Agentic AI · AI Agent Security · LLM Engineering · Security Automation
I am an AI Agent security researcher and engineer working across runtime guardrails, agent evaluation, LLM post-training, cloud-native security, and enterprise automation. I build systems from requirements discovery and prototype design through engineering, evaluation, iteration, and delivery -- not just demos.
我是一名偏工程落地的 AI Agent 安全研究与开发人员,长期在 AI、安全、全栈和自动化的交叉区域工作,能够把模糊需求转化为可验证 PoC、可部署 Agent 工作流和可复用评测体系。
| 📊 Evidence | 🚀 Scope |
|---|---|
| 3,000+ evaluation records | Agent and AI-security benchmark engineering |
| 9 core metrics | Model selection, architecture comparison, and regression evaluation |
| 14 OpenClaw security PRs | 11 vulnerability classes across trust boundaries and runtime behavior |
| 100+ AI workflows | Automation, data processing, security operations, and knowledge work |
| 1 granted patent | Cloud-security validation methodology |
| Layer | Tools and methods |
|---|---|
| 🤖 Agentic AI | |
| 🧠 Model Engineering | |
| 📐 Evaluation & Retrieval | |
| ⚙️ Inference & Delivery | |
| 🛡️ Security Engineering |
- Secure Agent Systems -- scope enforcement, permission boundaries, tool-call review, human approval, audit trails, and deterministic safety controls.
- Agent Evaluation -- reproducible benchmarks, long-horizon task analysis, LLM-as-Judge, regression testing, token/cost tracking, and failure attribution.
- LLM Post-training -- SFT, LoRA/QLoRA, DPO, GRPO, trajectory distillation, code-gym RL, reward design, and reward-hacking defenses.
- Enterprise AI Delivery -- Agent workflows for security operations, document intelligence, business analysis, API integration, and private-model deployment.
cain-agent · AionUi · Cloud Tool · fscan · Xiaobei · Apt_t00ls
- Audited OpenClaw security boundaries and submitted 14 security PRs, covering 11 vulnerability classes including SSRF, token exposure, path traversal, prototype pollution, environment-variable injection/RCE, and Windows junction escape.
- Research coding-agent trust boundaries across Claude Code, Codex, OpenCode, Gemini CLI, OpenClaw, and AI-integrated browsers, with responsible disclosures through Anthropic VDP, Google Bug Hunters, and GitHub Security Advisories.
- Contributed security advisories including
GHSA-g5hv-4fwh-h87randGHSA-wqv3-rc3w-52r6. - Built benchmark tooling around multi-step reasoning, agent architecture, tool-use reliability, validation quality, and operational efficiency.
- Previous research spans cloud/container security, BAS/AEV, RASP, endpoint/runtime security, Java code auditing, and responsible CNVD/CNNVD disclosure.
| EKS Cluster Game | K8s Lan Party |
|---|---|
![]() |
![]() |
| Cloud Hunter | Wiz Perimeter Leak |
|---|---|
![]() |
![]() |
| AI Security Challenge | Split Horizon |
|---|---|
![]() |
![]() |
| Category | Projects and contributions |
|---|---|
| 🤖 Agentic AI & LLM | cain-agent · dsh-guardian · dsh-island · dsh-llm-inspector · claude-agent-sdk-dev · cloud_native_mcp |
| ☁️ Cloud & Container Security | Cloud_Unauthorized_Tool · ebpf-c-tample-action · k8s-2024-21626 · CVE-2024-21626 · auto_change_version_for_cloudnative |
| 🌐 Application, Network & Runtime Security | Apt_t00ls fork · ASM-hide-RASP · fscan contribution · KubeAPI-Inspector contribution · Deadpool contribution · JarEditor contribution |
| 🖥️ Binary & Endpoint Research | Transacted-Hollowing-allinone · audio-reverse-shell · AVkiller · packer · STEAL-HOOK · Binary Utility Functions |
| ⚙️ Automation & Developer Tools | Site-Specific Extension Manager · workflow-use · clash-verge-mcp-pro · web-check-zh · Docker utilities · Windows Internals notes |
| 🧩 Products & Interactive Systems | Cloud-Native ATT&CK Matrix · Top 7 Cloud Attack Paths · Favorite Articles Real-Time |
- OpenClaw 17个漏洞攻击面:发布此文时只修复一个 — Agent runtime、SSRF、凭证泄露与沙箱边界研究
- 工具调用的信任困境:AI 编程智能体如何沦为“盲从执行者” — Coding Agent 工具信任与行为安全
- Claude Code v2.1.71 完整架构分析报告 — Agent 架构、调度与工具执行链分析
- 从“灰产数据”到“数据供应链”:Codex 污染问题的四轮追溯 — 模型数据供应链与污染溯源
- AI Agent 中浮点计算导致结果不一致:成因与优化 — Agent 可靠性与数值一致性
- 智·战 2025:腾讯云鼎 AI 安全测试大赛全景复盘 — 模型、Agent 框架与 Benchmark 对比
- RASP Attack and Defence — 从常规绕过到 ASM 动态擦除 Hook
- 50 种终端进程注入:原理与源码 — Endpoint 与 Windows Runtime 研究
📚 More Articles — Expand the complete topic archive (50+)
- Kubernetes Goat
- CVE-2024-21626 Analysis
- eBPF in Docker
- 基于 eBPF 的容器安全验证解决方案
- 从云原生攻防之道看 BAS 安全验证新方向
- 深入剖析 uevent_helper 容器逃逸向量
- Kubernetes 安全中的网络隔离
- 容器与 Kubernetes 多种配置不当 YAML
- 多维度云原生 ATT&CK 视角
- 云安全:Kubernetes 内核和用户环境问题
- 容器安全:内核中的各类问题
- 云安全:Kubernetes Container 四种后门注入方式
- 利用 Kubernetes 探针进行持久化的攻防观察与防护
- Terraform Goat Training
- Developing a Cloud Unauthorized Tool
- 7 条 Top 云攻击路径
- AWS S3 Enumeration Basics
- Identify the AWS Account ID from a Public S3 Bucket
- AWS: Exploit Weak Bucket Policies for Privileged Access
- AWS: Leverage Insecure Storage and Backups
- AWS: Leverage Leaked Credentials
- AWS SQS and Lambda SQL Injection
- AWS PwnLab Remaining Techniques
- Azure Blob Container to Initial Access
- GCP: Exploit SSRF with Gopher for Initial Access
- GCP: Reveal Hidden Files in Google Storage
- Cloudflare R2 存储桶探测
- Java 代码审计入门
- Java 代码审计小 Tips
- Java 代码审计:快速四层探索未授权 RCE
- 耗时半年挖掘 17 个 Java 闭源系统
- 应用安全 Hacktrick
- 穿透 chroot 牢笼的九大逃逸技术
- Quick MSSQL Penetration
- RCS 短信协议钓鱼的原理与利用
- 现代钓鱼技术报告
- Java 9 后如何实现 Self-Attach
- Javassist 修改运行时 Java 类名
- 使用音频在计算机之间传输数据
- 2024GH.V.V
__init__隐藏钓鱼木马分析 - PHP WebShell:从基础到深入变种
- Shell 编程开发
- 编写第一个 Shell
- 内存访问异常 Hook
Browse the full live archive at cdxiaodong.life.
Complete legacy profile and writing archive
The previous README, including every historical project and article link, is preserved verbatim in archive/README-legacy-2026-08-27.md.
Repositories · Pull Requests · Blog · Email











