Skip to content
View aisamuraiagent-source's full-sized avatar
🖥️
➰💻➰
🖥️
➰💻➰

Block or report aisamuraiagent-source

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Renan Raad

AI Security Engineer — Formal Verification (SMT/z3) + Offensive / Red Team

Founder, Sentinel Forge · EU citizen (Spain) · open to remote / relocation

I build local-first, evidence-first cybersecurity: every claim ships as a re-examinable artifact — a hash, a signature, a reproducible test, a validation record — not an assertion. My core is the control layer between what an AI agent intends and what it actually executes: deterministic, fail-closed enforcement, with traceable evidence at every boundary.

Alongside the defensive core, I do lawful, adversary-informed work — authorized, scoped, lab-safe — to sharpen detections, remediation quality, and proofs. AI is used as a support layer for review, diagnosis, documentation, and remediation planning. Security decisions remain scoped, human-reviewed, reversible where possible, and backed by traceable evidence.

Core Focus

  • AI agent security & deterministic (fail-closed) enforcement
  • Formal verification of authorization properties (SMT/z3, symbolic execution)
  • Blue Team validation · security validation · evidence automation
  • AppSec support · secure remediation · patch validation
  • Threat modeling · risk & residual-risk review
  • Authorized offensive research (SMT/z3 red teaming, CTFs) — to strengthen defense
  • Tamper-evident evidence (hash chains, Ed25519 signatures, trusted timestamping)
  • Local-first defensive automation · audit-ready, sanitized reporting

Public Proof Of Work

Repository Demonstrates Evidence Type
z3-reversing SMT/z3 for security — the same solver used to prove no authorization bypass exists and to find one: 18,000 self-authored solved challenges (9 families) + external picoCTF solves Reproducible solvers, Ed25519-signed certificate & attestation, CTF writeups
lab-records Signed, sanitized records of real defensive operations; hash-verified case study on non-auditable LLM self-report Lab records + SHA-256 sidecars
FCCSecurity-Public Defensive console, public-release governance, validation records, residual-risk tracking Static app, documentation, release-gate evidence
ai-threat-model-dependency-risk-lab Threat modeling, dependency-risk review, remediation planning, human approval gate Threat model, dependency review, remediation plan, validation report
codex-safe-operation-lab-public Human-controlled AI workflow, Windows defensive triage, local-first evidence handling Safe operation docs, static panel, sanitized triage summary

Operating Method

Scope -> Review -> Remediate -> Validate -> Evidence -> Sanitize

Every security claim is bounded by: observed facts; reasonable inferences; hypotheses; recommendations; unknowns. The goal is not vague automation — it is defensive work that can be reviewed, reproduced, audited, or safely sanitized for portfolio use.

Evidence Model

Evidence Class Meaning
Observed Fact Directly seen in file, command output, log, screenshot, diff, hash, test, or artifact
Reasonable Inference Supported by observed facts, but not directly proven
Hypothesis Plausible but not yet validated
Recommendation Action proposed from evidence, risk, or missing validation
Unknown Data still required before a claim can be validated

Boundary

Defensive-primary. Public material is sanitized and does not include secrets, private host data, live target details, credential material, exploit chains, persistence, evasion, malware, or unauthorized third-party activity. Any adversary-informed activity is authorized, scoped, non-destructive, lab-safe (self-authored labs and public CTFs), and used only to improve defenses, detections, remediation quality, and documentation.

Claim Boundary

This profile shows proof of work through public labs and documentation. It does not claim formal certification, third-party audit, legal attribution, complete absence of vulnerabilities, employment, membership, partnership, endorsement, or authorization outside the declared scope of each repository.

AI Assistance

This work is AI-assisted and human-reviewed: AI supports review, diagnosis, documentation, and remediation planning; a human scopes, reviews, decides, and signs the evidence.

Pinned Loading

  1. z3-reversing z3-reversing Public

    Python 1

  2. lab-records lab-records Public

    Signed, sanitized records of real defensive security work - every artifact ships with a SHA-256 sidecar for independent verification.

    1

  3. aisamuraiagent-source aisamuraiagent-source Public

    Defensive AI Systems Builder focused on Codex CLI, Codex Security, secure remediation, patch validation, and audit-ready evidence.