Portfolio / DEV.to / LinkedIn / Medium
Agents that remember. Actions with boundaries. Systems you can inspect.
I build at the intersection of applied AI, cybersecurity, and developer tools. My projects explore what agents should remember, what they should be allowed to do, and what evidence they leave behind.
What should an agent be allowed to do, and how do you prove it respected the boundary?
Agentic Security Lab explores that question with a deny-by-default policy boundary for tool calls, runtime enforcement, adversarial cases, and audit receipts.
| Project | What it does | Area |
|---|---|---|
| mcpscan | Scans MCP servers and agent projects for risky tools, permissions, commands, and secrets before install. | Agent security |
| agent-memory-protocol | An open protocol and reference implementation for durable, inspectable agent memory. | Agent infrastructure |
| ai-safety-compass | A local-first workspace that turns AI workflow facts into safeguards, hard stops, and review records. | Applied AI |
| secops-toolkit-mcp | Defensive utilities for IOC handling, hashing, CIDR checks, repository checks, and command assessment. | Security tooling |
More from the workbench
- autoreview: AI-powered pull request review in the terminal, with support for multiple model providers.
- dev-to-mcp: Browse DEV.to articles and challenges, and publish authenticated posts through MCP.
- human-approval-gate: An Agent Zero plugin that pauses high-risk actions for human approval.
- payment-webhook-repair-lab: A local lab for retries, idempotency, state protection, and webhook failure recovery.
Fixes I found while using these tools, merged by their maintainers.
| Project | Contribution |
|---|---|
| ahujasid/mcp-for-blender | Handle multi-byte UTF-8 sequences split across socket reads. |
| NVIDIA/SkillSpector | Stop the code-example heuristic from silently dropping SKILL.md findings. |
| teamhanko/hanko | Propagate context and fix a duplicate defer in the OAuth providers. |
| Tencent/AI-Infra-Guard | Surface the underlying error when an MCP scan can't connect. |
| gpustack/gpustack | Propagate asyncio cancellation and remove mutable default arguments. |
| zalando/skipper | Isolate the upgrade proxy dialer and give it a 30s timeout. |
| agent0ai/a0-plugins | Three Agent Zero plugins: human approval gate, chat jumper, chat status lights. |
Concrete workflow first. A small runnable implementation next. Then normal paths, adversarial inputs, and documented limits. I care about useful demos and evidence that someone else can reproduce.
I write about AI engineering, security, and what I learn while building. Find my articles on DEV.to and Medium.
For collaborations around agent security, developer tools, technical documentation, or code-backed demos, connect on LinkedIn.
Implementation first. Evidence over hype.


