AI red teamer working on LLM and agentic systems. I build these systems, then break them — the engineering side is where the findings come from.
Nairobi, Kenya (UTC+3) · Blog · LinkedIn · omondiaustine2@gmail.com
vuln-langgraph-001 — A deliberately vulnerable three-agent LangGraph system. Ten documented vulnerabilities, each with a working PoC, a framework mapping, and a remediation: cross-agent injection, confused-deputy tool-argument injection, goal hijacking, state pollution, path traversal, system-prompt leakage.
vuln-rag-001 — An intentionally vulnerable RAG service. A poisoned document planted through an unauthenticated endpoint leaks a system-prompt secret from an entirely benign user query. Attacks are automated and scored with PyRIT and Garak, including a false-positive analysis of the automated scanner.
GenAI-Agent-Security-Initiative — My LangGraph code sample for ASI02 (Tool Misuse & Exploitation), submitted to the OWASP Top 10 for Agentic Applications.
Working through a structured 26-week AI security program in the open at ai-sec-journey — adversarial ML, agentic security, and paired secure/insecure builds.
Competitive red teaming: Gray Swan Arena, Lakera Gandalf (top 8%), Hacker101 (36 points — web and crypto, including a CBC padding oracle written from scratch).
The older repositories here are data science and client engineering work from 2023–2025, before I moved to security full time.
Subcontract engagements with security consultancies and independent consultants:
- adversarial testing of LLM, RAG and agentic systems
- secure code review of AI application code and retrieval pipelines
- turning raw findings into client-ready reports
White-label, and small fixed-price pilots are welcome. A sample report is available on request.
Full-time roles in AI red teaming, LLM security research and agentic security engineering.
Remote, UTC+3 — full overlap with European teams, afternoons with US Eastern. omondiaustine2@gmail.com