Engagements

The bench is the résumé.

I break AI systems for a living and I build the tools that prove I can. The offensive frameworks, the defender's other half, the forensics that stay honest — all of it is open, running, and checkable. The résumé is a formality. This is the actual proof.

What I take on

  • Adversarial evaluation of frontier and multimodal models — prompt injection, tool poisoning, agent-to-agent trust boundaries, and the goal drift that only shows up under load.
  • The defender’s half — deception tokens, egress forensics, and attribution that never mistakes an IP for a person.
  • Architecture reviews for teams shipping agentic systems into places they can’t fully see, plus the working detection tooling you keep after I leave.

The bench

Forensics & Attribution

The part that stays honest about the difference between a lead and an identity.

What shipped

A month inside a frontier red team

Most recently: a month-long AI red-team engagement on a flagship, newest-generation model release at a leading frontier lab — under NDA, and current commercial vetting passed short of a government clearance. Working the methods labs are defending against right now, not last year's playbook. I can't name it. I can tell you what the work is made of.

A canary that named the extra device

A private channel had a device on it that the roster did not account for. I built a canary — a link that previewed as an ordinary shared photo and logged the truth: an unrostered handset, iPhone and Android both present. It was one piece of a real investigation. I handed over the clean timeline and stepped back when the detective did not want outside help. An IP is a lead, not an identity — the tool knows the difference, and so do I.

The public record

The bench is open on GitHub and the research is open here — the frontier attack surface, the training-pipeline supply chain, SPID and eIDAS threat models, the surveillance stack read from the inside. Written to be checked, not admired.

Read the research record →

If you've got a system you're not sure about, or a red-team program that needs someone who's worked both sides of the bench — the bench is public and the work speaks first. Authorized scope only. I bring the paperwork discipline, not just the exploit.

github.com/ghostintheprompt