Co-founder & CEO of Argus. Ex-PDD algorithm engineer. USC researcher. I build open-source security tools that find the vulnerabilities Semgrep and Bandit can't see — prompt injection, credential leakage, trust boundary violations in agent code.
I find and fix the security gaps that traditional tools can't see. Semgrep and Bandit produce zero findings on agent-specific vulnerabilities. Argus's open-source scanner surfaces the entire category — prompt injection in tool definitions, overprivileged MCP configs, credential leakage, unsandboxed code execution. 85+ detection rules mapped to the OWASP Agentic Top 10.
Before founding Argus, I was a Founding Engineer at Topify.ai, where I built a full end-to-end GEO agent from scratch — the company raised a $1.5M seed and hit $300K in bookings within 3 months. Before that, I was an Algorithm Engineer at PDD (Pinduoduo), working on causal inference and uplift modeling at scale.
I'm pursuing my M.S. in ECE at USC (2025–2027), researching LLM and agent security under Prof. Yue Zhao at the FORTIS Lab. My undergrad is from Shanghai Jiao Tong University (SJTU, ECE, 2022–2025).
The AI agent ecosystem is growing faster than its security infrastructure. Someone needs to build the guardrails. That's what I do.
The security platform for AI agent code — Snyk for agents and MCP. We find vulnerabilities that Semgrep and Bandit miss entirely, because those tools were never built for the agent era.
| Tool | Generic Issues | Agent-Specific | MCP Configs | Trust Boundaries |
|---|---|---|---|---|
| Semgrep | 45 | 0 | ✗ | ✗ |
| Bandit | 343 | 0 | ✗ | ✗ |
| Argus (agent-audit) | — | 30+ | ✓ | ✓ |
CLI security scanner for AI agent codebases. 85+ rules, 7 engines. Python AST, taint tracking, MCP config auditing, semantic credential detection. Python / TypeScript / Go / Solidity. GitHub Action for CI/CD.
First public benchmark for evaluating agent security tools. OWASP-aligned. No competitor has built one. Positions Argus as the standard-setter for agent security evaluation.
Specialized security profile for DeFi agents (--profile defi). 20 additional rules for on-chain agent interactions. Cross-stack AI Agent × DeFi security audit — globally unique.
Multi-Dimensional Trust Assessment Framework for LLM Agent Applications. Evaluating trust across safety, reliability, and compliance dimensions in production agent systems.
Robustness evaluation for tool-calling LLMs. Sim-to-Real gap perturbations on queries, tool descriptions, tool sets, and runtime environments. Testing if models reliably select and invoke tools under realistic variations.
Built end-to-end Generative Engine Optimization agent as Founding Engineer. $1.5M seed, $300K bookings in 3 months. Origin story: where I first discovered agent security gaps at scale.
Building the security infrastructure for AI agents. Shipped 85+ rule CLI to PyPI. Filed vulnerabilities in 4 major frameworks (143k+ combined stars). First commercial audit completed. Agent-Vuln-Bench published. Two ACM demo papers submitted. Stanford SNAP Lab engagement.
Built end-to-end GEO agent from scratch. Company raised $1.5M seed, $300K bookings in 3 months. First-hand encounter with agent security gaps — exploitable tool definitions, wildcard MCP permissions, scattered credentials. Direct origin of Argus.
Causal inference and uplift modeling at one of the world's largest e-commerce platforms. Built models to measure and optimize treatment effects at scale.
Research: LLM and agent security. USC FORTIS Lab under Prof. Yue Zhao (CMU PhD, 22k+ GitHub stars, 35M+ OSS downloads, NVIDIA & Amazon Research Awards).
Undergraduate degree in ECE from one of China's top engineering universities (C9 League).
Open to security audits, design partnerships, research collaborations, and open-source contributions.