Engagements
The bench is the résumé.
I break AI systems for a living and I build the tools that prove I can. The offensive frameworks, the defender's other half, the forensics that stay honest — all of it is open, running, and checkable. The résumé is a formality. This is the actual proof.
What I take on
- Adversarial evaluation of frontier and multimodal models — prompt injection, tool poisoning, agent-to-agent trust boundaries, and the goal drift that only shows up under load.
- The defender’s half — deception tokens, egress forensics, and attribution that never mistakes an IP for a person.
- Architecture reviews for teams shipping agentic systems into places they can’t fully see, plus the working detection tooling you keep after I leave.
The bench
The attack side. Where the payload lives in the pixels and the parser trusts the wrong byte.
The half most red teamers skip. You don't understand a trap until you've had to set one that works.
The part that stays honest about the difference between a lead and an identity.
What shipped
Most recently: a month-long AI red-team engagement on a flagship, newest-generation model release at a leading frontier lab — under NDA, and current commercial vetting passed short of a government clearance. Working the methods labs are defending against right now, not last year's playbook. I can't name it. I can tell you what the work is made of.
A private channel had a device on it that the roster did not account for. I built a canary — a link that previewed as an ordinary shared photo and logged the truth: an unrostered handset, iPhone and Android both present. It was one piece of a real investigation. I handed over the clean timeline and stepped back when the detective did not want outside help. An IP is a lead, not an identity — the tool knows the difference, and so do I.
The bench is open on GitHub and the research is open here — the frontier attack surface, the training-pipeline supply chain, SPID and eIDAS threat models, the surveillance stack read from the inside. Written to be checked, not admired.
If you've got a system you're not sure about, or a red-team program that needs someone who's worked both sides of the bench — the bench is public and the work speaks first. Authorized scope only. I bring the paperwork discipline, not just the exploit.
github.com/ghostintheprompt