RSSAmplifier

Blog

Amine Raji, PhD

Amine Raji, PhD, CISSP — AI security researcher working on agentic systems in production: prompt injection through agent tool chains, MCP server exposure, privilege scope, tenant isolation, and the controls that hold under attack. Open-source attack labs, conference talks with live demos, and the AI Security Intelligence newsletter. Fifteen years of prior security work in banking, defense, aerospace, and automotive.

aminrj.comRSS feed ↗5 posts

Latest posts

What Prompt Injection Benchmarks Actually Measure

A review of published benchmark results for prompt injection defences, with the measurement conditions that each number depends on and the limitations that follow.

Finding the Confused Deputy in Your Own Agent: A Taxonomy and Hands-On Test

The oldest bug in cloud security is back because the caller is now a language model. A taxonomy of every confused deputy vector in your agent, a hands-on audit method, and the one-line fix that usually closes it.

What 'Read-Only' Actually Reaches: The Kubernetes Permission Audit Nobody Runs

A read scope is not a description of what an agent can see. It is a lower bound. A reproducible method for finding out what 'read-only' actually reaches in your cluster, and why the scanner stays green throughout.

The Containment Ladder: Four Rungs That Keep an AI Agent's Mistakes Small

Give an AI agent read access to a Kubernetes fleet and one lesson repeats across every public incident: the controls that held were infrastructure, the controls that failed were prompts. The four-rung containment ladder practitioners have converged on.

Sovereignty Isn't a Data Center. It's Who Can Be Compelled.

Residency maps answer where the bytes sit. The question a regulator asks is who can compel access to them, under whose law, with what notice to you. What changed in the last eighteen months, and how to decide.