Skip to content
View Pyhroff's full-sized avatar

Highlights

  • Pro

Organizations

@zka19-team

Block or report Pyhroff

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Pyhroff/README.md

Praising Harris Ratnam

Computer science undergraduate focused on security for AI systems: scanners, red-team tooling, evaluation harnesses and defensive infrastructure for agents, MCP servers, RAG pipelines and model artifacts.

🛡️ AI Security Flagship

aisec-suite is the umbrella for my AI-security engineering work: a unified CLI, normalized findings, JSON/SARIF reporting, baselines, policy-as-code and CI enforcement across multiple AI trust boundaries.

Public engineering work

Project Focus
aisec-suite Umbrella AI-security scanner and common reporting/CI layer
mcp-scan-study Empirical MCP-security evaluation and validation
promptstrike Jailbreak, indirect-injection and adversarial evaluation
ModelHawk Static ML-model supply-chain / deserialization security
proxy-Strands Agent policy gating and indirect-injection defense
soc-parallax AI-assisted SOC detection and investigation

Private R&D

I also maintain private specialist work covering MCP, RAG, memory, agent-loop behavior, training-data poisoning, supply-chain controls and adversarial regression. Private repositories are intentionally not linked here; the public portfolio is the reproducible subset.

🔬 How I evaluate security

Threat model → attack/fixture → detection/defense → benchmark → measured result → limitations

I prefer controlled regression corpora, held-out validation data, explicit false-positive accounting and reproducible CI over unsupported security claims.

Stack

Python, FastAPI, TypeScript, Next.js, PostgreSQL, Neo4j, Docker, GitHub Actions, MITRE ATT&CK, MITRE ATLAS, Ollama and LangGraph.

Currently

Strengthening AI-security benchmark methodology, cross-repository regression testing and security engineering for agentic systems.

Contact

praisinghharris@gmail.com · LinkedIn

Pinned Loading

  1. aisec-suite aisec-suite Public

    Run static security scanners over AI-agent projects: MCP servers, agent memory files and RAG documents. SARIF output, baselines and reachability analysis.

    Python

  2. mcp-scan-study mcp-scan-study Public

    Empirical study of 135 public MCP-server repos: hand-labelled scanner findings with confidence intervals, and a measured false-positive reduction.

    Python

  3. soc-parallax soc-parallax Public

    SOC detection platform: attributable risk scores, MITRE ATT&CK rulebook, incident correlation in Neo4j, evidence-checked narratives. FastAPI, PostgreSQL, Next.js.

    Python 1

  4. ModelHawk ModelHawk Public

    Static scanner that detects code-execution backdoors in PyTorch/pickle ML model files (pickle-deserialization RCE), with an offensive demo generator. Python, stdlib-only.

    Python 1

  5. promptstrike promptstrike Public

    Automated adversarial red-teaming CLI for LLMs — PAIR/TAP/Crescendo jailbreak algorithms, live dashboard, multi-model sweep comparison, CI/CD safety gate

    Python 1