Security status / active and operational

AI Security and Engineering Leadership

Everything interesting happens at the trust boundary.

I build and break software systems with a security engineer's bias for evidence. The current focus is AI security research, red teaming, and response when systems fail, with the engineering leadership to turn findings into practice.

Current Position

Current Focus

Now

Updated September 2026

Active Mission Board

Selected Work

Systems worth testing under pressureAI security research and red-team work

Runnable AI security research, red-team practice, security event response, and the engineering leadership that turns findings into shipped controls.

Current Trajectory

Current Focus

Making AI security executable

I am building vulnerable-agent labs, attack harnesses, and practical writeups around the OWASP LLM Top 10. The goal is to turn vague AI risk into runnable examples, observable failures, and defensible mitigations.

Hull Integrity

Security Discipline

Security is the engineering baseline.

Threat modeling, permissions, storage, trust boundaries, and failure modes are treated as normal engineering constraints, not after-the-fact review rituals.

Latest Transmissions

Latest Writing

Security notes from the field

PostBreaking Agents to Build Better Ones: LLM01 Prompt Injection

A hands-on RAG prompt-injection lab for learning OWASP LLM01:2025, measuring attack success rate, and testing a simple spotlighting defense.

PostSupply Chain Attacks on AI Tooling: Lessons from Shai-Hulud

A field report on the npm worm that targeted ~/.claude/, the three scanners I built in response, and what AI infra security needs next.

PostWelcome

What this site is and what's coming.