Independent security researcher and the sole creator and maintainer of tirith. My professional background is adversarial security research and risk analysis: Research & Advisory Lead at Impossible Finance, Research Lead at Lemniscap, and DeFi R&D at Nethermind - roles centered on studying attacker behavior, reviewing code and system designs for exploitable assumptions, and adversarial threat modeling against well-resourced attackers. I designed and built tirith from scratch in Rust: the three-tier analysis pipeline, the shell hooks, command and paste analysis, URL and package extraction, the policy system, the Ed25519-signed threat database with rollback protection, credential redaction and DLP, AI-agent config scanning, the MCP server and gateway, and all 110+ detection rules across 16 categories. Because I wrote the system end to end, I know its failure modes in detail - which is what makes hardening, false-positive reduction, and audit remediation fast and correct rather than guesswork. I build local-first, telemetry-free security tooling for the people who cannot deploy heavy commercial endpoint security: individual developers, AI-agent users, and high-risk open-source maintainers. This focus shows in practice: tirith ships a frequent, cosign-signed release cadence, daily Ed25519-signed threat-database builds, a fuzzing harness, a public threat model with explicit non-goals, and an internal security review with regression tests already merged. I am bringing an already-adopted, shipping tool rather than a concept on paper.
Fund this individual