AI Security.
Security through AI.
Securing AI systems and agents — and building agentic systems that do security work at scale. Securing the AI systems, agents, and software teams are shipping — and building agentic systems that do security work previously too slow or too manual to do at scale.
+ 7,000+ lines crammed into a single file
+ obfuscation · fetch + exec primitives
+ credential + network access at install time
triage score 16,400 → local reviewer: malicious · 95%
reported → removed from PyPI Two mandates. Stated as two things.
Most firms do one or the other.
AI Security
Securing AI systems, agents, and the software teams are shipping with them — agent architectures, tool and MCP surfaces, prompt-injection and data-exfiltration paths, and the trust boundaries between a model and the systems it can act on.
Security through AI
Using AI and agentic systems to do security work that was previously too slow or too manual to do at scale — detection pipelines, static analysis, and review harnesses built for a specific codebase.
What we take on
Findings trace to code paths, with a reproduction and a patch — not a scanner export with severity labels attached.
AI security review
Assessment of AI systems in production: agent architectures, tool and MCP surfaces, prompt-injection and data-exfiltration paths. For teams shipping agents, not for teams writing AI policy documents.
Application security assessment
Source-driven review of web applications and APIs. Findings trace to code paths, with a reproduction and a patch.
Supply chain & dependency security
Detection of malicious and compromised packages in PyPI and npm, informed by current research into how scanners are evaded — cross-file splitting, directory relocation, and related techniques.
vCISO & security risk management
Fractional security leadership: risk scoring models, lifecycle definition, gap analysis against existing policy, and the reporting that makes risk legible to a board. Delivered at enterprise scale for organisations with existing policy landscapes.
Security tooling & automation
Custom static analysis, detection pipelines, and agentic harnesses built for a specific codebase or workflow — where an off-the-shelf tool doesn't fit the shape of the problem.
Secure by design programmes
Security built into how a team ships, not bolted on after: threat models and policies written with the developers, a suggested fix on every finding, the workflow living in the same board as the sprint. Proven over an 18-month enterprise engagement at zero commercial tooling cost. The heavy lifting that made it labour-intensive then — context-aware review, dependency mapping — is what we now automate with AI.
Projects we've built
Research, not products. Both repos are public — read the code.
pyDiffWatch
Static scanner for malicious PyPI publications: diffs each new release against the prior version, scores the change with community YAML rules, escalates to a local LLM reviewer. Static analysis only — it never executes or builds packages.
python · registry monitoring · MIT · public
npmDiffWatch
The same discipline pointed at npm — release diffing, YAML rule triage for install hooks, droppers, and typosquats, LLM review before a human sees the alert. Nothing leaves your machine except registry and model calls.
python · registry monitoring · MIT · public
Registered 2026. A decade behind it.
OffByQuant was registered in July 2026, but the practice behind it is ten years of security consulting — leading engagements and consulting teams for enterprise clients. Based in India, working with clients and partners across EMEA & APAC.
fixes, not findings · policies written with, not for · findings live where the sprint lives
the thinking behind this → uncategorized.blog · On Consulting