Computer science undergraduate focused on security for AI systems: scanners, red-team tooling, evaluation harnesses and defensive infrastructure for agents, MCP servers, RAG pipelines and model artifacts.
aisec-suite is the umbrella for my AI-security engineering work: a unified CLI, normalized findings, JSON/SARIF reporting, baselines, policy-as-code and CI enforcement across multiple AI trust boundaries.
| Project | Focus |
|---|---|
| aisec-suite | Umbrella AI-security scanner and common reporting/CI layer |
| mcp-scan-study | Empirical MCP-security evaluation and validation |
| promptstrike | Jailbreak, indirect-injection and adversarial evaluation |
| ModelHawk | Static ML-model supply-chain / deserialization security |
| proxy-Strands | Agent policy gating and indirect-injection defense |
| soc-parallax | AI-assisted SOC detection and investigation |
I also maintain private specialist work covering MCP, RAG, memory, agent-loop behavior, training-data poisoning, supply-chain controls and adversarial regression. Private repositories are intentionally not linked here; the public portfolio is the reproducible subset.
Threat model → attack/fixture → detection/defense → benchmark → measured result → limitations
I prefer controlled regression corpora, held-out validation data, explicit false-positive accounting and reproducible CI over unsupported security claims.
Python, FastAPI, TypeScript, Next.js, PostgreSQL, Neo4j, Docker, GitHub Actions, MITRE ATT&CK, MITRE ATLAS, Ollama and LangGraph.
Strengthening AI-security benchmark methodology, cross-repository regression testing and security engineering for agentic systems.