Security status / active and operational
AI Security and Engineering Leadership
Everything interesting happens at the trust boundary.
I build and break software systems with a security engineer's bias for evidence. The current focus is AI security research, red teaming, and response when systems fail, with the engineering leadership to turn findings into practice.
Current Position
Current Focus
Now
Updated September 2026
- Red-teaming AI features in production and mapping where agent tool use crosses trust boundaries.
- Building the runnable OWASP LLM Top 10 lab: ten vulnerable agents, an attacker payload library, and a spotlighting defense toggle.
- Writing up prompt-injection findings from the RAG lab.
Active Mission Board
Selected Work
Systems worth testing under pressureAI security research and red-team work
Runnable AI security research, red-team practice, security event response, and the engineering leadership that turns findings into shipped controls.
OWASP LLM Top 10 labs, vulnerable agents, attack harnesses, and writeups that make AI risks observable instead of abstract.
Active focus02 / Red TeamRed Team and ResponseAttacker-informed testing that changes engineering prioritiesApplication-layer penetration testing, vulnerability research, proof-of-concept exploits, and the response and postmortem work that follows a real event.
Flight proven03 / LeadershipEngineering LeadershipSecurity practice that survives contact with deliveryThreat modeling, secure development lifecycle, standards, and team formation that keep security inside normal engineering work instead of beside it.
Embedded disciplineCurrent Trajectory
Current Focus
Making AI security executable
I am building vulnerable-agent labs, attack harnesses, and practical writeups around the OWASP LLM Top 10. The goal is to turn vague AI risk into runnable examples, observable failures, and defensible mitigations.
Hull Integrity
Security Discipline
Security is the engineering baseline.
Threat modeling, permissions, storage, trust boundaries, and failure modes are treated as normal engineering constraints, not after-the-fact review rituals.
Latest Transmissions
Latest Writing
Security notes from the field
A hands-on RAG prompt-injection lab for learning OWASP LLM01:2025, measuring attack success rate, and testing a simple spotlighting defense.
PostSupply Chain Attacks on AI Tooling: Lessons from Shai-HuludA field report on the npm worm that targeted ~/.claude/, the three scanners I built in response, and what AI infra security needs next.
PostWelcomeWhat this site is and what's coming.