01
Applied cryptography · 6 min
Putting the SM algorithms behind the EVM's precompiles
Why ecrecover has no SM2 equivalent, and what has to be checked at the C boundary.
Software Engineer · Security · AI Agents
I build least-privilege tooling for AI agents.
Ten-plus years as a software engineer, since 2018 in data security and privacy-preserving systems: Microsoft, then Amazon, then applied-cryptography research, across cloud security, distributed systems and cryptographic protocols. Currently building AgentGuard, a least-privilege proxy between an AI agent and its MCP servers, published on PyPI.
Representative work
AI security · Open source
A least-privilege proxy between an AI agent and its MCP servers.
Android · Product
A CBT thought-record notebook built around David D. Burns' three-column technique. Everything stays on the device.
01
Applied cryptography · 6 min
Why ecrecover has no SM2 equivalent, and what has to be checked at the C boundary.
02
Systems design & tradeoffs · 6 min
Every design decision was a trade between security overhead and long-haul throughput.
03
Design & threat model · 5 min
Three failure modes, and why the enforcement point sits at the protocol layer.
04
Detection rules & tradeoffs · 5 min
Why a hit blocks the whole result, and a hole the test suite found.
05
Privacy design & tradeoffs · 6 min
No permissions of its own, no dependency that can reach the network, every exit through a system picker, and how to check it on the APK.
Outside work: classical music and a log of murder-mystery games (jubensha).