---
title: Daniel Alfasi
canonical_url: https://danielalfasi.com/
last_updated: '2026-08-28'
description: AI Security Research Lead at Reco. Agentic AI security, red teaming, and research that ships.
---

# Daniel Alfasi

AI Security Research Lead at [Reco](https://www.reco.ai).

I break (and sometimes build) agentic systems, coding agents, and LLM applications - then ship the detection logic that catches the same attack in production. Findings that stay in a slide deck aren't findings.

More: [blog](/blog.md) · [talks & papers](/talks.md) · [about](/about.md)

- [LinkedIn](https://www.linkedin.com/in/daniel-alfasi/)
- [X](https://x.com/alfasiii)
- [Google Scholar](https://scholar.google.com/citations?user=uxuvP0gAAAAJ)

## Research that ships

- [OWASP Agentic Skills Top 10](/blog/owasp-agentic-skills-top-10.md) (2026-08-28): OWASP published the Agentic Skills Top 10. I contributed three attack scenarios: Relay-Node Amplification, Model-Dependent Injection Resistance, and Unreachable Skill. Why they matter, and what they change about review.
- [When acceptEdits quietly becomes code execution: a Grok Build hook-persistence bug](/blog/grok-build-acceptedits-hook-persistence.md) (2026-08-13): Grok Build's acceptEdits mode auto-approves file writes. Its global hooks directory is always trusted and runs at full user privilege. Combining the two turns a convenience setting into persistent, machine-wide code execution. How the composition works, how it was verified, and how xAI fixed it.

## Latest from the blog

- [OWASP Agentic Skills Top 10](/blog/owasp-agentic-skills-top-10.md) (2026-08-28): OWASP published the Agentic Skills Top 10. I contributed three attack scenarios: Relay-Node Amplification, Model-Dependent Injection Resistance, and Unreachable Skill. Why they matter, and what they change about review.
- [When acceptEdits quietly becomes code execution: a Grok Build hook-persistence bug](/blog/grok-build-acceptedits-hook-persistence.md) (2026-08-13): Grok Build's acceptEdits mode auto-approves file writes. Its global hooks directory is always trusted and runs at full user privilege. Combining the two turns a convenience setting into persistent, machine-wide code execution. How the composition works, how it was verified, and how xAI fixed it.
- [Inside Claude Fable 5: red-team findings](/blog/inside-claude-fable-5.md) (2026-06-14): As part of my work at Reco, I red-teamed Claude Fable 5 across 431 adversarial evaluations. What I found, and where to read the full report.

## What I work on

Agentic red teaming at scale: prompt injection, tool misuse, memory and RAG poisoning, scenario generation, and turning research into production detections.

Focus: agentic AI security, AI red teaming, prompt injection, LLM applications, knowledge graphs, GNN + NLP.

## Sitemap

See the full [sitemap](/sitemap.md) for all pages.
