I build security and evaluation infrastructure for agentic systems — software that makes authority explicit, evidence reproducible, and failure modes legible.
U.S. person · no sponsorship required · TPM / TEE / MCP policy · Python + TypeScript
- Attested Capability Broker — Independent reference experiment using released AgenTrust components to bind TPM-appraised platform state and authenticated agent identity to a short-lived, minimal-scope MCP capability with at-most-once redemption.
- Resource-Bound Authorization — Independent reference implementation of resource audience enforcement, action binding, explicit delegation attenuation, and at-most-once redemption, with reproducible Compose procedures.
- confined-tool-execution — Linux tool-process confinement: workspace and audience from the capability; denied open/connect emit a record. Not a container runtime.
- GoldKey Guard — Policy-bound authorization receipts and a local, fail-closed enforcement path for privileged agent actions.
- SENTINEL — Reproducible prompt-injection evaluation and explicit policy gating for tool-using agents.
- raptor-trace — TRACE replay-transfer evidence, validators, and working note for the AI Agent Security competition.
- EMAP — Artifact-grounded experiments on multi-agent architectures under hard token budgets.
- cMCP — Consolidated TPM NV parsing on a shared API and added portable reference fixtures.
- Agent Manifest — Added shared, typed parsing for TPM NV attestations.
- cA2A — Added an official Python A2A SDK loopback example, integration documentation, and transport regression tests.
- Framework integrations — Improved LangGraph callback interoperability and added released-framework coverage.
- Reef — Improved release-read responsiveness during long-running evolution.
Least privilege · Explicit authorization · Reproducible evaluation ·
Auditable interfaces
Python · TypeScript/JavaScript · systems security


