I build trustworthy AI systems and developer infrastructure. My work covers agent security, security automation, memory, evaluation, and practical developer tools.
My work sits at the intersection of AI engineering, cybersecurity, and developer experience. I care about systems that are useful in practice, observable when they fail, and honest about their limits.
- AI security: threat-aware agent workflows, tool-use boundaries, configuration scanning, and defensive automation.
- Agent infrastructure: memory, state, authorization, lifecycle behavior, and multi-agent coordination.
- Developer tools: CLIs, MCP servers, SDKs, fixtures, tests, and documentation that make complex systems easier to use.
- Practical AI systems: focused applications and demos that connect technical depth to a real workflow.
A reproducible engineering lab for evaluating agents operating against code, GitHub, APIs, and security tools.
The core trace is simple:
agent → identity/policy gate → tool action → audit trace → adversarial scenario → evaluation report
The lab will connect the projects below into one broader story: how to build AI-enabled systems that remain understandable and controllable under real operating conditions.
Status: foundation and local design in progress. Public launch follows a reproducible first trace and fresh verification.
A short checkup for people and small teams that use AI at work.
Focus: turn AI safety questions into plain-language decisions and three practical next steps. No account, no data upload, and no security jargon.
An inspection and security-scanning tool for MCP servers, agent client configurations, source files, and GitHub workflows.
Focus: detect risky tool behavior, configuration weaknesses, secrets, workflow issues, and other agent-environment hazards before they become runtime surprises.
An HTTP-native protocol and reference implementation for durable agent memory, lifecycle behavior, access control, storage, and SDK usage.
Focus: make agent state explicit, inspectable, and useful across sessions and collaborating agents.
Defensive security utilities exposed through an MCP server and CLI, including IOC handling, hashing, entropy checks, CIDR analysis, repository checks, and shell-command assessment.
Focus: give analysts and agents small, composable security actions with clear boundaries.
- Start with a concrete workflow and its failure modes.
- Build a small, runnable slice.
- Test normal paths, adversarial inputs, and operational limits.
- Document the evidence, trade-offs, and non-goals.
- Turn the result into a demo, case study, or developer-facing guide.
MCP is one implementation surface in my work, not the whole identity. I also explore agent memory, evaluation, security automation, workflow systems, and practical AI applications. The common thread is building AI-enabled software that people can inspect, operate, and trust.
- Portfolio: kielltampubolon.id
- Dev.to: @kielltampubolon
- LinkedIn: Kiell Tampubolon
- Medium: @kielltampubolon
I’m interested in collaborations around AI security, agent infrastructure, developer tooling, technical documentation, and code-backed demos.
This profile is being rebuilt around fewer, stronger public proofs. Repositories may be archived, made private, or re-scoped as their evidence and maintenance state become clearer.
Implementation first. Evidence over hype. Useful systems over noise.


