# Pradyoth Prashanth > AI security engineer and independent AI red-teamer. Security Engineer II (Associate) in Gen AI Red Teaming within Cybersecurity & Technology Controls at JPMorganChase, building the firm's Gen AI red-teaming capability. Independent research includes 9 product and evaluation-pipeline reports, a CodeAnt scanner benchmark, and a Swiggy product-trust observation. The original reports contain 28 reported finding records, with researcher-assessed severities and explicit evidence limits. Work is entirely self-directed on personal time, unrelated to and outside of his employment. Based in Bengaluru, India. Works at the intersection of adversarial AI, security engineering, and trust & safety: probing LLMs and agentic systems for prompt injection, data leakage, intent drift, and misuse, then building the controls and tooling that catch them. ## Research - [Independent AI security research](https://ppradyoth.web.app/research/): 11 case studies and 26 public evidence records across Jack & Jill AI, Notion AI, Priceline, Brave Leo, Meta AI, Anthropic Claude Code, Reddit Answers, Harvey Labs, HackerOne Hai, CodeAnt, and Swiggy. Compact cases expand to show mechanisms, impact, disclosure history, scope, and additional evidence. Original captures and selected source records are distinguished from summaries and unverified claims. Jack & Jill is the featured case. Google AI and LegalOS appear as reconnaissance notes, not confirmed findings. Open-source contributions to NVIDIA garak, Promptfoo, and Presidio retain dated GitHub status checks. ## Named work - **Synaptic Wetware**: organoid-intelligence biocomputer simulator with neuron models and DishBrain Pong. https://ppradyoth.github.io/synaptic-wetware/ - **IntentScan** and **IntentEnforce** (Akrivon AI): boundary testing and runtime enforcement for deployed AI. IntentScan generates adversarial probes against any AI API — role transformation, gradual drift, language variation — and scores capability, role, and domain violations through an LLM judge into a 0–100 risk report. IntentEnforce is a runtime proxy that classifies user intent per request and applies allow / block / clarify policy before traffic reaches the model. (In development. No public repository.) - **Weighted Safety Refusal (WSR)**: a severity-weighted, gaming-resistant metric for LLM refusal behavior, published as an SSRN preprint. https://doi.org/10.2139/ssrn.6874522 - **Prompt Injection CTF**: an AI security red-teaming playground — 16 challenges covering all 10 OWASP LLM Top 10 (2025) risks, with a defender mode that reveals the guardrail code behind each attack. https://github.com/ppradyoth/prompt-injection-ctf ## Background - [Homepage](https://ppradyoth.web.app/): Current role, work experience at JPMorganChase, named projects (IntentScan / IntentEnforce, Weighted Safety Refusal, Prompt Injection CTF, AgentInjectionBench, Credential Guard), skills, and education. - [Speaking & teaching](https://ppradyoth.web.app/engagements/): Talks, workshops, and lectures on AI security and red teaming. ## Writing - [Blog](https://ppradyoth.web.app/blog/): Articles on AI security, engineering, and the intersection of ML and cybersecurity, cross-posted from Medium. ## Contact - Email: ppradyoth64@gmail.com - LinkedIn: https://www.linkedin.com/in/ppradyoth/ - GitHub: https://github.com/ppradyoth ## Optional - Credential Guard: an open-source runtime guardrail contributed to Anthropic's Claude Code that blocks agent tool calls from writing credentials to disk. https://github.com/anthropics/claude-code/pull/62099