I’m Noah Potti. I’ve spent the last dozen years in offensive security, red teaming, and adversarial engineering. These days I work mostly on how to test and bring systemic improvements at scale across identity, system boundaries, and the security of AI systems and agents.
I’m a co-founder of Adversis and Puck. A lot of my work is simply around this: if this credential, identity, or endpoint is compromised, what can it actually reach and do?
I also build security tools and co-wrote The Effective Red Team, forthcoming from No Starch Press.
Nothing new here
Most of the serious compromises I have been a part of didn’t need a zero-day. Something already in the environment, a token, a service account, a browser extension, a forgotten permission, had more access than anyone remembered giving it. We noticed before the attackers or defenders.
So much of the work is finding the gap between what a system is supposed to be able to reach and do and what it can actually reach, and then closing it.
Agents are making this more interesting. The software holding the credential now also reads untrusted text and decides what to do with it. The desktop agent is the new browser, except we’re skipping thirty years of hardening and shipping it with prompt injection unresolved. Agents need broad latitude, but must be task-constrained.
Questions I’m thinking about now: whether constraining an agent’s output to a fixed grammar makes it safe to act on, how to grant access based on what a user asked for, and what happens once attackers and defenders both run fleets of agents.
The other problem is measurement. Security has little reliable evidence about which controls work. Papers that convinced me of that are on the resources page.
Tools
Give it a credential, or a pile of them from a scanner report, and it tells you whether each one is still live and what it can reach. Over a hundred credential types. Read-only by construction, with a guard test that fails if anyone adds a write path. Detection tells you a key is real; geiger tells you whether it’s dangerous.
Built with the Puck Security folks.
Audits a Tailscale network for the ACLs and settings that quietly hand out more access than anyone intended. Checks for 57 misconfigurations, and has a fix mode for when you want it to just deal with them.
Built at Adversis.
For people who
git clonefirst and ask questions later. Scans a repo, package, or install script for the signs it’s about to ruin your day, before you run it.Built at Adversis.
Lets an agent investigate endpoints over MCP, read-only, with a policy engine and an audit log in front of every command. Ask a question about your fleet in plain English and get a narrative answer with containment steps.
Built with Puck Security.
A Burp extension that finds the server actions a Next.js app is exposing, whether or not anyone meant to expose them.
Built at Adversis.
Writing
- Jan 2027 The Effective Red Team: Adversary Emulation Inside the Enterprise — No Starch Press With Trevin Edgeworth and Jordan Potti. Build a red team that turns successful attacks into better security. Early access ebook is out now; print in January 2027.
- Oct 2026 After Red Teaming: What an Adversarial Assurance Function Actually Buys YouRed teams prove assumptions wrong. Adversarial assurance is the harder work after: what had to be true for the path to work, prove the fix mattered, and reopen the question when the company changes.
- Sep 2026 Beyond the Security OrganizationA closed-loop operating model where security evidence changes the right layer of the system and gets revalidated, instead of becoming a ticket. Also as a PDF.
- Jun 2026 Which credential do you rotate first? at Puck SecurityWhy geiger exists: scanners find keys, then leave the question open. Is it live, what does it reach, and in what order do you rotate.
- May 2026 Five findings every AI pen test walks through at AdversisIndirect injection, markdown exfil, tool abuse, cross-tenant retrieval, OAuth scope sprawl. Individually medium; together, critical.
- May 2026 Securing Claude Code for teams at AdversisPermission rules aren’t controls. Managed settings, sandboxes, and the two playbooks that scale from ten engineers to a hundred.
- Apr 2026 A demonstration of indirect prompt injection at AdversisFour poisoned documents, a seeded inbox, and an attacker console. Reproducible with cutout.
Now
Fractional CISO for a handful of companies through Adversis. AI security assessments for a few more. Building Puck, which is mostly about answering “are we affected?” from the endpoints instead of from a meeting.
Email noah at this domain. Haikus get read first. Everything else gets read eventually.
Elsewhere
GitHub (@thesubtlety, and @noahpotti) · LinkedIn · Adversis · Puck Security