PhiloCyber / AI security practice
Your systems now think.Their security model has to catch up.
I secure what teams are shipping with GenAI: LLM applications, autonomous agents and MCP integrations. Threat modeling, penetration testing and policy, all backed by published research.
Explore the practiceUser goalIntentOrchestratorPlan · delegateResolver agentRetrieve · synthesizeSecurity agentInspect · verifyPolicy gateIdentity · scope · allowMCP toolScoped capabilityUntrusted contentProvider responseGoalTaskReviewCallHostileVerified×RejectedTrust boundary
Security practice
Work at the point where models, tools and business logic meet.
Each engagement turns a vague concern about AI risk into boundaries, attack paths and decisions your team can act on.
- S/01Threat Modeling for AI SystemsA structured security review of how your agents, LLM features and MCP integrations could be misused, delivered one week after a single session with the people who built it.
- S/02Penetration Testing for Agents, LLMs and MCPsAuthorized adversarial testing of your deployed AI application, from prompt injection and tool abuse to complete data-exfiltration chains. Retest included.
- S/03AI Security Policy and GovernancePractical rules, review paths and evidence requirements for using and shipping AI without turning governance into a bottleneck.
Public evidence
Read the thinking before you hire it.
A few pieces that show how I work. The full archive lives on the blog.
R/01MCP Security for Enterprise Organizations: Real-world experiences and advanced defenseR/02My First Skills Security Review: OWASP AST10, SkillSpector, and from 60 Findings to 5 Real OnesR/03Indirect Prompt Injection: Manipulating LLMs Through Hidden CommandsR/04DemonAgent Exposed: Understanding Multi-Backdoor Implantation Attacks on LLMs
Bring the architecture
Something already in production you are not sure about?
Tell me what you are building and what worries you about it. If it is not something I can help with, I will tell you that too.
Tell me what you are building
