Skip to the content.

Work with me

I do independent security review of AI agents, MCP servers, and LLM applications — the kind of careful, curated audit the public scan log demonstrates, run privately and in depth against your codebase.

If you’re shipping an agent framework, an MCP server, a RAG pipeline, or anything that brokers credentials or executes tool calls on a user’s behalf, the questions that matter aren’t “how many findings does a scanner produce” — they’re which findings are real, which are reachable, and which are the dangerous one hiding behind a guard that almost holds. That’s the work.

The proof is public

Everything I’d do for you, I’ve done in the open — 52 curated scans of well-known AI/agent projects, with 11 confirmed fixes where maintainers acted on the findings, and a documented methodology behind each one.

What an engagement looks like

  First-look Full review Ongoing
Scope One service / repo, the high-risk surfaces (auth, tool execution, credential handling, ingestion trust) The whole codebase: source, dependencies (with reachability), container/CI, the trust model Recurring review on a cadence — pre-release, per-quarter, or per-major-feature
You get A prioritized list of real, exploitability-shaped findings with fix guidance + the documented FPs, and a call to walk through them The above, plus an architecture-level write-up of the trust boundaries and where they’re thin A standing relationship — your codebase reviewed as it evolves, not just once
Price $750 flat scoped — contact for a quote retainer, by arrangement

The first-look is a fixed-price entry point — one focused pass to surface what actually matters, with a call to walk through it. Anything larger is scoped per engagement: a 200-LOC MCP server and a 24-MB multi-tenant harness are not the same audit, so tell me the shape and I’ll give you a real number.

What I’m especially good at

The current AI/agent ecosystem, specifically: MCP servers, agent harnesses, tool-execution sandboxes, credential brokering, multi-tenant agent platforms, RAG ingestion, and the LLM-prompt-injection threat model. These are surfaces where off-the-shelf scanners are structurally blind — they see syntax, and the risk lives in cross-process trust boundaries, absence-of-control, and “who can reach this sink with what input.” That gap is the whole reason the public scans surface things scanners miss.

ai-patchlab-pro (coming)

The curation engine behind the public scans — the adversarial-verification workflows, the reachability and ownership-split analysis, the call-graph-aware rule refinements — is becoming a private tool: scan your own repo with the curation layer, not just the raw scanners. If you’d want that as a product (self-hosted or hosted), say so when you reach out and I’ll add you to the early list.

Get in touch

Email dosiswow2@gmail.com with:

I’ll come back with a scoped proposal and a real number. No source code leaves your control without an arrangement you’re comfortable with — the public scans are all run on public repos, and a private engagement is private.


← back to the scan log