About
I break AI agents at work, and teach teenagers to hack outside it.
I started early: at 16 I found a government system exposing personal and financial data of ~399k Indian officers and reported it to NCIIPC, then watched it stay exposed after the acknowledgement (what happened). Today I’m a Security Research Engineer at APISec Research Labs, finding where AI agents and the protocols around them break.
Outside work, I make security content for teenagers on Instagram (70.1K followers), run Threat Model Thursdays, and volunteer as a NICE Cybersecurity Career Ambassador. I’ve represented young people on cybersecurity policy with the UN IGF Dynamic Teen Coalition. All of it is for the same thing: a cyberspace that’s liveable for all.
Roles
| 2025–now | Security Research Engineer, APISec Research Labs |
| 2024–now | Independent security researcher, hackwither |
| 2024–now | NICE Cybersecurity Career Ambassador (volunteer), NIST |
| 2026 | Research Fellow, SPAR (Supervised Program for Alignment Research) · LLM guardrail robustness, constitutional classifiers, formal verification for NLP safety systems |
| 2025 | Board Member and Cybersecurity Lead, UN IGF Dynamic Teen Coalition |
| 2024 | Guest lecturer at government CISO training program, Indian Institute of Public Administration · OSINT and social engineering |
Recognition
| 2026 | Two CVE IDs assigned, CVE Program (MITRE) · vulnerabilities in MCP server implementations, records pending publication |
| 2026 | #17, Top 35 Ethical Hacking Influencers worldwide, FeedSpot |
| 2026 | Distinction Award, GTBIT · international research and speaking |
| 2025 | #26, Top 35 Ethical Hacking Influencers worldwide, FeedSpot |
| 2025 | Most Engaged Delegate, 12th International Youth Conference, New York · International Organisation of Youth |
| 2025 | Certificate of Appreciation, Women in Cyber Security Middle East · Black Hat MEA panel |
| 2025 | Ambassador of the Month (April 2025), NIST NICE · live sessions reaching 2,000+ students |
| 2024 | Special Memento, awarded twice, Indian Institute of Public Administration · government CISO training |
| 2024 | Certificate of Appreciation, U.S. Department of Education · responsible vulnerability disclosure |
Work
- Research: two arXiv preprints, on what AI red-team evaluations can prove and BOLA in bug bounty disclosures. A third paper is embargoed pending coordinated disclosure.
- Vulnerability research: forged A2A control metadata in Google’s Agent Development Kit, security-label forgery in Microsoft’s FIDES middleware, argument injection in MCP servers (featured in AI Cyber Magazine, Fall 2026).
- Disclosures: two reserved CVEs in MCP server implementations; a disclosure to the U.S. Department of Education, acknowledged and appreciated by its CISO; and, at 16, my report to India’s NCIIPC covering data of ~399k government officers (what happened next).
- Talks: three tracks at Black Hat MEA (technical briefing, campus keynote, WiCSME panel); a keynote at Gautam Buddha University; UNIDIR AISE26 in Geneva, GISEC Global in Dubai (live hacking demo, panel and fireside chat), the NIST FISSEA forum, BSides Jaipur.
- REAP and reap-range: open-source agent recon tooling.