name : pie-script
focus : Application Security · LLM / AI Agent Safety · Data Systems
philosophy : Empirical, evidence-backed security testing -- not guesswork.
currently : Researching tool-calling vulnerabilities and confused-deputy attacks in agentic LLMs.
learning : OWASP Top 10, LLM Security (OWASP LLM Top 10), TryHackMe Paths.|
Empirical harness testing whether tool-calling LLM agents can be manipulated via prompt injection, confused-deputy attacks, and indirect data injections. 5 OWASP-aligned attack categories. |
Structured scanner evaluating HTTP security response headers against OWASP benchmarks. Graded findings with severity classification and remediation guidance. |
|
AI-assisted log analysis pipeline that flags anomalous patterns in system logs using structured rule matching combined with LLM-based reasoning. |
Structured markdown notes covering every room in TryHackMe's Pre-Security path — networking fundamentals, Linux basics, web principles, and more. |
| Platform | Path / Focus | Status |
|---|---|---|
| 🟥 TryHackMe | Pre-Security Path | ✅ Complete |
| 🟥 TryHackMe | SOC Level 1 / Web Fundamentals | 🔄 In Progress |
| 📖 OWASP | LLM Top 10 — Agentic Security | ✅ Applied |
| 🛡️ Projects | LLM Agent Security Testbed (v1) | ✅ Complete |
| 🛡️ Projects | HTTP Security Header Scanner | ✅ Complete |