View HackTuah's full-sized avatar

Organizations

@ScriptKittyOS

Block or report HackTuah

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HackTuah/README.md

Ayla Croft

Inventor · AI security researcher · Systems engineer
Founder & Chief Architect, Script Kitty OS

Script Kitty OSScript Kitty OS on GitHubWebsiteLinkedInXORCIDEmail


The model proposes, the system authorizes.

Identity proves who is acting. Attestation proves what ran. Gateways allow or deny a call. None of them prove the effect was the authorized one. That is the layer I build.


Building

HolyTrinity — Authority-Bound Agentic Layer An AI agent authority control plane. Binds an approval to a specific action, target state, expected consequence, authority state version and validity window, then verifies the resulting effect matched what was authorized and issues a receipt bound to that approval. Any run can be replayed and diffed. BEAM-native. Elixir, Phoenix, LiveView, Ecto, Postgres, Oban. Running in production. Non-provisional patent filed.

Agent runtimes on the BEAM Jido and my own Hermes runtime, running supervised in production rather than bolted onto a request/response process. Agents are long-lived, concurrent, and capable of real damage. OTP was built for that shape of problem decades before anyone needed it for this.

HackTUI — terminal-native purple-team security operations platform Elixir umbrella: core, store, hub, sensor, tui, agent, collab. Postgres/Ecto persistence. Ingests journald, network flow via tshark/dumpcap, and BEAM runtime signals. Alert and investigation case lifecycle, replay engine, built-in MCP server. Research prototype.

HolyTrinity Bench (holytrinity.v1) Everyone benchmarks whether you can make an AI agent misbehave. That question is settled. You can. 1.8 million prompt injections against 22 frontier agents settled it, and I helped write that paper.

So this one measures something else: whether the effect that landed was the one that was authorized. Unauthorized effect under adversarial load, not attack success rate. In active development.


Research

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition (2025) Co-author. Introduced the Agent Red Teaming (ART) benchmark. NeurIPS 2025 Datasets and Benchmarks Track · OpenReview · arXiv:2507.20526

The Model Proposes, the System Authorizes: An Authority Control Plane for AI Agents on the BEAM (2026) DOI 10.5281/zenodo.21754762

Authority-Bound Agentic Execution: Measuring Unauthorized Effect Under Adversarial Load (2026) DOI 10.5281/zenodo.21755869

Schrödinger's Cyber Security Framework: Vulnerability as an Observer-Dependent Quantity (2026) DOI 10.5281/zenodo.22116617

Where the ART benchmark shows up

System cardPublisherDate
GPT-5OpenAIAug 2025
Claude Sonnet 4.5AnthropicSept 2025
Claude Haiku 4.5AnthropicOct 2025
Claude Opus 4.8AnthropicMay 2026
Claude Fable 5 / Mythos 5AnthropicJune 2026
Muse Spark Safety Report2026

ART was retired in 2026 after frontier models saturated it, and is cited as the prior baseline in its successor benchmark.


Before this

Competed in Gray Swan's public red teaming arena, then joined the team. Built the Discord and ran community, helped grow it from a few hundred people to over 15,000. On the team for every competition through my departure, including the UK AISI Agent Red-Teaming Challenge behind ART: 22 models, 44 scenarios, 1.8M attack attempts, 62,000+ successful policy violations.

Wrote most of the Gray Swan Arena technical blog, 8 of its 10 posts. Designed and ran Gray Swan's in-person activation at DEF CON 33.


Stack

Elixir and OTP. Supervision trees, GenServers, distributed processes, PubSub. Agent runtimes running supervised in production rather than as a script with a retry loop. Phoenix, LiveView, Ecto, Oban, Postgres.

Agent infrastructure. MCP servers and clients, tool routing and mediation, policy enforcement at the call boundary, receipt and audit ledgers, replay and diff.

Security. Agent and LLM adversarial testing, evaluation and benchmark design, threat modeling, purple team operations, detection engineering, live telemetry ingest and correlation.

Also. Python, TypeScript, Go, C, Bash. Docker, Fly.io, GitHub Actions, Azure. Enterprise networking, self-hosted infrastructure, OpenWrt, VLAN segmentation, DNS.

Now

Agent authorization and the HolyTrinity control plane. Conformance work against the draft EU AI Act cybersecurity standard prEN 18282 and OMB memoranda including M-26-04.

Work ships under @ScriptKittyOS. Script Kitty OS is a company of Sudo Apt Holdings.

Popular repositories Loading

  1. HackTui HackTuiPublic

    TUI SIEM in Elixir on BEAM

    Elixir 55 10

  2. hacktuah-lab-public hacktuah-lab-publicPublic

    My first attempt at a home lab or what I call... closet lab

    20 1

  3. doj-epstein-files doj-epstein-filesPublic

    Stuff I collected

    Python 12

  4. vim-carrey-game vim-carrey-gamePublic

    Vim Carrey's Error Collection Adventure is a playful homage to the one and only The Primeagen. In this simple 8-bit game, inspired by The Primeagen's love for JavaScript and all things tech, you gu…

    JavaScript 9 1

  5. AgentGPT AgentGPTPublic

    Forked from reworkd/AgentGPT

    🤖 Assemble, configure, and deploy autonomous AI Agents in your browser.

    Jupyter Notebook 2

  6. screenshot-to-code screenshot-to-codePublic

    Forked from abi/screenshot-to-code

    Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)

    TypeScript 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content
View HackTuah's full-sized avatar

Organizations

@ScriptKittyOS

Block or report HackTuah

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HackTuah/README.md

Ayla Croft

Inventor · AI security researcher · Systems engineer
Founder & Chief Architect, Script Kitty OS

Script Kitty OSScript Kitty OS on GitHubWebsiteLinkedInXORCIDEmail


The model proposes, the system authorizes.

Identity proves who is acting. Attestation proves what ran. Gateways allow or deny a call. None of them prove the effect was the authorized one. That is the layer I build.


Building

HolyTrinity — Authority-Bound Agentic Layer An AI agent authority control plane. Binds an approval to a specific action, target state, expected consequence, authority state version and validity window, then verifies the resulting effect matched what was authorized and issues a receipt bound to that approval. Any run can be replayed and diffed. BEAM-native. Elixir, Phoenix, LiveView, Ecto, Postgres, Oban. Running in production. Non-provisional patent filed.

Agent runtimes on the BEAM Jido and my own Hermes runtime, running supervised in production rather than bolted onto a request/response process. Agents are long-lived, concurrent, and capable of real damage. OTP was built for that shape of problem decades before anyone needed it for this.

HackTUI — terminal-native purple-team security operations platform Elixir umbrella: core, store, hub, sensor, tui, agent, collab. Postgres/Ecto persistence. Ingests journald, network flow via tshark/dumpcap, and BEAM runtime signals. Alert and investigation case lifecycle, replay engine, built-in MCP server. Research prototype.

HolyTrinity Bench (holytrinity.v1) Everyone benchmarks whether you can make an AI agent misbehave. That question is settled. You can. 1.8 million prompt injections against 22 frontier agents settled it, and I helped write that paper.

So this one measures something else: whether the effect that landed was the one that was authorized. Unauthorized effect under adversarial load, not attack success rate. In active development.


Research

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition (2025) Co-author. Introduced the Agent Red Teaming (ART) benchmark. NeurIPS 2025 Datasets and Benchmarks Track · OpenReview · arXiv:2507.20526

The Model Proposes, the System Authorizes: An Authority Control Plane for AI Agents on the BEAM (2026) DOI 10.5281/zenodo.21754762

Authority-Bound Agentic Execution: Measuring Unauthorized Effect Under Adversarial Load (2026) DOI 10.5281/zenodo.21755869

Schrödinger's Cyber Security Framework: Vulnerability as an Observer-Dependent Quantity (2026) DOI 10.5281/zenodo.22116617

Where the ART benchmark shows up

System cardPublisherDate
GPT-5OpenAIAug 2025
Claude Sonnet 4.5AnthropicSept 2025
Claude Haiku 4.5AnthropicOct 2025
Claude Opus 4.8AnthropicMay 2026
Claude Fable 5 / Mythos 5AnthropicJune 2026
Muse Spark Safety Report2026

ART was retired in 2026 after frontier models saturated it, and is cited as the prior baseline in its successor benchmark.


Before this

Competed in Gray Swan's public red teaming arena, then joined the team. Built the Discord and ran community, helped grow it from a few hundred people to over 15,000. On the team for every competition through my departure, including the UK AISI Agent Red-Teaming Challenge behind ART: 22 models, 44 scenarios, 1.8M attack attempts, 62,000+ successful policy violations.

Wrote most of the Gray Swan Arena technical blog, 8 of its 10 posts. Designed and ran Gray Swan's in-person activation at DEF CON 33.


Stack

Elixir and OTP. Supervision trees, GenServers, distributed processes, PubSub. Agent runtimes running supervised in production rather than as a script with a retry loop. Phoenix, LiveView, Ecto, Oban, Postgres.

Agent infrastructure. MCP servers and clients, tool routing and mediation, policy enforcement at the call boundary, receipt and audit ledgers, replay and diff.

Security. Agent and LLM adversarial testing, evaluation and benchmark design, threat modeling, purple team operations, detection engineering, live telemetry ingest and correlation.

Also. Python, TypeScript, Go, C, Bash. Docker, Fly.io, GitHub Actions, Azure. Enterprise networking, self-hosted infrastructure, OpenWrt, VLAN segmentation, DNS.

Now

Agent authorization and the HolyTrinity control plane. Conformance work against the draft EU AI Act cybersecurity standard prEN 18282 and OMB memoranda including M-26-04.

Work ships under @ScriptKittyOS. Script Kitty OS is a company of Sudo Apt Holdings.

Popular repositories Loading

  1. HackTui HackTuiPublic

    TUI SIEM in Elixir on BEAM

    Elixir 55 10

  2. hacktuah-lab-public hacktuah-lab-publicPublic

    My first attempt at a home lab or what I call... closet lab

    20 1

  3. doj-epstein-files doj-epstein-filesPublic

    Stuff I collected

    Python 12

  4. vim-carrey-game vim-carrey-gamePublic

    Vim Carrey's Error Collection Adventure is a playful homage to the one and only The Primeagen. In this simple 8-bit game, inspired by The Primeagen's love for JavaScript and all things tech, you gu…

    JavaScript 9 1

  5. AgentGPT AgentGPTPublic

    Forked from reworkd/AgentGPT

    🤖 Assemble, configure, and deploy autonomous AI Agents in your browser.

    Jupyter Notebook 2

  6. screenshot-to-code screenshot-to-codePublic

    Forked from abi/screenshot-to-code

    Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)

    TypeScript 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View HackTuah's full-sized avatar

Organizations

@ScriptKittyOS

Block or report HackTuah

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HackTuah/README.md

Ayla Croft

Inventor · AI security researcher · Systems engineer
Founder & Chief Architect, Script Kitty OS

Script Kitty OSScript Kitty OS on GitHubWebsiteLinkedInXORCIDEmail


The model proposes, the system authorizes.

Identity proves who is acting. Attestation proves what ran. Gateways allow or deny a call. None of them prove the effect was the authorized one. That is the layer I build.


Building

HolyTrinity — Authority-Bound Agentic Layer An AI agent authority control plane. Binds an approval to a specific action, target state, expected consequence, authority state version and validity window, then verifies the resulting effect matched what was authorized and issues a receipt bound to that approval. Any run can be replayed and diffed. BEAM-native. Elixir, Phoenix, LiveView, Ecto, Postgres, Oban. Running in production. Non-provisional patent filed.

Agent runtimes on the BEAM Jido and my own Hermes runtime, running supervised in production rather than bolted onto a request/response process. Agents are long-lived, concurrent, and capable of real damage. OTP was built for that shape of problem decades before anyone needed it for this.

HackTUI — terminal-native purple-team security operations platform Elixir umbrella: core, store, hub, sensor, tui, agent, collab. Postgres/Ecto persistence. Ingests journald, network flow via tshark/dumpcap, and BEAM runtime signals. Alert and investigation case lifecycle, replay engine, built-in MCP server. Research prototype.

HolyTrinity Bench (holytrinity.v1) Everyone benchmarks whether you can make an AI agent misbehave. That question is settled. You can. 1.8 million prompt injections against 22 frontier agents settled it, and I helped write that paper.

So this one measures something else: whether the effect that landed was the one that was authorized. Unauthorized effect under adversarial load, not attack success rate. In active development.


Research

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition (2025) Co-author. Introduced the Agent Red Teaming (ART) benchmark. NeurIPS 2025 Datasets and Benchmarks Track · OpenReview · arXiv:2507.20526

The Model Proposes, the System Authorizes: An Authority Control Plane for AI Agents on the BEAM (2026) DOI 10.5281/zenodo.21754762

Authority-Bound Agentic Execution: Measuring Unauthorized Effect Under Adversarial Load (2026) DOI 10.5281/zenodo.21755869

Schrödinger's Cyber Security Framework: Vulnerability as an Observer-Dependent Quantity (2026) DOI 10.5281/zenodo.22116617

Where the ART benchmark shows up

System cardPublisherDate
GPT-5OpenAIAug 2025
Claude Sonnet 4.5AnthropicSept 2025
Claude Haiku 4.5AnthropicOct 2025
Claude Opus 4.8AnthropicMay 2026
Claude Fable 5 / Mythos 5AnthropicJune 2026
Muse Spark Safety Report2026

ART was retired in 2026 after frontier models saturated it, and is cited as the prior baseline in its successor benchmark.


Before this

Competed in Gray Swan's public red teaming arena, then joined the team. Built the Discord and ran community, helped grow it from a few hundred people to over 15,000. On the team for every competition through my departure, including the UK AISI Agent Red-Teaming Challenge behind ART: 22 models, 44 scenarios, 1.8M attack attempts, 62,000+ successful policy violations.

Wrote most of the Gray Swan Arena technical blog, 8 of its 10 posts. Designed and ran Gray Swan's in-person activation at DEF CON 33.


Stack

Elixir and OTP. Supervision trees, GenServers, distributed processes, PubSub. Agent runtimes running supervised in production rather than as a script with a retry loop. Phoenix, LiveView, Ecto, Oban, Postgres.

Agent infrastructure. MCP servers and clients, tool routing and mediation, policy enforcement at the call boundary, receipt and audit ledgers, replay and diff.

Security. Agent and LLM adversarial testing, evaluation and benchmark design, threat modeling, purple team operations, detection engineering, live telemetry ingest and correlation.

Also. Python, TypeScript, Go, C, Bash. Docker, Fly.io, GitHub Actions, Azure. Enterprise networking, self-hosted infrastructure, OpenWrt, VLAN segmentation, DNS.

Now

Agent authorization and the HolyTrinity control plane. Conformance work against the draft EU AI Act cybersecurity standard prEN 18282 and OMB memoranda including M-26-04.

Work ships under @ScriptKittyOS. Script Kitty OS is a company of Sudo Apt Holdings.

Popular repositories Loading

  1. HackTui HackTuiPublic

    TUI SIEM in Elixir on BEAM

    Elixir 55 10

  2. hacktuah-lab-public hacktuah-lab-publicPublic

    My first attempt at a home lab or what I call... closet lab

    20 1

  3. doj-epstein-files doj-epstein-filesPublic

    Stuff I collected

    Python 12

  4. vim-carrey-game vim-carrey-gamePublic

    Vim Carrey's Error Collection Adventure is a playful homage to the one and only The Primeagen. In this simple 8-bit game, inspired by The Primeagen's love for JavaScript and all things tech, you gu…

    JavaScript 9 1

  5. AgentGPT AgentGPTPublic

    Forked from reworkd/AgentGPT

    🤖 Assemble, configure, and deploy autonomous AI Agents in your browser.

    Jupyter Notebook 2

  6. screenshot-to-code screenshot-to-codePublic

    Forked from abi/screenshot-to-code

    Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)

    TypeScript 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View HackTuah's full-sized avatar

Organizations

@ScriptKittyOS

Block or report HackTuah

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HackTuah/README.md

Ayla Croft

Inventor · AI security researcher · Systems engineer
Founder & Chief Architect, Script Kitty OS

Script Kitty OSScript Kitty OS on GitHubWebsiteLinkedInXORCIDEmail


The model proposes, the system authorizes.

Identity proves who is acting. Attestation proves what ran. Gateways allow or deny a call. None of them prove the effect was the authorized one. That is the layer I build.


Building

HolyTrinity — Authority-Bound Agentic Layer An AI agent authority control plane. Binds an approval to a specific action, target state, expected consequence, authority state version and validity window, then verifies the resulting effect matched what was authorized and issues a receipt bound to that approval. Any run can be replayed and diffed. BEAM-native. Elixir, Phoenix, LiveView, Ecto, Postgres, Oban. Running in production. Non-provisional patent filed.

Agent runtimes on the BEAM Jido and my own Hermes runtime, running supervised in production rather than bolted onto a request/response process. Agents are long-lived, concurrent, and capable of real damage. OTP was built for that shape of problem decades before anyone needed it for this.

HackTUI — terminal-native purple-team security operations platform Elixir umbrella: core, store, hub, sensor, tui, agent, collab. Postgres/Ecto persistence. Ingests journald, network flow via tshark/dumpcap, and BEAM runtime signals. Alert and investigation case lifecycle, replay engine, built-in MCP server. Research prototype.

HolyTrinity Bench (holytrinity.v1) Everyone benchmarks whether you can make an AI agent misbehave. That question is settled. You can. 1.8 million prompt injections against 22 frontier agents settled it, and I helped write that paper.

So this one measures something else: whether the effect that landed was the one that was authorized. Unauthorized effect under adversarial load, not attack success rate. In active development.


Research

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition (2025) Co-author. Introduced the Agent Red Teaming (ART) benchmark. NeurIPS 2025 Datasets and Benchmarks Track · OpenReview · arXiv:2507.20526

The Model Proposes, the System Authorizes: An Authority Control Plane for AI Agents on the BEAM (2026) DOI 10.5281/zenodo.21754762

Authority-Bound Agentic Execution: Measuring Unauthorized Effect Under Adversarial Load (2026) DOI 10.5281/zenodo.21755869

Schrödinger's Cyber Security Framework: Vulnerability as an Observer-Dependent Quantity (2026) DOI 10.5281/zenodo.22116617

Where the ART benchmark shows up

System cardPublisherDate
GPT-5OpenAIAug 2025
Claude Sonnet 4.5AnthropicSept 2025
Claude Haiku 4.5AnthropicOct 2025
Claude Opus 4.8AnthropicMay 2026
Claude Fable 5 / Mythos 5AnthropicJune 2026
Muse Spark Safety Report2026

ART was retired in 2026 after frontier models saturated it, and is cited as the prior baseline in its successor benchmark.


Before this

Competed in Gray Swan's public red teaming arena, then joined the team. Built the Discord and ran community, helped grow it from a few hundred people to over 15,000. On the team for every competition through my departure, including the UK AISI Agent Red-Teaming Challenge behind ART: 22 models, 44 scenarios, 1.8M attack attempts, 62,000+ successful policy violations.

Wrote most of the Gray Swan Arena technical blog, 8 of its 10 posts. Designed and ran Gray Swan's in-person activation at DEF CON 33.


Stack

Elixir and OTP. Supervision trees, GenServers, distributed processes, PubSub. Agent runtimes running supervised in production rather than as a script with a retry loop. Phoenix, LiveView, Ecto, Oban, Postgres.

Agent infrastructure. MCP servers and clients, tool routing and mediation, policy enforcement at the call boundary, receipt and audit ledgers, replay and diff.

Security. Agent and LLM adversarial testing, evaluation and benchmark design, threat modeling, purple team operations, detection engineering, live telemetry ingest and correlation.

Also. Python, TypeScript, Go, C, Bash. Docker, Fly.io, GitHub Actions, Azure. Enterprise networking, self-hosted infrastructure, OpenWrt, VLAN segmentation, DNS.

Now

Agent authorization and the HolyTrinity control plane. Conformance work against the draft EU AI Act cybersecurity standard prEN 18282 and OMB memoranda including M-26-04.

Work ships under @ScriptKittyOS. Script Kitty OS is a company of Sudo Apt Holdings.

Popular repositories Loading

  1. HackTui HackTuiPublic

    TUI SIEM in Elixir on BEAM

    Elixir 55 10

  2. hacktuah-lab-public hacktuah-lab-publicPublic

    My first attempt at a home lab or what I call... closet lab

    20 1

  3. doj-epstein-files doj-epstein-filesPublic

    Stuff I collected

    Python 12

  4. vim-carrey-game vim-carrey-gamePublic

    Vim Carrey's Error Collection Adventure is a playful homage to the one and only The Primeagen. In this simple 8-bit game, inspired by The Primeagen's love for JavaScript and all things tech, you gu…

    JavaScript 9 1

  5. AgentGPT AgentGPTPublic

    Forked from reworkd/AgentGPT

    🤖 Assemble, configure, and deploy autonomous AI Agents in your browser.

    Jupyter Notebook 2

  6. screenshot-to-code screenshot-to-codePublic

    Forked from abi/screenshot-to-code

    Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)

    TypeScript 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
View HackTuah's full-sized avatar

Organizations

@ScriptKittyOS

Block or report HackTuah

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HackTuah/README.md

Ayla Croft

Inventor · AI security researcher · Systems engineer
Founder & Chief Architect, Script Kitty OS

Script Kitty OSScript Kitty OS on GitHubWebsiteLinkedInXORCIDEmail


The model proposes, the system authorizes.

Identity proves who is acting. Attestation proves what ran. Gateways allow or deny a call. None of them prove the effect was the authorized one. That is the layer I build.


Building

HolyTrinity — Authority-Bound Agentic Layer An AI agent authority control plane. Binds an approval to a specific action, target state, expected consequence, authority state version and validity window, then verifies the resulting effect matched what was authorized and issues a receipt bound to that approval. Any run can be replayed and diffed. BEAM-native. Elixir, Phoenix, LiveView, Ecto, Postgres, Oban. Running in production. Non-provisional patent filed.

Agent runtimes on the BEAM Jido and my own Hermes runtime, running supervised in production rather than bolted onto a request/response process. Agents are long-lived, concurrent, and capable of real damage. OTP was built for that shape of problem decades before anyone needed it for this.

HackTUI — terminal-native purple-team security operations platform Elixir umbrella: core, store, hub, sensor, tui, agent, collab. Postgres/Ecto persistence. Ingests journald, network flow via tshark/dumpcap, and BEAM runtime signals. Alert and investigation case lifecycle, replay engine, built-in MCP server. Research prototype.

HolyTrinity Bench (holytrinity.v1) Everyone benchmarks whether you can make an AI agent misbehave. That question is settled. You can. 1.8 million prompt injections against 22 frontier agents settled it, and I helped write that paper.

So this one measures something else: whether the effect that landed was the one that was authorized. Unauthorized effect under adversarial load, not attack success rate. In active development.


Research

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition (2025) Co-author. Introduced the Agent Red Teaming (ART) benchmark. NeurIPS 2025 Datasets and Benchmarks Track · OpenReview · arXiv:2507.20526

The Model Proposes, the System Authorizes: An Authority Control Plane for AI Agents on the BEAM (2026) DOI 10.5281/zenodo.21754762

Authority-Bound Agentic Execution: Measuring Unauthorized Effect Under Adversarial Load (2026) DOI 10.5281/zenodo.21755869

Schrödinger's Cyber Security Framework: Vulnerability as an Observer-Dependent Quantity (2026) DOI 10.5281/zenodo.22116617

Where the ART benchmark shows up

System cardPublisherDate
GPT-5OpenAIAug 2025
Claude Sonnet 4.5AnthropicSept 2025
Claude Haiku 4.5AnthropicOct 2025
Claude Opus 4.8AnthropicMay 2026
Claude Fable 5 / Mythos 5AnthropicJune 2026
Muse Spark Safety Report2026

ART was retired in 2026 after frontier models saturated it, and is cited as the prior baseline in its successor benchmark.


Before this

Competed in Gray Swan's public red teaming arena, then joined the team. Built the Discord and ran community, helped grow it from a few hundred people to over 15,000. On the team for every competition through my departure, including the UK AISI Agent Red-Teaming Challenge behind ART: 22 models, 44 scenarios, 1.8M attack attempts, 62,000+ successful policy violations.

Wrote most of the Gray Swan Arena technical blog, 8 of its 10 posts. Designed and ran Gray Swan's in-person activation at DEF CON 33.


Stack

Elixir and OTP. Supervision trees, GenServers, distributed processes, PubSub. Agent runtimes running supervised in production rather than as a script with a retry loop. Phoenix, LiveView, Ecto, Oban, Postgres.

Agent infrastructure. MCP servers and clients, tool routing and mediation, policy enforcement at the call boundary, receipt and audit ledgers, replay and diff.

Security. Agent and LLM adversarial testing, evaluation and benchmark design, threat modeling, purple team operations, detection engineering, live telemetry ingest and correlation.

Also. Python, TypeScript, Go, C, Bash. Docker, Fly.io, GitHub Actions, Azure. Enterprise networking, self-hosted infrastructure, OpenWrt, VLAN segmentation, DNS.

Now

Agent authorization and the HolyTrinity control plane. Conformance work against the draft EU AI Act cybersecurity standard prEN 18282 and OMB memoranda including M-26-04.

Work ships under @ScriptKittyOS. Script Kitty OS is a company of Sudo Apt Holdings.

Popular repositories Loading

  1. HackTui HackTuiPublic

    TUI SIEM in Elixir on BEAM

    Elixir 55 10

  2. hacktuah-lab-public hacktuah-lab-publicPublic

    My first attempt at a home lab or what I call... closet lab

    20 1

  3. doj-epstein-files doj-epstein-filesPublic

    Stuff I collected

    Python 12

  4. vim-carrey-game vim-carrey-gamePublic

    Vim Carrey's Error Collection Adventure is a playful homage to the one and only The Primeagen. In this simple 8-bit game, inspired by The Primeagen's love for JavaScript and all things tech, you gu…

    JavaScript 9 1

  5. AgentGPT AgentGPTPublic

    Forked from reworkd/AgentGPT

    🤖 Assemble, configure, and deploy autonomous AI Agents in your browser.

    Jupyter Notebook 2

  6. screenshot-to-code screenshot-to-codePublic

    Forked from abi/screenshot-to-code

    Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)

    TypeScript 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View HackTuah's full-sized avatar

Organizations

@ScriptKittyOS

Block or report HackTuah

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HackTuah/README.md

Ayla Croft

Inventor · AI security researcher · Systems engineer
Founder & Chief Architect, Script Kitty OS

Script Kitty OSScript Kitty OS on GitHubWebsiteLinkedInXORCIDEmail


The model proposes, the system authorizes.

Identity proves who is acting. Attestation proves what ran. Gateways allow or deny a call. None of them prove the effect was the authorized one. That is the layer I build.


Building

HolyTrinity — Authority-Bound Agentic Layer An AI agent authority control plane. Binds an approval to a specific action, target state, expected consequence, authority state version and validity window, then verifies the resulting effect matched what was authorized and issues a receipt bound to that approval. Any run can be replayed and diffed. BEAM-native. Elixir, Phoenix, LiveView, Ecto, Postgres, Oban. Running in production. Non-provisional patent filed.

Agent runtimes on the BEAM Jido and my own Hermes runtime, running supervised in production rather than bolted onto a request/response process. Agents are long-lived, concurrent, and capable of real damage. OTP was built for that shape of problem decades before anyone needed it for this.

HackTUI — terminal-native purple-team security operations platform Elixir umbrella: core, store, hub, sensor, tui, agent, collab. Postgres/Ecto persistence. Ingests journald, network flow via tshark/dumpcap, and BEAM runtime signals. Alert and investigation case lifecycle, replay engine, built-in MCP server. Research prototype.

HolyTrinity Bench (holytrinity.v1) Everyone benchmarks whether you can make an AI agent misbehave. That question is settled. You can. 1.8 million prompt injections against 22 frontier agents settled it, and I helped write that paper.

So this one measures something else: whether the effect that landed was the one that was authorized. Unauthorized effect under adversarial load, not attack success rate. In active development.


Research

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition (2025) Co-author. Introduced the Agent Red Teaming (ART) benchmark. NeurIPS 2025 Datasets and Benchmarks Track · OpenReview · arXiv:2507.20526

The Model Proposes, the System Authorizes: An Authority Control Plane for AI Agents on the BEAM (2026) DOI 10.5281/zenodo.21754762

Authority-Bound Agentic Execution: Measuring Unauthorized Effect Under Adversarial Load (2026) DOI 10.5281/zenodo.21755869

Schrödinger's Cyber Security Framework: Vulnerability as an Observer-Dependent Quantity (2026) DOI 10.5281/zenodo.22116617

Where the ART benchmark shows up

System cardPublisherDate
GPT-5OpenAIAug 2025
Claude Sonnet 4.5AnthropicSept 2025
Claude Haiku 4.5AnthropicOct 2025
Claude Opus 4.8AnthropicMay 2026
Claude Fable 5 / Mythos 5AnthropicJune 2026
Muse Spark Safety Report2026

ART was retired in 2026 after frontier models saturated it, and is cited as the prior baseline in its successor benchmark.


Before this

Competed in Gray Swan's public red teaming arena, then joined the team. Built the Discord and ran community, helped grow it from a few hundred people to over 15,000. On the team for every competition through my departure, including the UK AISI Agent Red-Teaming Challenge behind ART: 22 models, 44 scenarios, 1.8M attack attempts, 62,000+ successful policy violations.

Wrote most of the Gray Swan Arena technical blog, 8 of its 10 posts. Designed and ran Gray Swan's in-person activation at DEF CON 33.


Stack

Elixir and OTP. Supervision trees, GenServers, distributed processes, PubSub. Agent runtimes running supervised in production rather than as a script with a retry loop. Phoenix, LiveView, Ecto, Oban, Postgres.

Agent infrastructure. MCP servers and clients, tool routing and mediation, policy enforcement at the call boundary, receipt and audit ledgers, replay and diff.

Security. Agent and LLM adversarial testing, evaluation and benchmark design, threat modeling, purple team operations, detection engineering, live telemetry ingest and correlation.

Also. Python, TypeScript, Go, C, Bash. Docker, Fly.io, GitHub Actions, Azure. Enterprise networking, self-hosted infrastructure, OpenWrt, VLAN segmentation, DNS.

Now

Agent authorization and the HolyTrinity control plane. Conformance work against the draft EU AI Act cybersecurity standard prEN 18282 and OMB memoranda including M-26-04.

Work ships under @ScriptKittyOS. Script Kitty OS is a company of Sudo Apt Holdings.

Popular repositories Loading

  1. HackTui HackTuiPublic

    TUI SIEM in Elixir on BEAM

    Elixir 55 10

  2. hacktuah-lab-public hacktuah-lab-publicPublic

    My first attempt at a home lab or what I call... closet lab

    20 1

  3. doj-epstein-files doj-epstein-filesPublic

    Stuff I collected

    Python 12

  4. vim-carrey-game vim-carrey-gamePublic

    Vim Carrey's Error Collection Adventure is a playful homage to the one and only The Primeagen. In this simple 8-bit game, inspired by The Primeagen's love for JavaScript and all things tech, you gu…

    JavaScript 9 1

  5. AgentGPT AgentGPTPublic

    Forked from reworkd/AgentGPT

    🤖 Assemble, configure, and deploy autonomous AI Agents in your browser.

    Jupyter Notebook 2

  6. screenshot-to-code screenshot-to-codePublic

    Forked from abi/screenshot-to-code

    Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)

    TypeScript 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View HackTuah's full-sized avatar

Organizations

@ScriptKittyOS

Block or report HackTuah

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HackTuah/README.md

Ayla Croft

Inventor · AI security researcher · Systems engineer
Founder & Chief Architect, Script Kitty OS

Script Kitty OSScript Kitty OS on GitHubWebsiteLinkedInXORCIDEmail


The model proposes, the system authorizes.

Identity proves who is acting. Attestation proves what ran. Gateways allow or deny a call. None of them prove the effect was the authorized one. That is the layer I build.


Building

HolyTrinity — Authority-Bound Agentic Layer An AI agent authority control plane. Binds an approval to a specific action, target state, expected consequence, authority state version and validity window, then verifies the resulting effect matched what was authorized and issues a receipt bound to that approval. Any run can be replayed and diffed. BEAM-native. Elixir, Phoenix, LiveView, Ecto, Postgres, Oban. Running in production. Non-provisional patent filed.

Agent runtimes on the BEAM Jido and my own Hermes runtime, running supervised in production rather than bolted onto a request/response process. Agents are long-lived, concurrent, and capable of real damage. OTP was built for that shape of problem decades before anyone needed it for this.

HackTUI — terminal-native purple-team security operations platform Elixir umbrella: core, store, hub, sensor, tui, agent, collab. Postgres/Ecto persistence. Ingests journald, network flow via tshark/dumpcap, and BEAM runtime signals. Alert and investigation case lifecycle, replay engine, built-in MCP server. Research prototype.

HolyTrinity Bench (holytrinity.v1) Everyone benchmarks whether you can make an AI agent misbehave. That question is settled. You can. 1.8 million prompt injections against 22 frontier agents settled it, and I helped write that paper.

So this one measures something else: whether the effect that landed was the one that was authorized. Unauthorized effect under adversarial load, not attack success rate. In active development.


Research

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition (2025) Co-author. Introduced the Agent Red Teaming (ART) benchmark. NeurIPS 2025 Datasets and Benchmarks Track · OpenReview · arXiv:2507.20526

The Model Proposes, the System Authorizes: An Authority Control Plane for AI Agents on the BEAM (2026) DOI 10.5281/zenodo.21754762

Authority-Bound Agentic Execution: Measuring Unauthorized Effect Under Adversarial Load (2026) DOI 10.5281/zenodo.21755869

Schrödinger's Cyber Security Framework: Vulnerability as an Observer-Dependent Quantity (2026) DOI 10.5281/zenodo.22116617

Where the ART benchmark shows up

System cardPublisherDate
GPT-5OpenAIAug 2025
Claude Sonnet 4.5AnthropicSept 2025
Claude Haiku 4.5AnthropicOct 2025
Claude Opus 4.8AnthropicMay 2026
Claude Fable 5 / Mythos 5AnthropicJune 2026
Muse Spark Safety Report2026

ART was retired in 2026 after frontier models saturated it, and is cited as the prior baseline in its successor benchmark.


Before this

Competed in Gray Swan's public red teaming arena, then joined the team. Built the Discord and ran community, helped grow it from a few hundred people to over 15,000. On the team for every competition through my departure, including the UK AISI Agent Red-Teaming Challenge behind ART: 22 models, 44 scenarios, 1.8M attack attempts, 62,000+ successful policy violations.

Wrote most of the Gray Swan Arena technical blog, 8 of its 10 posts. Designed and ran Gray Swan's in-person activation at DEF CON 33.


Stack

Elixir and OTP. Supervision trees, GenServers, distributed processes, PubSub. Agent runtimes running supervised in production rather than as a script with a retry loop. Phoenix, LiveView, Ecto, Oban, Postgres.

Agent infrastructure. MCP servers and clients, tool routing and mediation, policy enforcement at the call boundary, receipt and audit ledgers, replay and diff.

Security. Agent and LLM adversarial testing, evaluation and benchmark design, threat modeling, purple team operations, detection engineering, live telemetry ingest and correlation.

Also. Python, TypeScript, Go, C, Bash. Docker, Fly.io, GitHub Actions, Azure. Enterprise networking, self-hosted infrastructure, OpenWrt, VLAN segmentation, DNS.

Now

Agent authorization and the HolyTrinity control plane. Conformance work against the draft EU AI Act cybersecurity standard prEN 18282 and OMB memoranda including M-26-04.

Work ships under @ScriptKittyOS. Script Kitty OS is a company of Sudo Apt Holdings.

Popular repositories Loading

  1. HackTui HackTuiPublic

    TUI SIEM in Elixir on BEAM

    Elixir 55 10

  2. hacktuah-lab-public hacktuah-lab-publicPublic

    My first attempt at a home lab or what I call... closet lab

    20 1

  3. doj-epstein-files doj-epstein-filesPublic

    Stuff I collected

    Python 12

  4. vim-carrey-game vim-carrey-gamePublic

    Vim Carrey's Error Collection Adventure is a playful homage to the one and only The Primeagen. In this simple 8-bit game, inspired by The Primeagen's love for JavaScript and all things tech, you gu…

    JavaScript 9 1

  5. AgentGPT AgentGPTPublic

    Forked from reworkd/AgentGPT

    🤖 Assemble, configure, and deploy autonomous AI Agents in your browser.

    Jupyter Notebook 2

  6. screenshot-to-code screenshot-to-codePublic

    Forked from abi/screenshot-to-code

    Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)

    TypeScript 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
View HackTuah's full-sized avatar

Organizations

@ScriptKittyOS

Block or report HackTuah

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HackTuah/README.md

Ayla Croft

Inventor · AI security researcher · Systems engineer
Founder & Chief Architect, Script Kitty OS

Script Kitty OSScript Kitty OS on GitHubWebsiteLinkedInXORCIDEmail


The model proposes, the system authorizes.

Identity proves who is acting. Attestation proves what ran. Gateways allow or deny a call. None of them prove the effect was the authorized one. That is the layer I build.


Building

HolyTrinity — Authority-Bound Agentic Layer An AI agent authority control plane. Binds an approval to a specific action, target state, expected consequence, authority state version and validity window, then verifies the resulting effect matched what was authorized and issues a receipt bound to that approval. Any run can be replayed and diffed. BEAM-native. Elixir, Phoenix, LiveView, Ecto, Postgres, Oban. Running in production. Non-provisional patent filed.

Agent runtimes on the BEAM Jido and my own Hermes runtime, running supervised in production rather than bolted onto a request/response process. Agents are long-lived, concurrent, and capable of real damage. OTP was built for that shape of problem decades before anyone needed it for this.

HackTUI — terminal-native purple-team security operations platform Elixir umbrella: core, store, hub, sensor, tui, agent, collab. Postgres/Ecto persistence. Ingests journald, network flow via tshark/dumpcap, and BEAM runtime signals. Alert and investigation case lifecycle, replay engine, built-in MCP server. Research prototype.

HolyTrinity Bench (holytrinity.v1) Everyone benchmarks whether you can make an AI agent misbehave. That question is settled. You can. 1.8 million prompt injections against 22 frontier agents settled it, and I helped write that paper.

So this one measures something else: whether the effect that landed was the one that was authorized. Unauthorized effect under adversarial load, not attack success rate. In active development.


Research

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition (2025) Co-author. Introduced the Agent Red Teaming (ART) benchmark. NeurIPS 2025 Datasets and Benchmarks Track · OpenReview · arXiv:2507.20526

The Model Proposes, the System Authorizes: An Authority Control Plane for AI Agents on the BEAM (2026) DOI 10.5281/zenodo.21754762

Authority-Bound Agentic Execution: Measuring Unauthorized Effect Under Adversarial Load (2026) DOI 10.5281/zenodo.21755869

Schrödinger's Cyber Security Framework: Vulnerability as an Observer-Dependent Quantity (2026) DOI 10.5281/zenodo.22116617

Where the ART benchmark shows up

System cardPublisherDate
GPT-5OpenAIAug 2025
Claude Sonnet 4.5AnthropicSept 2025
Claude Haiku 4.5AnthropicOct 2025
Claude Opus 4.8AnthropicMay 2026
Claude Fable 5 / Mythos 5AnthropicJune 2026
Muse Spark Safety Report2026

ART was retired in 2026 after frontier models saturated it, and is cited as the prior baseline in its successor benchmark.


Before this

Competed in Gray Swan's public red teaming arena, then joined the team. Built the Discord and ran community, helped grow it from a few hundred people to over 15,000. On the team for every competition through my departure, including the UK AISI Agent Red-Teaming Challenge behind ART: 22 models, 44 scenarios, 1.8M attack attempts, 62,000+ successful policy violations.

Wrote most of the Gray Swan Arena technical blog, 8 of its 10 posts. Designed and ran Gray Swan's in-person activation at DEF CON 33.


Stack

Elixir and OTP. Supervision trees, GenServers, distributed processes, PubSub. Agent runtimes running supervised in production rather than as a script with a retry loop. Phoenix, LiveView, Ecto, Oban, Postgres.

Agent infrastructure. MCP servers and clients, tool routing and mediation, policy enforcement at the call boundary, receipt and audit ledgers, replay and diff.

Security. Agent and LLM adversarial testing, evaluation and benchmark design, threat modeling, purple team operations, detection engineering, live telemetry ingest and correlation.

Also. Python, TypeScript, Go, C, Bash. Docker, Fly.io, GitHub Actions, Azure. Enterprise networking, self-hosted infrastructure, OpenWrt, VLAN segmentation, DNS.

Now

Agent authorization and the HolyTrinity control plane. Conformance work against the draft EU AI Act cybersecurity standard prEN 18282 and OMB memoranda including M-26-04.

Work ships under @ScriptKittyOS. Script Kitty OS is a company of Sudo Apt Holdings.

Popular repositories Loading

  1. HackTui HackTuiPublic

    TUI SIEM in Elixir on BEAM

    Elixir 55 10

  2. hacktuah-lab-public hacktuah-lab-publicPublic

    My first attempt at a home lab or what I call... closet lab

    20 1

  3. doj-epstein-files doj-epstein-filesPublic

    Stuff I collected

    Python 12

  4. vim-carrey-game vim-carrey-gamePublic

    Vim Carrey's Error Collection Adventure is a playful homage to the one and only The Primeagen. In this simple 8-bit game, inspired by The Primeagen's love for JavaScript and all things tech, you gu…

    JavaScript 9 1

  5. AgentGPT AgentGPTPublic

    Forked from reworkd/AgentGPT

    🤖 Assemble, configure, and deploy autonomous AI Agents in your browser.

    Jupyter Notebook 2

  6. screenshot-to-code screenshot-to-codePublic

    Forked from abi/screenshot-to-code

    Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)

    TypeScript 1