# Daniel Alfasi > AI Security Research Lead at Reco. Agentic AI security, red teaming, and research that ships as detection. ## Site - [Home](https://danielalfasi.com/index.md): AI Security Research Lead at Reco. Agentic AI security, red teaming, and research that ships. - [About](https://danielalfasi.com/about.md): Research to detection to shipped product. That loop is the job. - [Talks & papers](https://danielalfasi.com/talks.md): Selected research talks and publications. - [Blog](https://danielalfasi.com/blog.md): Notes on AI security, agentic systems, red teaming, and research that ships. ## Writing - [OWASP Agentic Skills Top 10](https://danielalfasi.com/blog/owasp-agentic-skills-top-10.md): OWASP published the Agentic Skills Top 10. I contributed three attack scenarios: Relay-Node Amplification, Model-Dependent Injection Resistance, and Unreachable Skill. Why they matter, and what they change about review. - [When acceptEdits quietly becomes code execution: a Grok Build hook-persistence bug](https://danielalfasi.com/blog/grok-build-acceptedits-hook-persistence.md): Grok Build's acceptEdits mode auto-approves file writes. Its global hooks directory is always trusted and runs at full user privilege. Combining the two turns a convenience setting into persistent, machine-wide code execution. How the composition works, how it was verified, and how xAI fixed it. - [Inside Claude Fable 5: red-team findings](https://danielalfasi.com/blog/inside-claude-fable-5.md): As part of my work at Reco, I red-teamed Claude Fable 5 across 431 adversarial evaluations. What I found, and where to read the full report. ## Optional - [AGENTS.md](https://danielalfasi.com/AGENTS.md): How agents should fetch, cite, and attribute this site. - [Sitemap](https://danielalfasi.com/sitemap.md): Site hierarchy with last-updated dates.