AI & Agent Security
Your agent can read data, call tools, and take actions. I find out what an attacker can make it do — before you ship.
10+ years of offensive AppSec and secure code review for banks and Fortune 500 tech companies, now pointed at AI.
What I Review
An LLM app is a normal app with a new, very persuadable component in the middle. I test both halves — and especially the places where they meet.
Direct and indirect — through the documents, web pages, emails, tickets, and tool output your model reads. Can an outsider steer your agent without ever talking to it?
What your agent can do, with whose credentials, and what happens when someone tricks it into doing it. Over-scoped tokens, missing approval steps, and actions that can’t be undone.
System prompts, RAG sources, secrets in context, and other users’ data showing up where it shouldn’t — including through links, images, and tool calls that quietly send data out.
Model output is untrusted input. I follow it into your HTML, SQL, shell commands, and downstream APIs to find where it turns into XSS, injection, or code execution.
The tools, plugins, and MCP servers your agent connects to — yours and third-party. Auth, input validation, and what a malicious or compromised tool could do.
Auth, session handling, multi-tenancy, APIs, and the glue code — reviewed line by line, like any other application. This is still where most serious bugs live.
Who It’s For
What You Get
Every finding comes with the exact prompts, payloads, and steps that triggered it — so your team can see it happen, not just read about it.
Severity based on what an attacker can actually do to your users and your data — not a generic checklist score.
Concrete remediation at the code and architecture level: permission scoping, approval gates, output encoding, and isolation that hold up.
A short executive summary for leadership, auditors, and customers asking how your AI features are secured.
How It Works
Free 30-minute call. Walk me through what it does, and you’ll leave with the biggest risks I see and a fixed price to review it.
Book a Scoping Call