Application & AI security. I build tooling that sits between autonomous systems and the things they can break — policy enforcement for AI agents, vulnerability triage that survives contact with a real backlog, and adversarial harnesses for testing AI code-review tools.
| Project | What it does |
|---|---|
| agent-guard | Zero-trust governance control plane for autonomous AI agents — RBAC/ABAC policy, DLP exfiltration blocking, credential isolation, human approval gates, adaptive risk scoring, and a tamper-evident audit ledger. |
| security-findings-mapper | Atlassian Forge app that turns noisy scanner output into deduplicated, actionable Jira issues. |
| prompt-injection-test-harness | Authorized red-team fixture for measuring whether AI code-review tools fall for indirect prompt injection. |
| cipher-notes | Secure notes app — Fernet symmetric encryption gated by OpenCV face verification. |
| web-designs | 20+ landing pages and UI experiments, most with live previews. |
Security — application security, AI/LLM security, prompt injection, agent governance, DevSecOps automation
Building with — Python, TypeScript, React, Next.js, Node.js, FastAPI, Docker
Open to collaborating on AI security tooling and offensive-security research.