AI application security
Testing AI coding tools, agentic workflows, and MCP integrations for exploitable trust and authorization failures.
Security researcher, red teamer, and AI security and risk management practitioner.
Jashid studies how AI tools and agentic systems fail in practice, then translates those findings into safeguards, risk decisions, and security work that organizations can act on.
Jashid approaches AI systems with an offensive-security mindset: map the trust boundaries, test how tools use authority, follow the data, and reproduce the failure. That work includes public research into AI coding assistants, MCP servers, prompt injection, permission bypasses, and other weaknesses in agentic workflows.
The technical result is only the start. His risk-management work connects attack paths to business exposure, control options, and clear recommendations. Advent brings those two perspectives together so customers can move from uncertainty to a practical security decision.
The work stays grounded in observable behavior, reproducible evidence, and controls that teams can operate.
Testing AI coding tools, agentic workflows, and MCP integrations for exploitable trust and authorization failures.
Turning technical findings into risk scenarios, practical safeguards, and decisions leaders can defend.
Using red-team and penetration-testing methods to validate how weaknesses combine into meaningful attack paths.
Designing compensating controls for AI tools, sensitive data, identities, developer environments, and supporting infrastructure.
Public work that connects AI attack-surface research with enterprise risk analysis and defensive architecture.
A risk model and defensive architecture for organizations evaluating agentic desktop tools in regulated environments.
Read the workResearch paperEmpirical analysis of MCP configuration attacks in Claude Code, paired with enterprise-focused compensating controls.
Read the workResearch paperA structured view of the AI tool execution path, the threats at each layer, and the controls available to reduce exposure.
Read the workPublic research covers MCP trust models, indirect prompt injection, permission bypasses, tool-confirmation weaknesses, and OAuth authorization behavior.
A command-line reconnaissance scanner that fingerprints MCP servers and flags patterns associated with publicly disclosed vulnerability classes.
A maintained reference covering AI coding tool vulnerabilities, prompt injection, model exploitation, and defensive architecture.
Start with the system, decision, or concern in front of you. We will help shape a focused next step.