Skip to content
View TrueFurina's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report TrueFurina

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
TrueFurina/README.md

TrueFurina

Typing SVG

Profile Views


🚀 About Me

name: TrueFurina
title: AI Agent Security Product Manager
company: DBAPP Security
focus_areas:
  - AI Agent Security Architecture & Governance
  - LLM Security Risk Assessment & Red Teaming
  - AI Security Product Strategy & Roadmap
  - Trustworthy AI Compliance & Standards
core_competencies:
  - AI Agent Security: 
    - Agent prompt injection defense & isolation
    - RAG pipeline security & data sanitization
    - Model output validation & guardrails
    - Agent-to-agent communication security
  - Product Management:
    - End-to-end product lifecycle management
    - Cross-functional team leadership
    - Technical roadmap planning
    - Stakeholder communication
  - Security Domain:
    - Threat modeling & risk assessment
    - Security architecture review
    - Compliance frameworks (ISO 27001, etc.)
    - Security testing & validation
mission: "Building AI systems that are not only powerful, but trustworthy."
motto: "Security is not a feature — it's a foundation."

Tech Stack


🔥 Featured Open Source

🕵️ Passive Recon

Zero-touch, purely passive OSINT/EASM/CTEM platform — 15+ data sources, one command, no probes sent.

Feature Description
🔍 15 Passive Data Sources crt.sh, HackerTarget, OTX, URLScan, Wayback, DNSDumpster, CommonCrawl, GitHub, Hunter, FOFA, SecurityTrails, Shodan, VirusTotal, ZoomEye, Qichacha
🛡️ Compliance Guardrail Fail-closed R1 compliance on every outbound call
🌐 Web Dashboard One-click panel
⏰ Auto Scheduler Daily collection with change tracking

Goal: 1000 Stars ⭐

⭐ Star on GitHub · 📖 README · 🌐 Website


💼 Work Experience

AI Agent Security Product Manager

DBAPP Security | 2023 - Present

Leading the development of AI Agent security products from concept to delivery. Focused on securing enterprise AI Agent deployments across multiple industries.

Key Responsibilities

Product Strategy & Roadmap

  • Defined and executed product roadmap for AI Agent security product line, covering LLM security assessment, Agent behavior monitoring, and security governance
  • Conducted competitive analysis and market research to identify gaps in AI security product landscape
  • Established product vision and OKRs aligned with company's AI security strategy

Product Development & Delivery

  • Led cross-functional teams (engineering, research, design) to deliver AI security products on schedule
  • Defined product requirements and technical specifications for Agent security features
  • Managed product backlog, prioritized features based on risk impact and customer needs
  • Drove go-to-market strategy and customer onboarding

Security Research & Standards

  • Developed internal frameworks for LLM vulnerability assessment and red teaming
  • Contributed to AI security standards and best practices documentation
  • Built security evaluation benchmarks for Agent behavior analysis

Key Achievements

  • Led the launch of AI Agent security assessment product, serving enterprise customers
  • Built security evaluation framework covering 50+ attack vectors for LLM-based Agents
  • Established internal AI security red teaming process from ground up

🛠️ Core Competencies

AI Security & Governance

Competency Proficiency Details
LLM Security Assessment ⚡ Advanced Prompt injection, jailbreaking, data leakage, model extraction
Agent Security Architecture ⚡ Advanced Isolation, sandboxing, privilege control, inter-agent security
RAG Security ⚡ Advanced Document sanitization, context isolation, retrieval poisoning defense
Security Governance ⚡ Advanced Policy definition, compliance monitoring, audit trails
Red Teaming 🔷 Expert Attack simulation, vulnerability discovery, remediation guidance

Product Management

Competency Proficiency Details
Product Strategy ⚡ Advanced Roadmap planning, market analysis, competitive intelligence
Requirements Management ⚡ Advanced PRD writing, user story mapping, prioritization frameworks
Cross-functional Leadership ⚡ Advanced Engineering, research, design, marketing coordination
Data-Driven Decision Making ⚡ Advanced Metrics definition, A/B testing, user research

Technical Skills

Skill Proficiency Details
Python ⚡ Advanced Security tooling, data analysis, automation
AI/ML Fundamentals ⚡ Advanced LLM architecture, RAG, fine-tuning, embeddings
Security Tools 🔷 Expert Burp Suite, OWASP methodologies, threat modeling
Data Analysis ⚡ Advanced SQL, statistics, visualization, analytics

📜 Key Projects

AI Agent Security Assessment Platform

Role: Product Manager (Lead) Status: Launched, serving enterprise customers

An enterprise-grade security assessment platform for AI Agent systems. Covers the full lifecycle of Agent security evaluation — from architecture review to runtime monitoring.

Key features:

  • Multi-dimensional LLM security testing (50+ attack vectors)
  • Agent behavior analysis and anomaly detection
  • Automated compliance reporting
  • Real-time security monitoring dashboard

Impact:

  • Reduced enterprise Agent security assessment time by 60%
  • Identified and helped remediate 200+ security vulnerabilities pre-launch
  • Established industry benchmark for Agent security evaluation

LLM Red Teaming Framework

Role: Technical Product Manager Status: Internal tool, deployed across teams

A systematic framework for red teaming LLM-based applications. Designed to be extensible, repeatable, and actionable.

Key features:

  • Automated attack scenario generation
  • Multi-turn conversation attack simulation
  • Vulnerability classification and severity scoring
  • Remediation recommendation engine

Impact:

  • Standardized security testing process across 5+ product teams
  • Discovered 30+ novel attack patterns in production Agents
  • Reduced security review cycle from weeks to days

AI Security Governance Framework

Role: Product Strategy Lead Status: Research & Standards

A comprehensive governance framework for enterprise AI deployment, covering security, privacy, compliance, and ethics.

Key components:

  • AI risk classification and assessment methodology
  • Security control requirements by risk level
  • Compliance mapping (ISO 27001, GDPR, etc.)
  • Continuous monitoring and improvement process

🏆 Certifications & Standards

Certification Area
AI Security & Governance Internal Enterprise AI Security Framework
Product Management End-to-end Product Lifecycle
Security Assessment OWASP / Threat Modeling
Data Protection ISO 27001 Compliance

📊 GitHub Stats

GitHub Stats GitHub Streak Stats

Top Languages

Contribution Activity Graph

Snake Contribution Grid


📫 Connect


Pinned Loading

  1. AGI-Distiller AGI-Distiller Public

    Not just another skill collection. A living knowledge distillation system that self-evolves by reading technical content. 不只是 skill 集合,是一个能自我进化的知识蒸馏系统。

    6

  2. passive-recon passive-recon Public

    🕵️ Purely passive OSINT/EASM/CTEM platform — 15+ data sources, zero-touch asset discovery, risk detection

    Python 6 1

  3. pikachu pikachu Public

    PHP 4

  4. cyber-terms-hub cyber-terms-hub Public

    Cybersecurity terminology resource navigation - glossary, acronyms, frameworks, standards collection

    Python 4

  5. DevRadar-GitHub-Trending-Monitor DevRadar-GitHub-Trending-Monitor Public

    Python 4

  6. MangDeHenZhi MangDeHenZhi Public

    调整后的框架保留了原有的 “技术 - 团队 - 模式” 三维壁垒,更贴合���生项目的普适语境,且每个亮点都有 “具体动作 + 数据支撑 + 对标优势”,既符合创赛对 “创新性、可行性、系统性” 的核心要求,又能让评委快速记住 “这是一个用跨学科能力解决软技能痛点、且能落地的学生项目”。这套亮点完全可以作为核心标签,在 PPT、路演、计划书中反复强化。

    Java 4