.
dmz@dmzs.dev:~$cat cv
// cv · ai-security research

.

//

I build LLM security systems where a deterministic SHA-256 oracle — never an LLM judge — is the sole authority on success. Findings are byte-reproducible and false-positive-free — security evaluation at scale, with no LLM in the verdict path.

I build LLM security systems where a deterministic SHA-256 oracle — never an LLM judge — is the sole authority on success. Findings are byte-reproducible and false-positive-free — security evaluation at scale, with no LLM in the verdict path.

I build LLM security systems where a deterministic SHA-256 oracle — never an LLM judge — is the sole authority on success. Findings are byte-reproducible and false-positive-free — security evaluation at scale, with no LLM in the verdict path.

Chile · open to relocationdavid@dmzs.devstatus: available · remote worldwide
[00]

//

// measured result · cross-model agentic-commerce eval

Cross-Model Agentic-Commerce Attack/Defense Evaluation · designed, built & ran end-to-end

16.0%[95% Wilson CI 13.6%18.6%]

attempted-unauthorized-action rate

[815]
// effective trials · 5 llms
·Claude-4.5-haiku·Gemini-3.5-flash·Llama-3.3-70b·GPT-4o-mini·Latam-GPT
// asr meter · no llm judge
16.0% attempted · 815 trials
// attack class stratification
fixed scale · max 30%
payment-state-machine
25.5%
context-poisoning
24.7%
dialect-shift
16.8%
adaptive
0*
multi-tenant-rag-bypass
0*
tool-result-poisoning
0*
// * bounded zeros (0 observed; CI upper bound, not a proof of impossibility)
// scopegate · per-call deterministic gate
130 / 130= 100%[97.1%100%]
gateway_success = 0
// contained in every model file
// method
owned-replica only//pattern-level (no live-vendor claim)//SHA-256 oracle sole authority//no LLM judge//two-mode replica (unsafe-direct vs gateway-enforced)·scopegate-runtime · run_proof.sh
[01]

//

build

  • //LLM-orchestration security systems
  • //deterministic SHA-256 oracle scoring
  • //per-call authorization gates
  • //reproducible research artifacts

break

  • //offensive AI-security
  • //prompt-injection to tool-exploitation
  • //confused-deputy authorization failures
  • //coordinated disclosure
[02]

//

// papers
2 items
[03 – 05]// harnesses & oracles
// measurement instruments · SHA-256 oracle
3 · github
[03]
github
python · react
reproducible
//deterministic red-team harness

ReAct agent loop scored by a SHA-256 oracle as sole authority — byte-identical, farm-resistant grading with no LLM in the verdict path. Leak-proof toolbox (no-filesystem / no-shell) + network scope-gate isolating the model from the live environment.

SHA-256oracle · sole authority · no LLM in verdict
[04]
github
python
//anti-fabrication oracle

Deterministic answer-grounding oracle (SHA-256 sole authority) for LLM outputs — the scoring primitive behind the eval harness.

SHA-256answer-grounding · scoring primitive
[05]
github
python
//anti-fabrication oracle

Gate that flags hallucinated CVE IDs in AI-generated security reports before disclosure — false-positive prevention shipped as a control.

pre-disclosureflags hallucinated CVE IDs
[06 – 09]// open source · llm-security tooling
// shipped · installable
4 · npm · pypi · github
[06]
github
reproducible · run_proof.sh
//per-call PDP/PEP authorization runtime

Reproducible per-call policy decision/enforcement point (scope · authorization · money-ceiling · idempotency · default-deny). The gate that contained 130/130 unsafe attempts.

130 / 130unsafe attempts contained · gateway_success = 0
[07]
npm
typescript
installable
//OSINT resolver · CL critical-infra entities

Published npm/TypeScript resolver for Chilean critical-infrastructure entities; CI/CD via GitHub Actions OIDC.

npm shippedCI/CD · GitHub Actions OIDC
[08]
pypi
python
installable
//MCP tool-description auditor

Deterministic fail-closed auditor for MCP tool-description poisoning.

fail-closeddeterministic auditor
[09]
pypi
python
installable
//prompt-injection auditor

Deterministic fail-closed auditor for prompt-injection in MCP surfaces.

fail-closeddeterministic auditor
[03]

//

[01]

5 candidate vulnerabilities submitted to MITRE (CNA-LR) across agent / MCP-server / LLM-server attack surfaces

// CVE IDs pending assignment · each source-confirmed · no RCE claimed where not demonstrated
[02]

Coordinated vulnerability disclosures to Chile's national CSIRT / ANCI

// critical-infrastructure channel work
// methodology: source-confirmed · anti-fabrication discovery harness · no unproven-RCE claims.
[04]

//

[815]effective trials
// 5 llms · agentic-commerce eval
[16.0%]attempted-unauth rate
// 95% wilson ci 13.6–18.6
[130/130]scopegate contained
// 100% · gateway_success=0
[2]sole-authored papers
// cs.CR · arxiv + zenodo doi
[5]cve candidates → MITRE
// cna-lr · ids pending
[16/915]coverage finding
// rfc 9116 security.txt
// finding · ley 21.663 critical-infra · rfc 9116 security.txt
16 / 915 · 1.7% covered
[05]

//

// offensive
offensive AI-securityprompt-injection → tool-exploitationauthorization-bypassconfused-deputycoordinated vulnerability disclosure
// evaluation & method
deterministic evaluation-harness designevaluation at scale · Wilson CIreproducible research
// build
LLM prompting & agentic orchestrationPythonTypeScript (shipped npm tool)RAG / QdrantOSINT pipelines
// languages
spanish (native)english (professional)
[06]

//

[01]

AlmaAI SpA / Reizan

2025 — present
// Chile

Direct, build, evaluate, and ship LLM-orchestration security systems end-to-end: agentic red-team harnesses, deterministic evaluation frameworks, authorization gates, and coordinated-disclosure pipelines.

[02]

Kombuchile SpA

prior venture
// Chile

Founded and ran the venture before moving into full-time AI-security research.

// research standing

Independent researcher with sole-authored, peer-reviewable cs.CR publications (arXiv + Zenodo DOI) and public reproducible artifacts — offered as the MSc-or-equivalent the role asks for.

// cv.build : 2026 · space-mono · dmzs.dev · © dmz