Skip to content
View mismail21's full-sized avatar

Highlights

  • Pro

Block or report mismail21

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mismail21/README.md

Hi, I'm Mohammad Ismail 👋

Computer & Data Science student at Concordia University (2028) · AI engineering & AI security 📍 Montréal, QC · 🔐 Currently exploring: agent security & evaluation

I build LLM agents and secure systems, and I care about making AI output verifiable and agents hard to hijack. I've interned across enterprise consulting, security engineering and full-stack ML, and co-founded a startup that reached $8K+ in monthly revenue.

🔭 Projects

AgentShield — a prompt-injection defense layer and reproducible benchmark for tool-using LLM agents. Three agents to attack, a 100-attack corpus, four composable safeguards (detector, spotlighting, least-privilege tools, output checker), a DistilBERT detector and an AgentDojo adapter, all on free/local models. On Qwen3 1.7B the full defense cut attack success from 11% to 0% while utility under attack rose from 44% to 66%. The DistilBERT detector failed to generalize, and that result is reported openly.

Grounded Vulnerability Triage Agent — an LLM agent that turns a dependency file into a prioritized vulnerability fix report using 6 tools (OSV, NVD, CISA KEV, EPSS, upgrade checks, schema-validated report). A grounding checker ("no source, no value") verifies every claim against fetched evidence: across 18 test manifests it found 171/171 vulnerabilities, raised 0 false alarms, and blocked the 1 fabricated value in 1,026 claims.

SustainaMars — an interactive Mars growth system built around sustainable waste recycling at Jezero Crater, with plant monitoring and AI mission planning.

💼 Experience

  • Co-Founder, Carevio (2026) — B2B pharmacy delivery platform grown to $8K+/month in 7 months. Built the iOS app, website and delivery tools (TypeScript, Supabase) and designed the routing algorithm.
  • Technology & Transformation Intern, Deloitte Middle East (2026) — Business Continuity Management; designed a 5-agent agentic AI pipeline to automate Business Impact Analysis (~75% fewer analyst hours modelled on synthetic data).
  • Cybersecurity Engineering Intern, IronClad Family (2026) — Built a blockchain layer and Zero Trust (NIST 800-207) permission layer for a zero-knowledge vault; scanned with OWASP ZAP and Bandit.
  • Full Stack Software Engineering Intern, Micropolis Robotics (2025) — Spring Boot + Angular movie recommendation platform with a Python similarity model.

🛠️ Tech

Python Java TypeScript JavaScript SQL FastAPI React Spring Boot Angular Supabase Docker

  • GenAI / Agents: LLM agents, tool calling, grounding & evaluation, prompt-injection defense, n8n, Make.com
  • Security: Penetration testing (OWASP Top 10, SQLi, XSS), CVSS, OWASP ZAP, Bandit, Zero Trust
  • ML: Machine learning, recommendation models, data analysis (Matplotlib, Seaborn)

📫 Reach me

LinkedIn · Email

Pinned Loading

  1. grounded-vuln-triage grounded-vuln-triage Public

    LLM agent that triages dependency vulnerabilities (OSV, NVD, CISA KEV, EPSS) with a grounding checker: no source, no value.

    Python 1 1

  2. agentshield agentshield Public

    Prompt-injection defense layer and benchmark for tool-using LLM agents: 3 agents, 100 attacks, composable safeguards, DistilBERT detector, AgentDojo comparison

    Python