About me
Aleksandr Churilov is an independent security researcher working on the safety of LLM-based systems, with a focus on the supply-chain and agent-security failure modes that appear as models move into real developer workflows. His recent work replicated and extended the measurement of LLM package hallucinations across the 2026 frontier-model cohort, quantifying the model-agnostic slopsquatting attack surface through coordinated disclosure with PyPI Security and Socket.dev. He also builds bulwark-mcp, an open-source local proxy that detects indirect prompt injection in tool results before they reach an AI agent.