Hello,
Thanks for your offer
While a logic analyzer could be useful for hardware documentation of the dock connector (and on older models, the J04 connector), the possibility of tampering with the calculator through the connectors isn't very high, and anyway, the fact that using the connectors requires extra hardware makes such tampering impractical among users...
Software exploits are more practical. For those, you need to find out how to decompress+decrypt the boot2 or decrypt the OS (although the tool is available publicly, the decryption keys are not; you can also have nspire_emu dump them for you, provided you can find a copy of CX boot1 3.0.99 somehow), and disassemble the code.