$ whoami
Daniel Alfasi
AI Security Research Lead at Reco
I break (and sometimes build) agentic systems, coding agents, and LLM applications - then ship the detection logic that catches the same attack in production. Findings that stay in a slide deck aren't findings.
selected work
Research that ships
OWASP Agentic Skills Top 10
OWASP published the Agentic Skills Top 10. I contributed three attack scenarios: Relay-Node Amplification, Model-Dependent Injection Resistance, and Unreachable Skill. Why they ...
When acceptEdits quietly becomes code execution: a Grok Build hook-persistence bug
Grok Build's acceptEdits mode auto-approves file writes. Its global hooks directory is always trusted and runs at full user privilege. Combining the two turns a convenience sett...
writing
Latest from the blog
focus
What I work on
Agentic red teaming at scale: prompt injection, tool misuse, memory and RAG poisoning, scenario generation, and turning research into production detections.