Shengxing Zhang

Software Engineer · Security · AI Agents

Shengxing Zhang

I build least-privilege tooling for AI agents.

Ten-plus years as a software engineer, since 2018 in data security and privacy-preserving systems: Microsoft, then Amazon, then applied-cryptography research, across cloud security, distributed systems and cryptographic protocols. Currently building AgentGuard, a least-privilege proxy between an AI agent and its MCP servers, published on PyPI.

Focus
AI-agent security · Applied cryptography · Cloud security
Stack
Python · C++ · Java · Kotlin · AWS (KMS, IAM, S3, DynamoDB) · Linux
Previously
Changan Automobile · Peking University · Amazon · Microsoft
Education
Beihang University, B.Eng. and M.Eng.
Open to
Security and AI-infrastructure roles
Contact
nzaocan@icloud.com

Representative work

  1. 2 TBEncrypted data transfer between the AWS China and global partitionsAmazon · KMS envelope encryption · two untrusting IAM domains · Direct Connect
  2. SM2 · SM4 · SM9National-standard precompiles for a blockchain EVMPeking University · GmSSL · deployed in government and carrier pilots
  3. 369 tests · 93%AgentGuard, a least-privilege proxy for AI agentsOpen source · 34 rules · 1 runtime dependency · PyPI

Projects

All projects

AI security · Open source

AgentGuard

A least-privilege proxy between an AI agent and its MCP servers.

Python · MCP · MIT · PyPI

Android · Product

The Three Column Method

A CBT thought-record notebook built around David D. Burns' three-column technique. Everything stays on the device.

Writing

All writing

05

Designing a notebook that never goes online

No permissions of its own, no dependency that can reach the network, every exit through a system picker, and how to check it on the APK.

Outside work: classical music and a log of murder-mystery games (jubensha).