Zhuoran Tan

Zhuoran (Newt) Tan

If it’s right, time will catch up.

LLM Agent Security · Runtime Sandboxing · AI & Software Supply Chain Defense · Threat Detection R&D

I build security systems for the AI-agent era: runtime sandboxes, attack simulation frameworks, evaluation pipelines, and detection tools for LLM agents, MCP tool servers, CI/CD workflows, and open-source package ecosystems.

My work combines Python, Go, Rust, and Typescript engineering with security research in agentic AI, software supply chain attacks, runtime observability, and graph-based threat detection.

What I Build

  • Agentic AI security testing platforms for prompt injection, jailbreaks, tool misuse, multimodal attacks, and MCP server risks.
  • Runtime sandboxes and behavioral analysis tools for safely executing and monitoring untrusted packages, tools, and agent integrations.
  • Software and AI supply chain attack simulations covering package ecosystems, CI/CD compromise, Docker/ML pipelines, and tool-chain abuse.
  • Threat detection and attribution systems using logs, execution traces, dependency metadata, provenance graphs, and security telemetry.

Recent News

  • 2026-07 — 🎉 Our paper, “An Empirical Study of Observability Limits in Advanced Software Supply Chain Attacks,” (full paper coming soon) has been accepted to ACM CCS 2026! See you in The Hague, the Netherlands.
  • 2026-06 — !! Submitted my thesis: Runtime Observability and Security Analytics for Software Supply Chain Defense, marking a major milestone toward the completion of my degree.
  • 2026-06 - Accepted an offer from TryHackMe as an incoming Senior AI Security Content Engineer on a part-time basis, starting July 2026.
  • 2026-05 - !! Our co-authored paper, FedHera: Towards Drift-Resilient Federated Fine-tuning with Heterogeneous Resources, has been accepted as a regular paper at ICML 2026. Congrats to Xiao Ke!

Medium · GitHub · Google Scholar · LinkedIn · ResearchGate · Credly