I work on agentic security: scanners an agent can actually run, the harness around them, and whether any of it actually helps.
Cyber Security Engineering at Iowa State, class of 2027. I'm a Security Researcher at Anitu Security Labs, building agent-native SAST/DAST and vuln-discovery pipelines. Before that I interned twice as a Security Engineer at Amazon.
The Agent Is Not the Scanner. 11 models, skills vs MCP vs a control. Short version: scaffolding helps weak models and gets in the way of strong ones. tl;dr sec #334 picked it up.
- The Scaffolding — agent-agnostic harness (skills + MCP + rules). This is how I found CVE-2026-53626 and CVE-2026-57152 in GLPI.
- Lattice Mind — recon and vuln detection an agent can steer: fingerprint, probe, score, then check if the finding is real.
I used to captain Iowa State's CTF team, PseudoSudo.


