Skip to content
View cdxiaodong's full-sized avatar
🎯
Focusing
🎯
Focusing

Organizations

@miao2sec

Block or report cdxiaodong

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cdxiaodong/README.md

Hi, I'm CDxiaodong

Agentic AI · AI Agent Security · LLM Engineering · Security Automation

CDxiaodong focus

Blog GitHub followers Agent project stars Email

Agentic AI AI Agent Security LLM post-training Open source contributor


👨‍💻 About Me

I am an AI Agent security researcher and engineer working across runtime guardrails, agent evaluation, LLM post-training, cloud-native security, and enterprise automation. I build systems from requirements discovery and prototype design through engineering, evaluation, iteration, and delivery -- not just demos.

我是一名偏工程落地的 AI Agent 安全研究与开发人员,长期在 AI、安全、全栈和自动化的交叉区域工作,能够把模糊需求转化为可验证 PoC、可部署 Agent 工作流和可复用评测体系。

📊 Evidence 🚀 Scope
3,000+ evaluation records Agent and AI-security benchmark engineering
9 core metrics Model selection, architecture comparison, and regression evaluation
14 OpenClaw security PRs 11 vulnerability classes across trust boundaries and runtime behavior
100+ AI workflows Automation, data processing, security operations, and knowledge work
1 granted patent Cloud-security validation methodology

🏆 Rank & GitHub Activity

CDxiaodong GitHub Rank

🧰 AI & Engineering Toolkit

Core engineering toolkit

Layer Tools and methods
🤖 Agentic AI LangGraph LangChain LlamaIndex MCP Claude Agent SDK ReAct
🧠 Model Engineering Transformers SFT LoRA DPO GRPO Unsloth
📐 Evaluation & Retrieval LLM-as-Judge Benchmark RAG FAISS Milvus BM25
⚙️ Inference & Delivery vLLM FastAPI Docker Kubernetes n8n CI/CD
🛡️ Security Engineering Agent Security Prompt Injection Behavior Audit Cloud Native RASP BAS

🎯 Current Focus

  • Secure Agent Systems -- scope enforcement, permission boundaries, tool-call review, human approval, audit trails, and deterministic safety controls.
  • Agent Evaluation -- reproducible benchmarks, long-horizon task analysis, LLM-as-Judge, regression testing, token/cost tracking, and failure attribution.
  • LLM Post-training -- SFT, LoRA/QLoRA, DPO, GRPO, trajectory distillation, code-gym RL, reward design, and reward-hacking defenses.
  • Enterprise AI Delivery -- Agent workflows for security operations, document intelligence, business analysis, API integration, and private-model deployment.

🚀 Featured Projects & Open-source Impact

Featured projects and open-source contributions

cain-agent · AionUi · Cloud Tool · fscan · Xiaobei · Apt_t00ls

🔬 AI Security Research

  • Audited OpenClaw security boundaries and submitted 14 security PRs, covering 11 vulnerability classes including SSRF, token exposure, path traversal, prototype pollution, environment-variable injection/RCE, and Windows junction escape.
  • Research coding-agent trust boundaries across Claude Code, Codex, OpenCode, Gemini CLI, OpenClaw, and AI-integrated browsers, with responsible disclosures through Anthropic VDP, Google Bug Hunters, and GitHub Security Advisories.
  • Contributed security advisories including GHSA-g5hv-4fwh-h87r and GHSA-wqv3-rc3w-52r6.
  • Built benchmark tooling around multi-step reasoning, agent architecture, tool-use reliability, validation quality, and operational efficiency.
  • Previous research spans cloud/container security, BAS/AEV, RASP, endpoint/runtime security, Java code auditing, and responsible CNVD/CNNVD disclosure.

🥇 Security Challenge Gallery

EKS Cluster Game K8s Lan Party
EKS Cluster Game K8s Lan Party
Cloud Hunter Wiz Perimeter Leak
Cloud Hunter Wiz Perimeter Leak
AI Security Challenge Split Horizon
AI Security Challenge Split Horizon

🧭 Project & Tool Map

Category Projects and contributions
🤖 Agentic AI & LLM cain-agent · dsh-guardian · dsh-island · dsh-llm-inspector · claude-agent-sdk-dev · cloud_native_mcp
☁️ Cloud & Container Security Cloud_Unauthorized_Tool · ebpf-c-tample-action · k8s-2024-21626 · CVE-2024-21626 · auto_change_version_for_cloudnative
🌐 Application, Network & Runtime Security Apt_t00ls fork · ASM-hide-RASP · fscan contribution · KubeAPI-Inspector contribution · Deadpool contribution · JarEditor contribution
🖥️ Binary & Endpoint Research Transacted-Hollowing-allinone · audio-reverse-shell · AVkiller · packer · STEAL-HOOK · Binary Utility Functions
⚙️ Automation & Developer Tools Site-Specific Extension Manager · workflow-use · clash-verge-mcp-pro · web-check-zh · Docker utilities · Windows Internals notes
🧩 Products & Interactive Systems Cloud-Native ATT&CK Matrix · Top 7 Cloud Attack Paths · Favorite Articles Real-Time

📝 Articles You Don't Want to Miss

⭐ Featured

📚 More Articles — Expand the complete topic archive (50+)

🤖 AI, Agent & Model Engineering

☁️ Cloud Native & Container Security

🌩️ AWS, Azure & GCP Security

🌐 Application Security, Java & RASP

🖥️ Endpoint, Binary & Systems Engineering

⚙️ Automation, Workflow & Product Delivery

🎯 CTF, Competitions & Benchmarks

📓 Annual Notes

Browse the full live archive at cdxiaodong.life.

📈 Contribution Landscape

CDxiaodong 3D contribution graph
Complete legacy profile and writing archive

The previous README, including every historical project and article link, is preserved verbatim in archive/README-legacy-2026-08-27.md.


Repositories · Pull Requests · Blog · Email

Profile views

Pinned Loading

  1. Cloud_Unauthorized_Tool Cloud_Unauthorized_Tool Public

    A tool designed to detect and exploit unauthorized access in various services. It supports the following functionalities \n\n This is a tool for attacking the cloud environment from the outside, so…

    Go 55 1

  2. iOfficeAI/AionUi iOfficeAI/AionUi Public

    Open-source 24/7 Cowork app for OpenClaw, Hermes, Claude Code, Codex, OpenCode and 20+ more CLI Agent | Customize your assistants | Team them up|Star if you like it!

    TypeScript 32.4k 3.3k

  3. White-hua/Apt_t00ls White-hua/Apt_t00ls Public

    高危漏洞利用工具

    Java 1.8k 244

  4. thinkoaa/Deadpool thinkoaa/Deadpool Public

    deadpool代理池工具,可从hunter、quake、fofa等网络空间测绘平台取高质量socks5代理,或本地导入socks5代理,轮询使用代理进行流量转发。

    Go 720 83

  5. CVE-2024-21626 CVE-2024-21626 Public

    CVE-2024-21626-poc-research-Reappearance-andtodo

    5 1

  6. TeamWiseFlow/xiaobei TeamWiseFlow/xiaobei Public

    为OPC/中小微企业量身打造的自媒体获客智能体

    Python 8.5k 1.4k