
Or Raz
156 posts

Or Raz
@OrRaz6
LLM security enthusiast. Learning, sharing, and helping others understand the complexities. Join me on this journey.


LLM based agents are growing in popularity, and I often wonder how many people are aware of the risks in enabling LLMs to use tools. While playing with LlamaIndex agents, I came across an example notebook for an OpenAPI + Requests based agent which is vulnerable to SSRF.


Exciting changes coming from @langchain on the security front. There is a new announcement that any component that has vulnerabilities (SQL & python agents for example) will be moved from the package core into an experimental package github.com/hwchase17/lang…




Are data poisoning attacks practical? tl;dr: yes - podcast with ETHZ prof on work w. Robust, Google, NVIDIA mlsecops.com/podcast/tramer…










