Skip to content
View TrueFurina's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report TrueFurina

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
TrueFurina/README.md

TrueFurina

Typing SVG


🚀 About Me

name: TrueFurina
title: AI Agent Security Product Manager
company: DBAPP Security
focus_areas:
  - AI Agent Security Architecture & Governance
  - LLM Security Risk Assessment & Red Teaming
  - AI Security Product Strategy & Roadmap
  - Trustworthy AI Compliance & Standards
core_competencies:
  - AI Agent Security: 
    - Agent prompt injection defense & isolation
    - RAG pipeline security & data sanitization
    - Model output validation & guardrails
    - Agent-to-agent communication security
  - Product Management:
    - End-to-end product lifecycle management
    - Cross-functional team leadership
    - Technical roadmap planning
    - Stakeholder communication
  - Security Domain:
    - Threat modeling & risk assessment
    - Security architecture review
    - Compliance frameworks (ISO 27001, etc.)
    - Security testing & validation
mission: "Building AI systems that are not only powerful, but trustworthy."
motto: "Security is not a feature — it's a foundation."


🔥 Featured Open Source

🕵️ Passive Recon

Zero-touch, purely passive OSINT/EASM/CTEM platform — 15+ data sources, one command, no probes sent.

Feature Description
🔍 15 Passive Data Sources crt.sh, HackerTarget, OTX, URLScan, Wayback, DNSDumpster, CommonCrawl, GitHub, Hunter, FOFA, SecurityTrails, Shodan, VirusTotal, ZoomEye, Qichacha
🚀 One Command
🛡️ Compliance Guardrail Fail-closed R1 compliance on every outbound call
🌐 Web Dashboard — one-click panel
⏰ Auto Scheduler Daily collection with change tracking

Goal: 1000 Stars ⭐

⭐ Star on GitHub · 📖 README · 🌐 Website


💼 Work Experience

AI Agent Security Product Manager

DBAPP Security | 2023 - Present

Leading the development of AI Agent security products from concept to delivery. Focused on securing enterprise AI Agent deployments across multiple industries.

Key Responsibilities

Product Strategy & Roadmap

  • Defined and executed product roadmap for AI Agent security product line, covering LLM security assessment, Agent behavior monitoring, and security governance
  • Conducted competitive analysis and market research to identify gaps in AI security product landscape
  • Established product vision and OKRs aligned with company's AI security strategy

Product Development & Delivery

  • Led cross-functional teams (engineering, research, design) to deliver AI security products on schedule
  • Defined product requirements and technical specifications for Agent security features
  • Managed product backlog, prioritized features based on risk impact and customer needs
  • Drove go-to-market strategy and customer onboarding

Security Research & Standards

  • Developed internal frameworks for LLM vulnerability assessment and red teaming
  • Contributed to AI security standards and best practices documentation
  • Built security evaluation benchmarks for Agent behavior analysis

Key Achievements

  • Led the launch of AI Agent security assessment product, serving enterprise customers
  • Built security evaluation framework covering 50+ attack vectors for LLM-based Agents
  • Established internal AI security red teaming process from ground up

🛠️ Core Competencies

AI Security & Governance

Competency Proficiency Details
LLM Security Assessment ⚡ Advanced Prompt injection, jailbreaking, data leakage, model extraction
Agent Security Architecture ⚡ Advanced Isolation, sandboxing, privilege control, inter-agent security
RAG Security ⚡ Advanced Document sanitization, context isolation, retrieval poisoning defense
Security Governance ⚡ Advanced Policy definition, compliance monitoring, audit trails
Red Teaming 🔷 Expert Attack simulation, vulnerability discovery, remediation guidance

Product Management

Competency Proficiency Details
Product Strategy ⚡ Advanced Roadmap planning, market analysis, competitive intelligence
Requirements Management ⚡ Advanced PRD writing, user story mapping, prioritization frameworks
Cross-functional Leadership ⚡ Advanced Engineering, research, design, marketing coordination
Data-Driven Decision Making ⚡ Advanced Metrics definition, A/B testing, user research

Technical Skills

Skill Proficiency Details
Python ⚡ Advanced Security tooling, data analysis, automation
AI/ML Fundamentals ⚡ Advanced LLM architecture, RAG, fine-tuning, embeddings
Security Tools 🔷 Expert Burp Suite, OWASP methodologies, threat modeling
Data Analysis ⚡ Advanced SQL, statistics, visualization, analytics

📜 Key Projects

AI Agent Security Assessment Platform

Role: Product Manager (Lead) Status: Launched, serving enterprise customers

An enterprise-grade security assessment platform for AI Agent systems. Covers the full lifecycle of Agent security evaluation — from architecture review to runtime monitoring.

Key features:

  • Multi-dimensional LLM security testing (50+ attack vectors)
  • Agent behavior analysis and anomaly detection
  • Automated compliance reporting
  • Real-time security monitoring dashboard

Impact:

  • Reduced enterprise Agent security assessment time by 60%
  • Identified and helped remediate 200+ security vulnerabilities pre-launch
  • Established industry benchmark for Agent security evaluation

LLM Red Teaming Framework

Role: Technical Product Manager Status: Internal tool, deployed across teams

A systematic framework for red teaming LLM-based applications. Designed to be extensible, repeatable, and actionable.

Key features:

  • Automated attack scenario generation
  • Multi-turn conversation attack simulation
  • Vulnerability classification and severity scoring
  • Remediation recommendation engine

Impact:

  • Standardized security testing process across 5+ product teams
  • Discovered 30+ novel attack patterns in production Agents
  • Reduced security review cycle from weeks to days

AI Security Governance Framework

Role: Product Strategy Lead Status: Research & Standards

A comprehensive governance framework for enterprise AI deployment, covering security, privacy, compliance, and ethics.

Key components:

  • AI risk classification and assessment methodology
  • Security control requirements by risk level
  • Compliance mapping (ISO 27001, GDPR, etc.)
  • Continuous monitoring and improvement process

🏆 Certifications & Standards

Certification Area
AI Security & Governance Internal Enterprise AI Security Framework
Product Management End-to-end Product Lifecycle
Security Assessment OWASP / Threat Modeling
Data Protection ISO 27001 Compliance

📊 GitHub Stats

GitHub Stats Top Languages

passive-recon profile


📈 Contribution Graph

Activity Graph

Snake Contribution Grid


📈 Activity


📈 Contribution Graph

TrueFurina's GitHub Contribution Chart



📫 Connect


Pinned Loading

  1. AGI-Distiller AGI-Distiller Public

    Not just another skill collection. A living knowledge distillation system that self-evolves by reading technical content. 不只是 skill 集合,是一个能自我进化的知识蒸馏系统。

    2

  2. passive-recon passive-recon Public

    🕵️ Purely passive OSINT/EASM/CTEM platform — 15+ data sources, zero-touch asset discovery, risk detection

    Python 2

  3. pikachu pikachu Public

    PHP 2

  4. cyber-terms-hub cyber-terms-hub Public

    Cybersecurity terminology resource navigation - glossary, acronyms, frameworks, standards collection

    Python 2

  5. DevRadar-GitHub-Trending-Monitor DevRadar-GitHub-Trending-Monitor Public

    Python 2

  6. MangDeHenZhi MangDeHenZhi Public

    调整后的框架保留了原有的 “技术 - 团队 - 模式” 三维壁垒,更贴合学生项目的普适语境,且每个亮点都有 “具体动作 + 数据支撑 + 对标优势”,既符合创赛对 “创新性、可行性、系统性” 的核心要求,又能让评委快速记住 “这是一个用跨学科能力解决软技能痛点、且能落地的学生项目”。这套亮点完全可以作为核心标签,在 PPT、路演、计划书中反复强化。

    Java 2