Skip to content
View andyyaro's full-sized avatar

Block or report andyyaro

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
andyyaro/README.md

Andy Yaro

Cybersecurity Engineering @ George Mason University · B.S. Dec 2028 · Minor in Data Science AWS Certified Security - Specialty · studying AWS DevOps Engineer - Professional

I build systems that assume something will go wrong, and write the tests that prove what happens when it does. Most of what is here is infrastructure for AI coding agents and cloud security work on AWS. Lately I spend my competition time on the other side of that: red-teaming AI agents.


Start here

Project What it is Scale
provalume · PyPI Evidence-based memory for AI coding agents. Only trusts what was proved: a check that passed, a reviewer who was not the author, a commit that actually landed. Append-only hash-chained journal, deterministic rebuild, five-rung trust ladder. 26k LOC · 566 tests (161 security) · 26-threat model · 18 ADRs
orkestra · PyPI Runtime that coordinates many coding agents (Claude Code, Codex CLI, Antigravity) on one repo. Each task in its own Git worktree, your tests are the referee, and nothing lands until a different agent has reviewed it. 16k LOC · 557 tests · 17 releases · 15-threat model
Secure Data Hub Multi-account AWS architecture for client PII. Cross-account STS, KMS item-level encryption, tenant identity taken from a validated JWT claim rather than the caller. 9-account design · 4 least-privilege IAM policies · 31-slide architecture deck
tableau-public-authoring-mcp MCP server that compiles a declarative spec into Tableau workbooks and validates them against the real desktop app. 17k LOC · 419 tests, more test code than source
local-ai-orchestrator Seven-agent local LLM pipeline with a deterministic validation layer that overrides model self-assessment. Runs offline, no paid APIs. 11k LOC · 215 tests
AGA_Datathon_2026 🥇 1st place, National AGA Datathon. I built the public site and the methodology appendix that made federal spending and audit data legible to ordinary citizens. 8 pages · 29 appendix documents

What I actually work on

Cloud security on AWS. IAM across trust boundaries, cross-account sts:AssumeRole, KMS customer-managed keys, Cognito and OIDC, API Gateway, Lambda, CloudTrail, GuardDuty, DNSSEC. Multi-account organisations rather than one account with everything in it. Smaller AWS builds too: a serverless profile-photo checker on Lambda + Rekognition, 14 Terraform resources.

AI agent security. The reason the projects above are built the way they are. I red-team tool-using AI agents in adversarial competitions: prompt injection, tool-call boundary abuse, and where an agent's guardrails actually hold versus where its own helpful behaviour leaks. Building agent infrastructure and attacking it turns out to be the same skill from two directions.

Security engineering as a habit. Five threat models across projects that did not require one. I have fixed ReDoS vulnerabilities CodeQL found in my own code, hardened FTS5 query construction against injection, and proved a "no network calls" guarantee by AST-walking every module rather than asserting it in the README.

Testing and verification. 2,000+ test functions written. One project ships a 41-gate verification harness that CI and local runs invoke identically, so the two cannot disagree about what "passing" means.

Infrastructure as Code. Terraform, GitHub Actions, hash-pinned dependencies, and PyPI publishing through OIDC trusted publishing rather than long-lived tokens.


Tools

Python Terraform Docker AWS Linux SQLite GitHub Actions pytest mypy Ruff Bandit CodeQL MCP JSON-RPC MATLAB JavaScript


📍 Arlington, VA · 💼 LinkedIn · ✉️ yyaro@gmu.edu

Pinned Loading

  1. Building-A-Secure-Data-Hub-in-the-cloud-AWS- Building-A-Secure-Data-Hub-in-the-cloud-AWS- Public

    Multi-account AWS architecture for sensitive client data: cross-account STS, KMS item-level encryption, Cognito-authorized APIs, and least-privilege IAM across a trust boundary.

    Python

  2. local-ai-orchestrator local-ai-orchestrator Public

    A local-first multi-agent AI orchestrator with routing, validators, resilience, metrics, retrieval/research scaffolding, coding-agent tools, and release gates.

    Python 1

  3. orkestra orkestra Public

    Local-first orchestration runtime for multiple autonomous coding agents (Claude Code, Codex CLI, Antigravity CLI, and more). A dynamic director plans, a deterministic kernel enforces.

    Python 7 1

  4. tableau-public-authoring-mcp tableau-public-authoring-mcp Public

    MCP server that authors Tableau workbooks from a declarative spec, validates them by opening them in Tableau Public, and publishes through the desktop workflow.

    Python 1

  5. AGA_Datathon_2026 AGA_Datathon_2026 Public

    Forked from fiscalpatriots/AGA_Datathon_2026

    A public-facing educational platform helping citizens explore federal financial assistance alongside audit oversight signals.

    HTML

  6. provalume provalume Public

    Verified, git-aware memory for autonomous software agents. Tracks what worked, what failed, what is currently true, and the evidence that proved it.

    Python