Agentic AI Security · Authorization Boundaries · Attack Surface Management · Service Mesh Security · ML Runtime Security · Coordinated Vulnerability Disclosure
Senior cybersecurity practitioner, independent vulnerability researcher, and open-source security tooling contributor.
Current research centers on trust boundaries in multi-agent AI systems; how autonomous agents, service identities, and humans are distinguished (or fail to be distinguished) by the authorization models that gate consequential actions.
Founder of NetGuard 24/7 LLC · coordinated disclosure, cybersecurity tooling, threat intelligence.
Upstream remediations where I authored or co-authored the patch, the advisory, or both.
| Finding | Project | Status | Disposition |
|---|---|---|---|
| ADK A2A human-in-the-loop confused deputy · CWE-346 | google/adk-python | 🟡 Merged · reverted · successor in review | PR #6462 · 9e9eaa6 · revert 9a32eba · PR #7134 |
Envoy jwt_authn authentication bypass · CWE-287 |
envoyproxy/envoy | ✅ Merged | PR #43630 · 6d005fe |
| TFLite uint64 external-offset overflow · CWE-190 | tensorflow/tensorflow · google-ai-edge/LiteRT | 🟡 Fixed upstream · tests and fuzz target in review | #116632 · PR #116631 · PR #10223 · PR #123123 |
flatbuffer_utils out-of-range Buffer offset/size |
google-ai-edge/LiteRT | 🟡 Approved · awaiting merge | PR #7028 |
| CERT/CC VU#692236 · multi-vendor coordination | React ecosystem | 🟡 Coordinated | reactghost.com |
Featured: Google ADK human-in-the-loop bypass over A2A. Identified and authored the fix for a trust-boundary failure in Google's Agent Development Kit, where a tool confirmation arriving over the Agent-to-Agent protocol could satisfy the human-approval gate gating confirmation-protected tools. The confirmation check keyed on the protocol message role (role="user") rather than on message provenance, so a remote agent could effectively self-approve actions that were designed to require a person. Reported through Google's VRP; public issue #6461, fix merged to main as 9e9eaa6. The patch rejects A2A-originated tool confirmations so machine provenance is preserved across the boundary. That first fix was reverted on Aug 20, 2026 (9a32eba) after it blocked legitimate confirmations; the successor, PR #7134, replaces the channel heuristic with a CallerPrincipal carried on the invocation context: the serving layer records whether it authenticated the caller, and the confirmation processor refuses an approval that lacks verified human provenance, with strict mode behind the feature registry. It is rebased on current main and in review.
Protocol role ≠ security principal ≠ human authority. As agentic systems mature, authorization models have to treat autonomous agents as distinct actors and read the absence of verified human provenance as denial, not consent.
Featured: Envoy jwt_authn confused-deputy fix. Authored the fix for an authorization-boundary failure in Envoy's JWT filter where extract_only_without_validation paired with claim_to_headers produced HTTP headers indistinguishable from cryptographically validated ones, letting a forged alg:none token satisfy downstream RBAC. Reported through Envoy's private security advisory process (GHSA-gr4r-79wp-5w3x, reporter credit accepted); the public PR added a verification_status_header field with runtime-guarded staged rollout. Merged into main on May 4, 2026 as commit 6d005fe.
Active coordinated-disclosure patches submitted upstream to Google and OSS projects. States current as of October 2026.
| Contribution | Project | State | Reference |
|---|---|---|---|
TFLite model-load / interpreter fuzz target + overflow-safe interpreter_builder bounds checks |
tensorflow/tensorflow | In review | PR #123123 |
tflite::Verify() regression tests for the uint64 external-offset wrap |
google-ai-edge/LiteRT | In review | PR #10223 |
ADK CallerPrincipal gate for human-in-the-loop confirmations |
google/adk-python | In review | PR #7134 |
| PayPal REST API secret detector + OAuth2 validator | google/osv-scalibr | In review | PR #1815 |
Additional memory-safety and path-traversal disclosures in TensorFlow, LiteRT, and MediaPipe are under vendor review.
| Project | Description | Stack |
|---|---|---|
| CitrixScan | Citrix NetScaler ADC/Gateway security scanner. 25 CVEs, 10 fingerprint vectors, GZIP timestamp analysis, IoC detection. | Python |
| cve-2026-1731-scanner | Passive scanner for CVE-2026-1731 (BeyondTrust Remote Support / PRA pre-auth RCE). Defensive and educational use. | Python |
| ADK caller-principal gate | Upstream contribution: CallerPrincipal on the invocation context, populated at the A2A edge, so confirmation-protected tools refuse approvals without verified human provenance. |
Python |
| TFLite interpreter fuzz target | Upstream contribution: FuzzTest harness for model load, interpreter build and invoke, plus overflow-safe external-offset bounds checks in interpreter_builder.cc. |
C++ |
Envoy jwt_authn patch |
Upstream contribution: verification_status_header field, runtime guard, RBAC integration example, security-considerations docs. |
C++ |



