Skip to content
View woxff's full-sized avatar
  • 21:55 (UTC -12:00)

Highlights

  • Pro

Block or report woxff

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
woxff/README.md

woxff

Security architect and engineer working on AI and agent security, cloud security, runtime isolation, and policy-governed automation.

I write about bounded autonomy: how a system can detect risk, reason about impact, and take action without becoming a new source of risk. That takes more than good automation — it takes trustworthy identity and delegation, enforceable policy, a constrained blast radius, verification and rollback, and complete auditability.

Writing

Bounded Autonomy — secure systems design, agent identity, and policy-governed autonomous defense.

Projects

Repository What it is
agentic-identity-graph Graph-based identity resolution and runtime authorization for enterprise AI agents. Models users, agents, tools, connectors, scopes and policies to make explainable allow/deny decisions on agent tool calls.
autonomous-defense-policy-agent Policy-governed autonomous remediation. Detects risk, scores impact, plans fixes, auto-executes low-risk actions, escalates the rest — with a full audit trail.
agent-guard A safety and audit layer for autonomous agents.
coupon An intentionally vulnerable agentic AI app — the DVWA/WebGoat of the OWASP LLM Top 10, hardened one category at a time. Teaching code, not production.

Views expressed in my writing are my own and do not represent those of any employer.

Popular repositories Loading

  1. agent-guard agent-guard Public

    Python

  2. llm-inference-firewall llm-inference-firewall Public

    Policy enforcement and security controls for multi-tenant LLM inference and agent systems.

  3. autonomous-defense-policy-agent autonomous-defense-policy-agent Public

    Policy-governed autonomous security remediation: detects risk, scores impact, plans fixes, auto-executes low-risk actions, and escalates high-risk changes for human approval — with full audit trail…

    Python

  4. coupon coupon Public

    Intentionally vulnerable agentic AI app for security education — the DVWA/WebGoat of the OWASP LLM Top 10, hardened one vulnerability at a time. Teaching code, not production.

    Python

  5. agentic-identity-graph agentic-identity-graph Public

    Graph-based identity resolution and runtime authorization for enterprise AI agents — models users, agents, tools, connectors, workloads, scopes, policies, and data boundaries to make explainable al…

    Python

  6. woxff woxff Public

    Profile README