Skip to content
View howardhsieh's full-sized avatar

Block or report howardhsieh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
howardhsieh/README.md

Hi, I'm Howard

Security engineer focused on cloud infrastructure security and AI agent security.
MS Cybersecurity Engineering @ USC (Jun 2027) · prev. Security Engineer @ Systex (Splunk SIEM, 15 enterprise clients)

Website LinkedIn Email

Stack

Python Bash AWS Terraform Splunk GitHub Actions Linux Tailscale

What I've built

  • agent-policy-gateway — reference-monitor gateway for AI agent tool calls: YAML policies + taint-tracking information-flow control that blocks indirect prompt-injection exfiltration. On PyPI, OIDC trusted publishing.
  • tracesig — Sigma-style detection rules for AI agent tool-call traces: open YAML rule format, reference engine, and a 12-rule starter pack covering prompt injection, exfiltration, privilege, and anomaly patterns. On PyPI.
  • llm-canary — canary tokens for LLM contexts to catch prompt injection and context exfiltration.
  • Interned on a security team building a zero-trust AWS platform: eliminated all public SSH across dev/prod (Tailscale subnet routers + ephemeral CI nodes), designed 12h JIT access to production, rolled out GuardDuty/Inspector/Prowler across a multi-account org.
  • Co-author, IEEE Access (2025): TIRDH — reversible data hiding algorithm.

GitHub

GitHub streak

Pinned Loading

  1. agent-policy-gateway agent-policy-gateway Public

    Reference-monitor security gateway for AI agents — YAML policies + information-flow control over MCP / OpenAI / Anthropic tool calls. Blocks indirect prompt-injection exfiltration by policy.

    Python 1

  2. llm-canary llm-canary Public

    Plant detection canaries in LLM contexts to catch prompt injection, cross-tenant leaks, and context exfiltration.

    Python

  3. tracesig tracesig Public

    Sigma-style detection rules for AI agent tool-call traces: 23 provenance, taint and sequence rules. Scans Claude Code sessions and agent-policy-gateway audit logs; works on any agent's JSONL trace.

    Python 1