, checks length and variety, and flags common patterns — with a hard guarantee that passwords never leave the device.

A local-only tool that analyzes how resistant a password would be to common guessing attacks: its length, the character types it uses, whether it appears in common-password and dictionary lists, and whether it follows predictable patterns like dates, sequences, or keyboard runs. It returns an estimated strength band plus specific, actionable feedback — all computed on the device, with no server involved.
>A hard privacy boundary. This analyzer never transmits a password, never stores one, and never logs one. There is no backend, no analytics payload containing input, and no network call in the entire flow. If a “password strength checker” sends your input anywhere, walk away — that is exactly the behavior this project refuses to implement. It is also not a password manager, and it does not store or autofill anything.
Two failures dominate password-strength meters. First, many “checkers” are actually web pages that send the password — or a hash of it — to a server, turning a security question into a credential-harvesting risk. Second, even honest meters disagree wildly because strength is a prediction about guessing attacks, not a physical property. Without a local tool and a clear model of what the estimate means, users get false confidence (“it says strong!”) or false panic. This project fixes the first problem by architecture and treats the second honestly: the meter estimates, explains its reasoning, and never pretends to be a guarantee.
The tool is a static page (HTML + JavaScript) or a small local CLI. Input stays in memory for the duration of one analysis and is discarded when the result renders. The page can even be opened from a downloaded file with no server at all.
The score is a model of how many guesses an attacker would likely need before hitting the password. The estimate combines several signals, each implemented as a small, testable function:
abcdef, 123456), keyboard runs (qwerty, asdf), repeated characters (aaaaaa), and date-like patterns (1990, 1985)The output is a strength band (very weak → strong) with reasons: “length is good, but this is in the top-10,000 most common passwords,” or “the pattern qwerty makes this far easier to guess than its character count suggests.” Each reason links to the check that produced it, so the user learns why, not just “weak.”
Alongside feedback on a weak choice, the tool suggests a healthier approach: long passphrases of unrelated words, unique passwords per account, and using a password manager to generate and store them (the analyzer itself deliberately does none of that storage).
P@ssw0rd123 scores poorly despite its symbols, so that I learn what attackers actually exploit.Date-pattern detection, substitution-aware dictionary checks, i18n word lists, and a browser-extension variant are natural second-phase additions.
fetch/XMLHttpRequest/sendBeacon calls; manual verification in airplane mode.This project is the local analysis corner of the site’s security cluster — deliberately different from the tools that watch the outside world. The data breach monitor watches for your accounts in other people’s breaches; this analyzer never touches the network at all. The phishing email detection system inspects incoming messages; this tool inspects an idea in your head and forgets it. And unlike the cookie consent enforcement extension, which actively reshapes other sites’ behavior, this is a purely local, single-purpose utility — a clean, small first security project that teaches the fundamentals without ever handling real credentials.
| Tool type | Approach | Limitation |
|———–|———-|————|
| Online “strength meters” | Server-side check | Often transmit the input — the exact risk this project avoids |
| Library strength estimators | Heuristic score you embed | Black-box scoring; no teaching value unless you read the source |
| Password manager generators | Generate + store strong passwords | Different job — this tool analyzes, never stores |
This project’s differentiators: a zero-network, no-persistence architecture; fully readable and extensible checks; and explanations that teach why a choice is weak.
Browse more Project Ideas · Beginner Ideas
A research project that makes recovery a first-class evaluation object: injecting controlled, sandboxed unsafe-execution events into agent benchmarks and measuring...
A research project that answers the question every failed agent run raises: which step broke it? Building an attributed corpus...
A research project that audits the measurement instruments themselves: applying the ABC validity-checklist methodology to agent-security benchmarks to find task-validity...
Ready to level up? These ideas offer more complexity:
Published on September 7, 2026
A team of developers, researchers, and innovators who review and publish practical ideas for builders and creators.
Published on September 7, 2026
A team of developers, researchers, and innovators who review and publish practical ideas for builders and creators.