AI Strategy, Deployment, Risk Management
Helping companies adopt AI and run a practical security program.
From strategy through safe deployment to ongoing risk management.
Why this keeps happening
Every wave ships first.
Security catches up years later.
And each wave inherits the last one's mistakes before adding its own.
Web
Mobile
Cloud
Blockchain
AI agents
AI agents run on web APIs, cloud infrastructure, and the same phishable humans, so they carry every prior wave's risk, plus their own. I've defended each layer of this stack as it shipped.
Tools
Live software tools
I don't just advise on this attack surface. I work in it. These tools started as ways to answer my own questions; they're rough, but they're real.
Scans any MCP server for the red flags that turn AI agents into liabilities: risky permissions, missing auth, prompt-injection exposure. Free, open methodology.
Signal ScoutCatalogs and classifies over 50,000 public GitHub repositories by AI framework, MCP server, and security practice, so you can compare framework momentum and spot security gaps across the MCP ecosystem without running your own scans.
StableScopeBetaA stablecoin registry with a live freeze-events monitor, still early and rough around the edges. Watch centralized control get exercised on "decentralized" money, in real time.
HookdA 48-hour benchmark for AI-assisted delivery: full iOS app, API, and site shipped in a weekend (in mid-2025, before Claude Sonnet 4.5 and the agentic-coding wave that followed). Useful for calibrating what AI tooling actually changes about build risk and speed.
Frameworks
Open frameworks
The methodologies behind the tools, published and maintained in the open, so you can check my work.
The open scoring methodology behind mcprisk: provenance, capabilities, transport and auth, vulnerabilities, and description integrity.
Stablecoin Risk Assessment FrameworkThe layered scoring methodology behind the stablecoin risk note, maintained as an open repo.
A security checklist for on-chain treasury and multisig setupsSigner management, quorum design, monitoring, and offboarding risk.
A risk assessment framework for stablecoins and crypto treasuriesA layered methodology for scoring stablecoin and crypto protocol risk, from settlement mechanics to end-user exposure.
What actually belongs in an AI agent security policyAgent inventory, kill-switches, API scope governance, and how it maps to the OWASP LLM/Agentic Top 10.
Work with me
Two kinds of engagements: securing the new attack surface, and running the fundamentals that still decide whether you survive the old one.
The new surface
For organizations that know they need AI but not where to start: tool selection, staff training, workflow automation, and agent development, with governance built in from day one. I've run this playbook end-to-end inside a company that went all in.
Agent inventories, MCP/tool-permission review, kill-switch design, policy mapped to the OWASP LLM & Agentic Top 10. For teams running agents in production, or about to.
Treasury and multisig security, stablecoin exposure assessment, protocol risk scoring. For companies holding or moving value on-chain.
The fundamentals
Ongoing security leadership without the full-time hire.
From nothing to a real program, sequenced by risk instead of by checklist.
SOC 2 and ISO 27001, treated as an output of a good program rather than the goal of one.
Technical expert witness services: cybersecurity, AI and agent security, and crypto and blockchain security disputes.
Writing
Direct takes
Analysis and opinions, mostly on tech deep dives and how to manage new technology and risk.
A scan of the official MCP registry with John Abraham and Mrigendra Soni: missing repositories, thin authorization, and what it means to trust a server before connecting it.
A Visual Guide to Enterprise AI RiskA data-flow view of enterprise AI risk across four layers, data, access, agent, model, with a control paired to every numbered risk.
From Web1 to Web3 SecurityWhy Web3 security failures mostly repeat Web1 and Web2 mistakes, and what a real program needs beyond smart contract audits.
The Stablecoin Payments Stack: an IntroductionA layered framework for the stablecoin payments ecosystem, settlement, value, liquidity, access, and application, with risk management running through every layer.
Circle USDC Blacklist ImplementationHow USDC's blacklist function actually works at the code level, and why centralized issuance control persists regardless of how permissionless the underlying chain is.
A Visual Guide to Blockchain Bridge SecurityBridge risk spans the entire stack, web interfaces, RPC nodes, smart contracts, validators, multisigs, and people, not just the contract layer most audits focus on.
More writing on MediumThe full archive, including the stablecoin risk series and earlier technical deep-dives.