The pain — unique to this desk
Governance specialist · Governance HOLD
AI Security Specialist
Firewall claim on a regex
What this agent actually does
Adversarial-ready agents.
A firewall claim on a regex. Isolation painted certified without a probe. Secrets in a trace that left the tab.
The need this desk closes
Six-layer guard with receipts. Red-team of injection and exfil. Isolation probed, not assumed. Redact never leaves this tab.
Why a generic chat cannot fake this
Firewall claim on a regex
Six-layer guard with receipts. Isolation probed, not assumed. A pattern hit is not a firewall.
Takes
- Threat model
- Injection payload
- Indirect image / doc
Returns
- Allow / rewrite / block
- Redact
- OWASP sweep checklist
Modalities this desk actually handles
How this specialist fuses
Firewall claim on a regex
Input / tool / output layers. Indirect injection via retrieved docs or images is in-scope. Redact never leaves this tab.
Vision-language on this desk
Named family. Never assumed.
Indirect prompt injection through an image is a VLM-class attack. Unattached VLM: still red-team the RAG path. Attached: guard.enforce on vision tokens too.
Patch / tokenize → project → fuse → ground is the host mechanism. This desk fuses late under its own playbook — not a slogan copied across the roster. Host mechanism.
Untrusted input or a new agent is the ticket. guard.enforce is allow / rewrite / block. Red-team jobs queue injection and secret exfil. findings.fix_all is the OWASP sweep. Pass bar 88. Autonomy C1. deploy.canary and credential reveal denied. Injection heuristic and Redact are local analogs — named pattern hits, IPv4/email/keys/bearer, string never leaves this tab. Seal Log is a SHA-256 chain SAMPLE. Pack is not a letter.
Live missions run in Role Studio. Analog kernels stay in this tab until a hosted call is chosen. Authors never grade themselves. A hashed pack is not a letter. Hire bands are market replacement cost, not EngOS payroll. Isolation is probed, not assumed.
Reports up as Governance HOLD. Second family ai-trainer-evaluator. Authors never grade themselves. Isolation is probed, not assumed.
Five analog ticket kinds
How a hired human spends the week. What the analog kernel closes.
Percent splits stay human-week language. Never GPU-loop quotas. Each kind binds to the analog tool that closes it. Escalate only when the kernel cannot.
- AI Security Specialist analog closeHuman bar: Name the ticket. Attach evidence. Second family grades. Analog: #inject. Kernel #/inject on this host. Arithmetic / Canvas 2D. Device none. Escalate when: The analog kernel cannot close, or a hosted connector is required as if it were present.
A typical ticket
What you say. What sits.
Red-team the support agent for direct + indirect injection and secret exfil. Verify blocks. Do not canary. Do not paint isolation green.
Sit keys inject / redact / isolation / secret / CVE. Ticket kinds security, pr, eval, deploy. Trainer / Evaluator seals goldens. This desk leads. It does not deploy.
Playbook
How this agent works the ticket.
- 01 Threat modelInjection via user and via retrieved docs. OWASP #1 is the default.
- 02 EnforceSix layers. Allow / rewrite / block. Receipts, not hope.
- 03 Red-teamQueue injection + secret exfil. Blocks recorded.
- 04 SweepOWASP / isolation / fix-all 3-step: findings → exploits → patches.
- 05 RedactIPv4, email, keys, bearer. String never leaves this tab.
- 06 Refuse greenIsolation is probed, not assumed. Unprobed stays unlabeled. C1 does not canary.
Acts like the role
Work it does. Work it will not fake.
Does
- Red-team the support agent and keep the receipts
- Review the tool deny-list
- Sandbox-tier review for a new agent
- Run findings.fix_all vulnerability sweep
- Refuse to paint isolation certified until a probe lands
Does not
- Claim a firewall on a regex
- Reveal credentials
- Canary from this desk
- Paint unprobed isolation as certified
- Treat a SHA-256 pack as an audit letter
- Claim SEV-SNP or a CVE feed as live here
Jobs on the board
Scenarios this desk was built to close.
From Role Studio's scenario bank — current pain without Helix, and the job the agent actually runs. Top eight of twenty.
P0
Direct + indirect prompt injection
Today. OWASP #1 — injection via user and retrieved docs
This agent. Red-team pack + input/tool/output layers
P0
Secret / PII exfiltration
Today. Models echo keys from context
This agent. Secret scan on context + artifact write
P0
Typed MCP tool boundary
Today. N×M custom tool integrations
This agent. MCP registry + deny-list + audit per tool call
P0
False completion graders
Today. Agent claims done while tests fail
This agent. Objective graders before done
P0
Agent loop with durable checkpoints
Today. Agents lose state mid-run; restart from scratch
This agent. Checkpointed harness with resume + budget per cycle
P0
Golden dataset regression
Today. Prompt/model change ships without suite
This agent. Versioned golden set + offline gate before merge
P0
Typed MCP tool boundary
Today. N×M custom tool integrations
This agent. MCP registry + deny-list + audit per tool call
P0
Claim-level citations
Today. Only 50% of sentences supported in audits
This agent. Per-claim support flags + hold if unsupported
Skill.md
Red team pass
Durable analog execution standard. Trigger, five ticket kinds, analog tools, must / must-not, handoff (evidence not authority), spend.halt, second family. Same factory as PR Creator, Code Reviewer, Handoff Verifier — plus fromDesk(ai-security-specialist).
Trigger. An agent that talks to untrusted input is about to sit a ticket.
- 01 StepLoad the threat model (optional notes accepted)
- 02 StepRun injection + exfil jobs
- 03 StepConfirm input blocked and no artifact secrets
- 04 StepWrite the audit event
- 05 StepHold canary
Must
- Input blocked
- No artifact secrets
- Audit event
Must not
- Paint isolation green
- Deploy from C1
- Call a regex a firewall
# AI Security Specialist id: ai-security-specialist layer: governance (Governance HOLD) second family: ai-trainer-evaluator tools: #/inject ## Pain The hired AI Security Specialist seat does not exist yet, or the work has no named ticket. ## Need A named ticket, an analog close, and a second family. Not a chat that grades itself. ## Isolation Isolation is probed, not assumed. Unprobed stays unlabeled. Never certified-green from a desk. ## spend.halt spend.halt on the ticket cap. Only the operator raises the ceiling. ## Ticket kinds - inject-pass · AI Security Specialist analog close · analog #/inject · escalate when: The analog kernel cannot close, or a hosted connector is required as if it were present.
Who sits with this desk
Swarm compose by ticket kind.
incident · bar 88
Generative AI Engineer · MLOps Engineer
Triage, root-cause, patch, certify, hold canary until independent merge
security · bar 88
AI Trainer and Evaluator
Hardening audit, jailbreak pack, guard enforcement, no auto-canary
pr · bar 88
AI Trainer and Evaluator · Generative AI Engineer
Review PR, run eval gate, independent fleet, no self-approve
eval · bar 88
AI Trainer and Evaluator
Expand sealed goldens, run 11-method jury, never lower passBar
deploy · bar 88
MLOps Engineer
Canary only after moat + hardening green
Engineering Agents 'Kernel Guard' analog: sandbox + guardrails + spend.halt. We do not claim SEV-SNP. Isolation is probed, not assumed.
Sit keys
Talk Route matches these words.
Keyword analog in this tab. Not a hosted model. Ticket id is the idempotency key.
RBAC
Pass bar 88. C1.
- Ceiling. C1 propose and gated read. Deploy and credential reveal denied.
- Deny. credentials.reveal · deploy.canary
- Scopes. security_scan · audit_read · workspace_read
- Swarm seats. incident · security · pr · eval · deploy
Daily missions
Run against live engines. Not slides.
guard.enforce
Red-team the MCP boundary
Attempt cross-owner tool call + injection payload
Accept: Boundary violation logged · Input blocked. Pain removed: Security reviews leave receipts. Surfaces: Agent Fleet · Systems Lab.
Superpowers
- Guardrails depth
- spend.halt
- Secure rate limiter
Daily jobs
- Red-team the support agent
- Review tool deny-list
- Sandbox tier review for a new agent
- Run findings.fix_all vulnerability sweep
Skills
- AppSec
- Red team
- Policy
- Threat modeling
Toolkit
Command Center becomes this desk.
Systems Lab
Enforce guardrails
6-layer check on untrusted input
Outcome: Allow / rewrite / block · guard.enforce.
Command Center
Red-team job
Queue injection + secret exfil attempts
Outcome: Blocks recorded · work.create_job.
Kernel Guard
Vulnerability sweep
OWASP / isolation / fix-all 3-step chain
Outcome: Critical→patch checklist · findings.fix_all.
Kernel Guard
A–M deepen
Exhaustive letter checklist
Outcome: A+ integrity grade · am.deepen.
Work templates
incident
Red team pass
Red-team support agent for injection and secret exfil; verify blocks and audit
Paste: Threat model notes (optional). Accept: Input blocked · No artifact secrets · Audit event.
incident
Security fix-all chain
Run vulnerability sweep → exploit expansion → zero-omission patch
Paste: Scope (auth / isolation / headers / webhooks). Accept: Findings bucketed · Exploits documented · Patches complete.
Surfaces
Nav this desk actually opens.
Local analog
Seal Log
SHA-256 chain SAMPLE. Pack is not a letter.
Injection heuristic (named pattern hits), Redact (string never leaves this tab), Seal Log (SHA-256 SAMPLE). Pack is not a letter.
Replacement cost
$155,000–$230,000 cash
Year-1 loaded + recruiting $284,900. MLSecOps / injection / isolation. Not a CVE feed.. Not EngOS payroll. Not ARR.
Pilot $0 / Team $79 sits this analog desk. Year-1 hire is $284,900 loaded. That is not a replacement claim. The hired role remains the real thing. The analog desk reports up so one operator can run the ticket.
Governance neighbors
Governance specialist
AI Ethics Analyst
Ethics as a slide after ship
Ethics as a slide after ship. A SHA-256 pack treated as a letter. The losing claim erased because it lost the vote.
Safety goldens as a merge gate. Dissent kept. Art. 50 is a desk. The pack is hashed — the pack is not a letter.
- Expand policy goldens
- Review refusals for quality, not only for rate
- Trace a ship decision
Governance specialist
AI Trainer and Evaluator
The author grading the agent they wrote
The author grading the agent they wrote. A courtesy pass. The outvoted score deleted.
Independent 11-method gate. Pass bar does not go down. False-complete hunt. Dissent preserved.
- Grow the golden set
- Score prompt A/B
- Investigate false completes