Software
Breachwright
Get in Touch

Jashid Sany

Security researcher, red teamer, and AI security and risk management practitioner.

Jashid studies how AI tools and agentic systems fail in practice, then translates those findings into safeguards, risk decisions, and security work that organizations can act on.

How Jashid approaches the work

Jashid approaches AI systems with an offensive-security mindset: map the trust boundaries, test how tools use authority, follow the data, and reproduce the failure. That work includes public research into AI coding assistants, MCP servers, prompt injection, permission bypasses, and other weaknesses in agentic workflows.

The technical result is only the start. His risk-management work connects attack paths to business exposure, control options, and clear recommendations. Advent brings those two perspectives together so customers can move from uncertainty to a practical security decision.

Areas of expertise

The work stays grounded in observable behavior, reproducible evidence, and controls that teams can operate.

01

AI application security

Testing AI coding tools, agentic workflows, and MCP integrations for exploitable trust and authorization failures.

02

Technology risk management

Turning technical findings into risk scenarios, practical safeguards, and decisions leaders can defend.

03

Offensive security

Using red-team and penetration-testing methods to validate how weaknesses combine into meaningful attack paths.

04

Defensive architecture

Designing compensating controls for AI tools, sensitive data, identities, developer environments, and supporting infrastructure.

Tools and reference material

AI security research

Published findings across agentic AI tools

Public research covers MCP trust models, indirect prompt injection, permission bypasses, tool-confirmation weaknesses, and OAuth authorization behavior.

View AI security research
Open-source tool

mcp-recon

A command-line reconnaissance scanner that fingerprints MCP servers and flags patterns associated with publicly disclosed vulnerability classes.

Explore mcp-recon
Reference work

AI Security Reference

A maintained reference covering AI coding tool vulnerabilities, prompt injection, model exploitation, and defensive architecture.

Open the reference

Discuss an AI security or risk question

Start with the system, decision, or concern in front of you. We will help shape a focused next step.

Start a conversation