Warren Smith
Principal Engineer and independent researcher in the UK. AI agent security and authorization, evaluation reliability, formal verification, and the engineering behind them.
warrensmith8@ymail.com · github.com/repowazdogz-droid · omegaprotocol.org
Experience
WRKS Holdings Ltd, Bristol · Principal Engineer · 2024–present
- Eight applications on one shared Python engine, owned from the engine through React frontends to a packaged desktop build and the deploy.
- A governed runtime for decision records: cryptographic record hashing over an append-only trail, so a record can be shown intact and reconstructed by someone who was not present when it was written.
- On a shipped clinical product: removed a client-inlined model API key, routed the browser through a same-origin server-side proxy, capped request bodies, and put both model-output paths behind one guarded send with a prebuild script that fails the build if the chokepoint is bypassed.
Clickout Media · Head of Data, Sports PR · August 2024 – January 2026
- Analytics and forecasting behind operational decisions under uncertainty, including stress and reverse-stress scenarios.
Block Labs · Head of Finance · 2022–2024
- Forecasting and stress testing through acute crypto-market volatility.
Deloitte, Propel · Internal Finance · 2019–2022
- Propel was Deloitte's outsourced accounting and business-services firm for SMEs, covering bookkeeping, accounts, year-end accounting and wider finance and business support.
- Worked in Propel's own finance function, on its internal financial operations rather than on client delivery.
Independent research and engineering
Alongside the roles above, self-directed AI research and engineering since 2023: experiments and tooling that later became the public work on this site. This was not a research appointment and carried no institutional affiliation. The artifacts here, and the findings resting on them, date from 2026.
Selected technical work
Each item is published on this site with its claim, its grade, its sample and its limits. The grade says how far the evidence reaches, not how important the result is.
- Agent authorization and confinement
- mcp-authority-boundary: a Cedar-enforced tool boundary over six tools and 25 adversarial scenarios, separating mediation, binding, policy adequacy and effect verification. A write of 100,000 bytes executed under a 4,096-byte policy while 66 of 66 tests passed and an independent replay verifier returned VERIFIED. capctl-iris: a machine-checked bound in Rocq and Iris showing a shared capability meter never exceeds its cap over every concurrent interleaving.
- Enforcement position and safeguards evidence
- safeguards-control-plane: across 10,000 injected events, a monitoring arm recorded 1,026 actions as prevented and all 1,026 executed, against 6 of 9,880 for an in-series arm consuming identical events.
- Evaluation reliability
- evaltrust: a pre-registered study over 600 items and 171 judge pairs. Judge errors correlated positively in 171 of 171 pairs at mean phi 0.567, and the correlation between agreement and accuracy fell from 0.824 to 0.077 once the algebraically forced component was removed. inspect-audit and inspect-replay: read-only validity auditing and deterministic comparison of evaluation logs.
- Formal verification
- Machine-checked results in Lean 4, Rocq and Iris, TLA+ and Z3: escrow-budget (a budget bound over all reachable states), compositional-temporal-safety, escrow-budget-mpst and vsf-cjson (kernel-checked theorems about a C JSON parser). Axiom audits are published with the results.
- Protocol boundary and integrity
- mcp-boundary-audit: detects tools hidden from a discovery listing yet reachable through the call surface, the class catalogued as CVE-2026-46519. nanogpt-provenance and OMEGA: re-derivation and tamper-evidence for recorded runs and decisions.
Contributions to other projects
Status is stated exactly. Full detail on Contributions.
- UKGovernmentBEIS/inspect_ai, issue 4602. A finished evaluation reported a different number of completed samples depending only on scorer declaration order. Reported 23 July 2026, fixed upstream 29 July 2026. The fix, pull request 4604, was written and merged by the maintainers.
- cedar-policy/cedar-spec, pull request 995. A differential random testing target comparing the typed expression from the Rust typechecker against the Lean formalisation. Open, in review.
- pulp-platform/common_cells, pull request 355. A SymbiYosys proof for the error-correcting-code encode and decode cells. Open.
- strata-org/Strata and Strata-CLI, three pull requests on goal classification and verification-goal counting. Open.
Writing and policy
- Per-Agent Compliant, Collectively Unsafe. AMLUCS 2026: poster and presentation accepted; presenting poster, September 2026.
- Decision Surface of Agent Firewalls, with Arnab Kumar Biswas (QUB/CSIT). Under review at AGENT-SEC 2026, a CCS workshop.
- techUK's response to Ofgem's AI assurance consultation, July 2026: four contributions under my name in the tracked-changes record.
- Technical notes on this site, including the pre-registration and deviation record and the citation verification record: Writing.
Tools
Python FastAPI, Pydantic, pytest, numpy, pandas, scikit-learn, PyTorch. Agents and evaluation Model Context Protocol server and broker design, Cedar policy, Inspect with custom tasks, scorers and metrics, AgentDojo, self-hosted open-weight models. Verification Lean 4, Rocq and Iris, TLA+ and TLC, Z3, Hypothesis, cargo-fuzz, SymbiYosys. Also TypeScript, Rust, SQL, GCP, OpenTofu, Docker.
Education and qualifications
- CIMA Advanced Diploma in Management Accounting, regulated at Ofqual RQF Level 7, the same framework level as a Master's degree (learning aim 00267042). A professional qualification at Master's level, not a taught Master's degree.
- Chartered management accountant (CIMA), admitted 2023.
- BA Business Management, Cardiff University.