Thomas NJ Shadwell
selected experience
Built out OpenAI's first Secure Development Lifecycle (SDLC); security for OAI products including ChatGPT Canvas (ChatGPT Apps, MCP Apps & Code Blocks), OpenAI Atlas, ChatGPT Lockdown Mode, Sign In With ChatGPT, ChatGPT Finance, GPT-4o, GPT5, Apple Intelligence and others. Work on Prompt Injection, Agentic Security & AI cyber risk.
Automated security mitigation, detection and refactoring using compiler technology (“langsec”), SDKs and DSLs (“hardening”) on TypeScript and Java. Google-wide mitigations for Log4Shell, XSS, deserialization attacks. Product security review and design, Google Ads (“FLOC”, “FLEDGE”), Google Cloud, Google's IDE (“Cider”). Research including critical disclosures such as CVE-2022-41034.
advisory position. Provided expertise to UK cyber advisory / defence group on Go and building security analysis systems. Launched world's first government-wide responsible disclosure program.
first security engineer at the video game streaming website. Designed security architecture for flagship projects including bits, the Twitch API, extensions and Twitch's OIDC / OAuth AuthN/Z systems. Created and defined security relationships and processes. Built Go security static analysis system, security frameworks and libraries
Full stack freelance work building MVPs for London startups and wrangling data for hackathons.
Charity focused on teaching code literacy. Ran and participated in hackathons for good causes. Taught software engineering to young people.
selected highlights
Security for OpenAI's next-generation model.
Bypassing cutting-edge web security techniques to hack Apple ID.
AI enabled web-browser.
The highest award given by the world's largest hacker convention. Awarded for the HackFortress CTF.
Blog post on how prompt injection attacks are becoming more like social engineering and how we can design AI agents to be more resistant to them.
Paper describing the mechanism OpenAI products such as ChatGPT use to detect when an AI is communicating non-public data.
Technical talk at offensive AppSec conference summarising through example research into hybrid web / desktop application security
Google research; exploit to remotely take over VSCode and any attached cloud systems. CVE-2022-41034, GHSA-pw56-c55x-cm9m