Offensive security for the swarm.
Independent security researcher — multi-agent & embodied AI.
Founder of MASec Lab: offensive tooling & audit methodology for the layer between agents.
maseclab.com · Blog · x.com/maseclab · Bugcrowd · HTB
Offensive security + agentic-AI safety. The industry is racing to test AI models; the riskier surface — how agents coordinate, delegate and act together — goes largely unexamined. I build the methodology and tooling for that layer, and publish it openly.
Single-agent safety doesn't compose. The boundary moved from the model to the protocol traffic between agents — that's where MASec Lab works.
| CyberAI — offensive platform · Apache-2.0 | Runtime offensive testing for MCP servers and LLM agents — blind findings proven out-of-band, not inferred from response diffs. Coordinated specialist agents for recon, exploitation and reporting; native tool-calling, prompt-injection defence, cost/budget tracking, structured findings. Air-gapped-ready, 3000+ tests. |
| mas-sentry-toolkit — defensive audit · AGPL-3.0 · PyPI | Active scanner that audits agentic systems from the outside: speaks MCP / A2A / MQTT / AMQP on the wire and probes live targets instead of reading config off disk. Deterministic — no model gives the verdict, nothing about the target leaves the host. ABFP behavioural fingerprinting, unified threat engine, SARIF out, OWASP Agentic Top-10 (ASI01–ASI10). |
pip install mas-sentry-toolkit
- The Layer Nobody Baselines — runtime behavioural detection for the MCP agent bus. →
- Hunting MCP Tool Poisoning — malicious instructions hidden in tool metadata, and how CyberAI catches them. →
- Agent-in-the-Middle — what's wrong with unsigned A2A agent cards. →
- Why the coordination layer is the real attack surface — single-agent safety doesn't compose. →
- ABFP — Agent Behavioural FingerPrint. Baseline an agent by how it acts across 6 dimensions; surface drift, hijack and impersonation as statistical deviations instead of predefined rules.
- HCAP — Hierarchical Capability & Attestation Protocol. Prove what an agent may do and where its authority came from, down a delegation chain. N-of-M quorum, confused-deputy detection.
- ASI mapping — findings mapped to the OWASP Agentic Top 10 (2026) for a shared, recognised taxonomy.
- phantom-grid — free Burp Collaborator alternative: OOB interaction capture (HTTP/HTTPS/DNS), SQLite store + DNS exfil reassembly.
- phantom-intel — CVE threat-intelligence platform on the NVD API 2.0 (CVSS, exploit assessment, CWE KB, EN/RU).
- reality-probe — VLESS/Reality SNI selection under 2026 DPI: freeze-test, ASN/subnet topology scoring, subnet-neighbor discovery.
- OSCP+ track · active on PortSwigger / HackTheBox / TryHackMe
- Bug bounty — Bugcrowd · Intigriti · Immunefi
- Web3 audit stack: Foundry · Slither · Aderyn · Halmos · Echidna
The agentic frontier is shipping faster than anyone is testing it.

