Artificial Inteligence
-
Accelerating Federal Authorization Through Agentic Assessment
Executive Summary Agentic workflows can materially reduce the time required to prepare and assess federal authorization packages by turning large volumes of system information into a traceable assessment record. The approach described in this paper has been implemented and tested across the full authorization workflow. The results show that a governed agentic system can perform…
-
Trident – Source Code Vulnerability Triage Engine
Trident is a self hosted platform for identifying, correlating, reviewing, and prioritizing vulnerabilities in source code. The problem is not finding vulnerabilities. Static analyzers, dependency scanners, secret detection tools, and configuration scanners already do that well. The problem is what comes next. A typical scan can produce hundreds or thousands of findings with very little…
-
ATO Bot
Source Code: GitHub Repository Technical White Paper: ATOBot Technical White Paper Installation Tutorial: Watch on YouTube Status: Active Development ATO Bot is an open source platform for performing NIST SP 800 53 assessment and supporting the broader federal Authority to Operate process. I built it to see how far AI could be applied to authorization…
-
BuildLLM Learning Lab
BuildLLM teaches you how a decoder-only language model is built, trained, evaluated, and scaled. You will work with the same implementation used by all three model iterations in this repository. The smaller models are not separate tutorial programs. Architecture, runtime, and data choices change through configuration and command-line arguments while the training framework remains the…
-
Engineering a Reliable, Virtualized, Fully Agentic Pentest Platform Through Loop Engineering
Executive Summary CyberOps is a reliable, stable, fully agentic penetration-testing platform built utilizing loop engineering. It coordinates a real offensive toolkit across long-running authorized missions, maintains durable mission state, and turns tool output into structured evidence and analyst-grade findings. The platform is virtualized: the same core architecture can run on premises or in cloud infrastructure,…
-
Candidate Selection Board
The Candidate Selection Board is a self-hosted platform that utilizes a 13-agent AI model to facilitate structured hiring decisions through expert evaluations and consensus recommendations. It includes multi-stage reviews, robust audit trails, and FISMA Moderate compliance for federal use, ensuring transparency and defensibility in the hiring process.
-
Nutrition AI Pro
Summary Nutrition AI Pro is an agentic AI recipe and nutrition-content production platform for fitness-focused teams. It helps content teams move beyond one-shot prompting by combining structured recipe generation, iterative quality critique, human review, content conversion, prompt management, and operational controls in one self-hosted application. Use it to produce recipe cards, blog posts, social assets,…
-
CyberTabletop
Summary CyberTabletop is an agentic AI cybersecurity tabletop platform for running live, scored incident response exercises. It helps security teams move beyond static slide decks by combining AI-generated scenarios, adaptive injects, role-based player decisions, facilitator controls, real-time scoring, and structured debriefs. Use it to rehearse ransomware, business email compromise, data breach, insider threat, DDoS, supply-chain,…
-
AI Vulnerability Discovery and the Case for Systems Security Engineering
For decades, the approach to building technology has operated on an implicit assumption that security could be addressed after the fact. Organizations built systems to meet functional requirements, shipped them when they worked, and addressed security through periodic assessments, patching, and monitoring. The economics of the threat environment supported this approach. Vulnerability discovery was expensive,…
-
A Case Study in AI Assisted Development and Rapid System Delivery
Building a Production Quality, NIST SP 800 53 Rev. 5 Aligned Tabletop Exercise Platform in Approximately Four Hours of Active Work Executive Summary I built a production-ready cybersecurity tabletop exercise platform in approximately four hours of active work spread across two days. The application includes a live multiplayer exercise engine, AI-generated scenarios, three AI provider…
-
How AI System Behavior Shapes Oversight and Risk Distinguishing Generative and Agentic Systems
Artificial intelligence is being integrated into the processes, platforms, and services that organizations depend on to deliver value. These implementations may involve systems that generate natural language in response to prompts, or systems designed to carry out defined workflows without constant human intervention. In many cases, the terminology used to describe these capabilities is applied…
-
How AI System Behavior Shapes Oversight and Risk
Learn the key differences between generative and agentic AI, how autonomy shapes oversight and why precision in AI governance reduces operational risk. Artificial intelligence is being integrated into the processes, platforms and services that organizations depend on to deliver value. These implementations may involve systems that generate natural language in response to prompts, or systems…
-
Securing AI: Addressing the OWASP Top 10 for Large Language Model Applications
AI Is Just Software, But It Is Not Just Software Artificial Intelligence (AI) is frequently portrayed as a disruptive force with the potential to revolutionize industries, optimize workflows, and enhance decision-making in ways that were often seen as unattainable. While this perspective highlights AI’s impact, it overlooks a fundamental reality. AI is still software at…
-
Understanding and Addressing Unbounded Consumption in AI Systems
AI systems require substantial computational resources to process data efficiently. These systems generate responses that enable automation by performing tasks typically involving human intervention. They carry out complex operations, enhancing analytical capabilities and improving efficiency across various applications. Additionally, they integrate with other platforms to facilitate seamless data exchange and ensure interoperability within an organization’s…
-
Understanding and Addressing Inaccurate or Misleading Outputs in AI Systems
Inaccurate outputs weaken the trustworthiness of AI systems, particularly large language models (LLMs), by generating responses that appear credible but lack accuracy. When incorrect information is presented as a fact, users may unknowingly rely on flawed outputs that seem correct but ultimately are fabricated. The underlying causes can stem from weaknesses in training data, insufficient…
-
Understanding and Addressing Vector and Embedding Weaknesses in AI Systems
Vectors and embeddings are essential components of modern AI systems, enabling the efficient processing, representation, and retrieval of complex information. These structures enhance the AI system’s ability to interpret and connect data meaningfully, leading to improved relevance and accuracy in generated responses. However, this design can also introduce vulnerabilities that compromise the reliability of the…
-
Understanding and Addressing System Prompt Leakage in AI Systems
System prompts are essential to an AI system. Unlike user-provided prompts, these are embedded instructions that guide how a model processes input and generates output. When system prompts are exposed, they give adversaries important information that can be used to bypass access restrictions, alter decision-making rules, or extract sensitive information. Protecting these prompts is important…
-
Understanding and Addressing Excessive Agency in AI Systems
As AI systems take on more complex roles, their ability to make decisions and perform tasks independently presents significant opportunities to optimize operations and foster innovation. However, this growing autonomy also introduces new challenges, particularly when these systems function outside their intended scope. Without careful management, such overreach can result in unintended consequences that undermine…
-
Understanding and Addressing Improper Output Handling in AI Systems
AI systems assist in decision-making, improve operational efficiency, and automate complex processes. However, if the output is not managed carefully, it can result in significant organizational issues, such as misleading inaccuracies and inadvertent exposure of sensitive information. These risks can undermine the reliability and effectiveness of AI systems, posing potential legal, ethical, and reputational challenges…
-
Understanding and Addressing Data and Model Poisoning in AI Systems
AI systems are heavily dependent on data, and the quality and integrity of that data significantly impact their performance. However, this reliance also creates vulnerabilities. Data and model poisoning attacks occur when the data used to train or update these systems is intentionally manipulated. Such attacks can compromise the accuracy and reliability of AI outputs,…
-
Understanding and Addressing Supply Chain Risks in AI Systems
AI systems typically depend on various components from third-party sources, such as software libraries, pre-trained models, APIs, and hardware. These dependencies can introduce supply chain risks undermining security, reliability, and functionality. Effectively managing these risks is crucial for deploying AI systems that organizations can trust. What Are Supply Chain Risks in AI Systems? Supply chain…
-
Understanding and Addressing Sensitive Information Disclosure in AI Systems
Sensitive information disclosure occurs when AI systems unintentionally share private or confidential information. Organizations that utilize AI to handle sensitive data must understand this risk and take proactive steps to prevent it. This article explores how AI can inadvertently expose confidential information and outlines the measures necessary to prevent such breaches. What Is Sensitive Information…
-
Understanding and Addressing Prompt Injection in AI Systems
Artificial intelligence (AI) is transforming how organizations make decisions. However, it also introduces risks that must be addressed to protect operations and data. One such risk is prompt injection, a vulnerability that can manipulate AI systems to produce harmful or unintended results. What Is Prompt Injection? Prompt injection occurs when a user submits input that…
-
Key Takeaways from CISA/NCSC Guidelines for Secure AI System Development
AI security is a hot topic in today’s cybersecurity landscape due to the increasing integration of AI systems in essential areas like healthcare, finance, transportation, and national security. My company advocates for the responsible design and implementation of AI by taking an ethical, human-on-the-loop approach to AI operations. While offering immense benefits, these systems also…
-
Recommendations for Implementing Secure AI
As I wrote in my previous article Key Takeaways from CISA/NCSC Guidelines for Secure AI System Development, CISA’s “Guidelines for Secure AI System Development” provide a clear path for safely managing AI systems. They highlight the importance of building security into AI systems from the beginning. These guidelines help organizations deal with specific AI threats,…
-
The Attacks of the Future
What might the most damaging attacks of the future look like? The answer to the question may lie somewhere between the known patterns that attackers have established over the years, and signs that we are starting to see today. A look back It started with the sun and the moon. Solar Sunrise was discovered in…
-
Drones, AI, and Security – The Future of Terrorism and Warfare
The purpose behind this article is to pull together some interesting news from the week of 11/13/2017 as it relates to the future use of advanced drone technologies and their ability to cause serious physical harm. In the below article you are presented with a fictional story (video) where advanced drones are used to selectively…



























