Topic
AI security & red-teaming
Authorised adversarial testing of LLM applications and agents: injection, leakage, excessive agency and trust boundaries.
Case studies
How do you find out how an AI agent can be attacked, before someone else does?
An adversarial testing practice for LLM and agentic systems, with risks categorised against the OWASP LLM Top 10, NIST AI RMF and MITRE ATLAS, on top of a full application security programme.
How do you turn AI red-teaming from a one-off exercise into a repeatable engineering system?
A reference harness that generates adversarial tests, judges outcomes, scores severity against OWASP and MITRE ATLAS, and re-runs every confirmed finding as a CI regression test.
Articles
Testing indirect prompt injection in RAG and agent pipelines
Where untrusted content enters an LLM pipeline, how to design planted-instruction tests with canaries, how to measure attack success, and how to verify defences actually hold.
Security testing AI agents: permissions and trust boundaries
How to test what an AI agent is allowed to do, on whose behalf, and with whose data. Least privilege, confused deputies, MCP trust and approval gates, with a test matrix.
Work with me
Working on a problem like the ones above? I am glad to compare notes.