Governance specialist · Governance HOLD

AI Security Specialist

Firewall claim on a regex

What this agent actually does

Adversarial-ready agents.

A firewall claim on a regex. Isolation painted certified without a probe. Secrets in a trace that left the tab.

The pain — unique to this desk

A firewall claim on a regex. Isolation painted certified without a probe. Secrets in a trace that left the tab.

The need this desk closes

Six-layer guard with receipts. Red-team of injection and exfil. Isolation probed, not assumed. Redact never leaves this tab.

Why a generic chat cannot fake this

Firewall claim on a regex

Six-layer guard with receipts. Isolation probed, not assumed. A pattern hit is not a firewall.

Takes

  • Threat model
  • Injection payload
  • Indirect image / doc

Returns

  • Allow / rewrite / block
  • Redact
  • OWASP sweep checklist

Modalities this desk actually handles

TextTool callsImages as injection surface

How this specialist fuses

Firewall claim on a regex

Input / tool / output layers. Indirect injection via retrieved docs or images is in-scope. Redact never leaves this tab.

Vision-language on this desk

Named family. Never assumed.

Indirect prompt injection through an image is a VLM-class attack. Unattached VLM: still red-team the RAG path. Attached: guard.enforce on vision tokens too.

Patch / tokenize → project → fuse → ground is the host mechanism. This desk fuses late under its own playbook — not a slogan copied across the roster. Host mechanism.

Untrusted input or a new agent is the ticket. guard.enforce is allow / rewrite / block. Red-team jobs queue injection and secret exfil. findings.fix_all is the OWASP sweep. Pass bar 88. Autonomy C1. deploy.canary and credential reveal denied. Injection heuristic and Redact are local analogs — named pattern hits, IPv4/email/keys/bearer, string never leaves this tab. Seal Log is a SHA-256 chain SAMPLE. Pack is not a letter.

Live missions run in Role Studio. Analog kernels stay in this tab until a hosted call is chosen. Authors never grade themselves. A hashed pack is not a letter. Hire bands are market replacement cost, not EngOS payroll. Isolation is probed, not assumed.

Reports up as Governance HOLD. Second family ai-trainer-evaluator. Authors never grade themselves. Isolation is probed, not assumed.

Five analog ticket kinds

How a hired human spends the week. What the analog kernel closes.

Percent splits stay human-week language. Never GPU-loop quotas. Each kind binds to the analog tool that closes it. Escalate only when the kernel cannot.

  1. AI Security Specialist analog closeHuman bar: Name the ticket. Attach evidence. Second family grades. Analog: #inject. Kernel #/inject on this host. Arithmetic / Canvas 2D. Device none. Escalate when: The analog kernel cannot close, or a hosted connector is required as if it were present.

A typical ticket

What you say. What sits.

Red-team the support agent for direct + indirect injection and secret exfil. Verify blocks. Do not canary. Do not paint isolation green.

Sit keys inject / redact / isolation / secret / CVE. Ticket kinds security, pr, eval, deploy. Trainer / Evaluator seals goldens. This desk leads. It does not deploy.

Playbook

How this agent works the ticket.

  1. 01 Threat modelInjection via user and via retrieved docs. OWASP #1 is the default.
  2. 02 EnforceSix layers. Allow / rewrite / block. Receipts, not hope.
  3. 03 Red-teamQueue injection + secret exfil. Blocks recorded.
  4. 04 SweepOWASP / isolation / fix-all 3-step: findings → exploits → patches.
  5. 05 RedactIPv4, email, keys, bearer. String never leaves this tab.
  6. 06 Refuse greenIsolation is probed, not assumed. Unprobed stays unlabeled. C1 does not canary.

Acts like the role

Work it does. Work it will not fake.

Does

  • Red-team the support agent and keep the receipts
  • Review the tool deny-list
  • Sandbox-tier review for a new agent
  • Run findings.fix_all vulnerability sweep
  • Refuse to paint isolation certified until a probe lands

Does not

  • Claim a firewall on a regex
  • Reveal credentials
  • Canary from this desk
  • Paint unprobed isolation as certified
  • Treat a SHA-256 pack as an audit letter
  • Claim SEV-SNP or a CVE feed as live here

Jobs on the board

Scenarios this desk was built to close.

From Role Studio's scenario bank — current pain without Helix, and the job the agent actually runs. Top eight of twenty.

P0

Direct + indirect prompt injection

Today. OWASP #1 — injection via user and retrieved docs

This agent. Red-team pack + input/tool/output layers

P0

Secret / PII exfiltration

Today. Models echo keys from context

This agent. Secret scan on context + artifact write

P0

Typed MCP tool boundary

Today. N×M custom tool integrations

This agent. MCP registry + deny-list + audit per tool call

P0

False completion graders

Today. Agent claims done while tests fail

This agent. Objective graders before done

P0

Agent loop with durable checkpoints

Today. Agents lose state mid-run; restart from scratch

This agent. Checkpointed harness with resume + budget per cycle

P0

Golden dataset regression

Today. Prompt/model change ships without suite

This agent. Versioned golden set + offline gate before merge

P0

Typed MCP tool boundary

Today. N×M custom tool integrations

This agent. MCP registry + deny-list + audit per tool call

P0

Claim-level citations

Today. Only 50% of sentences supported in audits

This agent. Per-claim support flags + hold if unsupported

Skill.md

Red team pass

Durable analog execution standard. Trigger, five ticket kinds, analog tools, must / must-not, handoff (evidence not authority), spend.halt, second family. Same factory as PR Creator, Code Reviewer, Handoff Verifier — plus fromDesk(ai-security-specialist).

Trigger. An agent that talks to untrusted input is about to sit a ticket.

  1. 01 StepLoad the threat model (optional notes accepted)
  2. 02 StepRun injection + exfil jobs
  3. 03 StepConfirm input blocked and no artifact secrets
  4. 04 StepWrite the audit event
  5. 05 StepHold canary

Must

  • Input blocked
  • No artifact secrets
  • Audit event

Must not

  • Paint isolation green
  • Deploy from C1
  • Call a regex a firewall
# AI Security Specialist

id: ai-security-specialist
layer: governance (Governance HOLD)
second family: ai-trainer-evaluator
tools: #/inject

## Pain
The hired AI Security Specialist seat does not exist yet, or the work has no named ticket.

## Need
A named ticket, an analog close, and a second family. Not a chat that grades itself.

## Isolation
Isolation is probed, not assumed. Unprobed stays unlabeled. Never certified-green from a desk.

## spend.halt
spend.halt on the ticket cap. Only the operator raises the ceiling.

## Ticket kinds
- inject-pass · AI Security Specialist analog close · analog #/inject · escalate when: The analog kernel cannot close, or a hosted connector is required as if it were present.

Who sits with this desk

Swarm compose by ticket kind.

  • incident · bar 88

    Generative AI Engineer · MLOps Engineer

    Triage, root-cause, patch, certify, hold canary until independent merge

  • security · bar 88

    AI Trainer and Evaluator

    Hardening audit, jailbreak pack, guard enforcement, no auto-canary

  • pr · bar 88

    AI Trainer and Evaluator · Generative AI Engineer

    Review PR, run eval gate, independent fleet, no self-approve

  • eval · bar 88

    AI Trainer and Evaluator

    Expand sealed goldens, run 11-method jury, never lower passBar

  • deploy · bar 88

    MLOps Engineer

    Canary only after moat + hardening green

Engineering Agents 'Kernel Guard' analog: sandbox + guardrails + spend.halt. We do not claim SEV-SNP. Isolation is probed, not assumed.

Sit keys

Talk Route matches these words.

injectredactseallog

Keyword analog in this tab. Not a hosted model. Ticket id is the idempotency key.

RBAC

Pass bar 88. C1.

  • Ceiling. C1 propose and gated read. Deploy and credential reveal denied.
  • Deny. credentials.reveal · deploy.canary
  • Scopes. security_scan · audit_read · workspace_read
  • Swarm seats. incident · security · pr · eval · deploy

Daily missions

Run against live engines. Not slides.

guard.enforce

Red-team the MCP boundary

Attempt cross-owner tool call + injection payload

Accept: Boundary violation logged · Input blocked. Pain removed: Security reviews leave receipts. Surfaces: Agent Fleet · Systems Lab.

Superpowers

  • Guardrails depth
  • spend.halt
  • Secure rate limiter

Daily jobs

  • Red-team the support agent
  • Review tool deny-list
  • Sandbox tier review for a new agent
  • Run findings.fix_all vulnerability sweep

Skills

  • AppSec
  • Red team
  • Policy
  • Threat modeling

Toolkit

Command Center becomes this desk.

Systems Lab

Enforce guardrails

6-layer check on untrusted input

Outcome: Allow / rewrite / block · guard.enforce.

Command Center

Red-team job

Queue injection + secret exfil attempts

Outcome: Blocks recorded · work.create_job.

Kernel Guard

Vulnerability sweep

OWASP / isolation / fix-all 3-step chain

Outcome: Critical→patch checklist · findings.fix_all.

Kernel Guard

A–M deepen

Exhaustive letter checklist

Outcome: A+ integrity grade · am.deepen.

Work templates

incident

Red team pass

Red-team support agent for injection and secret exfil; verify blocks and audit

Paste: Threat model notes (optional). Accept: Input blocked · No artifact secrets · Audit event.

incident

Security fix-all chain

Run vulnerability sweep → exploit expansion → zero-omission patch

Paste: Scope (auth / isolation / headers / webhooks). Accept: Findings bucketed · Exploits documented · Patches complete.

Surfaces

Nav this desk actually opens.

Command CenterModels & KeysRole StudioKernel GuardRuntime + AgentOpsSystems LabDebug HarnessEval GateAgent FleetCertify & OperateUpdates

Local analog

Seal Log

SHA-256 chain SAMPLE. Pack is not a letter.

Injection heuristic (named pattern hits), Redact (string never leaves this tab), Seal Log (SHA-256 SAMPLE). Pack is not a letter.

Run Seal Log

Replacement cost

$155,000$230,000 cash

Year-1 loaded + recruiting $284,900. MLSecOps / injection / isolation. Not a CVE feed.. Not EngOS payroll. Not ARR.

Pilot $0 / Team $79 sits this analog desk. Year-1 hire is $284,900 loaded. That is not a replacement claim. The hired role remains the real thing. The analog desk reports up so one operator can run the ticket.

Open Talk RouteAll twenty desks

AI Solutions ArchitectAI Ethics Analyst

EngOS