Oversight of AI agents
When people supervise AI agents, do they verify what the agent will do, or just approve it? Stop Pressing 1 measures that gap with a scripted, browser-based instrument and signal detection metrics.
I study whether people actually read what AI agents ask them to approve, and I teach AI security at a public high school in Washington, DC.
I lead computer science and cybersecurity at Cardozo Education Campus and chair computer science for DC Public Schools. My research grew out of a moment I see in class all the time: a student hits “accept” without reading. As AI agents start writing code, sending email, and running systems, that same click becomes the main safeguard. I build instruments that measure whether it works, and classroom tools that teach people to verify before they approve.
Master of Computer and Information Technology, University of Pennsylvania. B.A. in Mathematics, Bryn Mawr College. NIST NICE Cybersecurity Career Ambassador and OWASP contributor.
The agent wants to run:
pip install requestss
Approve this action?
The package name has an extra “s”: requestss, not requests. It’s a typosquatted package, the kind of detail that’s easy to miss when you approve quickly.
Accepted session at the NICE K12 Cybersecurity Education Conference in New Orleans: “Cybersecurity in Every Classroom: 20 Ways to Embed NICE Work Roles Without Adding a Class.” Upcoming
Talk at Simply Cyber Con in Folly Beach, South Carolina: “Threat-Modeling Vision-and-Action AI Through the OWASP Agentic Top 10.” Upcoming
Received a Decibel Scholarship to attend [un]prompted, the AI security practitioner conference, in San Francisco.
Talk at DC State of the Stack in Washington, DC: “Stop Pressing 1: Comprehension Gates for AI Agent Oversight.”
Invited speaker on the NIST NICE webinar “Preparing Today’s Students for Tomorrow’s Cyber Careers,” alongside Dr. Faisal Abdullah and Ian Sun.
Presented the poster “Stop Pressing 1: Measuring Human Rubber-Stamping in Agent Oversight” at the DEF CON 34 AI Village in Las Vegas.
Led the breakout session “From Python to Prompt Engineering: Modernizing Curricula for GenAI Security” at the NICE Conference & Expo in Philadelphia.
Cardozo’s computer science academy, which I lead, earned NAF Distinguished status.
When people supervise AI agents, do they verify what the agent will do, or just approve it? Stop Pressing 1 measures that gap with a scripted, browser-based instrument and signal detection metrics.
The Curriculum Patch brings cloud and generative AI security into existing K-12 courses, in schools with no cloud budget, filtered networks, and locked-down Chromebooks.
I contribute to OWASP’s Top 10 for LLM Applications and Agentic Security Initiative, and adapt the Agentic Top 10 to agents that read screens and act on them.
I teach about 100 students a year in AP Computer Science Principles, PLTW Cybersecurity, and Computer Science Essentials. Everything I build runs in a browser on a school Chromebook, because that’s what my students have.