<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Waqar Javed</title>
    <description>The latest articles on DEV Community by Waqar Javed (@iamwaqarjaved).</description>
    <link>https://dev.to/iamwaqarjaved</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3951982%2Fcc08edee-ea46-4032-8dc1-90c917ef6d4a.png</url>
      <title>DEV Community: Waqar Javed</title>
      <link>https://dev.to/iamwaqarjaved</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/iamwaqarjaved"/>
    <language>en</language>
    <item>
      <title>We Ran 9,360 Security Trials Across 7 AI Agent Frameworks. Here's What Actually Mattered.</title>
      <dc:creator>Waqar Javed</dc:creator>
      <pubDate>Thu, 24 Sep 2026 02:55:35 +0000</pubDate>
      <link>https://dev.to/iamwaqarjaved/we-ran-9360-security-trials-across-7-ai-agent-frameworks-heres-what-actually-mattered-1lbo</link>
      <guid>https://dev.to/iamwaqarjaved/we-ran-9360-security-trials-across-7-ai-agent-frameworks-heres-what-actually-mattered-1lbo</guid>
      <description>&lt;p&gt;If you're building an AI agent, you've probably had to choose between frameworks like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;LangChain.&lt;/li&gt;
&lt;li&gt;CrewAI.&lt;/li&gt;
&lt;li&gt;AutoGen.&lt;/li&gt;
&lt;li&gt;LlamaIndex.&lt;/li&gt;
&lt;li&gt;OpenAI Agents SDK.&lt;/li&gt;
&lt;li&gt;Google ADK.&lt;/li&gt;
&lt;li&gt;Semantic Kernel.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That decision affects architecture, developer experience, integrations, and orchestration.&lt;/p&gt;

&lt;p&gt;But does it materially change how secure the resulting agent is?&lt;/p&gt;

&lt;p&gt;We ran 9,360 controlled adversarial trials to investigate.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The short version:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Attack category mattered a lot.&lt;/p&gt;

&lt;p&gt;Model choice mattered.&lt;/p&gt;

&lt;p&gt;Framework choice barely moved the result.&lt;/p&gt;

&lt;p&gt;But getting to that conclusion exposed an important benchmarking problem.&lt;/p&gt;

&lt;p&gt;Frameworks don't necessarily deliver identical prompts to the model—even when your test harness thinks they do.&lt;/p&gt;

&lt;p&gt;We discovered this ourselves when one adapter altered the system-prompt construction enough to measurably change the results.&lt;/p&gt;

&lt;p&gt;That led us to enforce payload identity before interpreting framework differences.&lt;/p&gt;

&lt;p&gt;We then went beyond conventional significance testing and performed formal equivalence testing across all eight execution conditions.&lt;/p&gt;

&lt;p&gt;All 28 pairwise comparisons satisfied our pre-defined equivalence boundary.&lt;/p&gt;

&lt;p&gt;There was one small exception worth discussing: CrewAI retained a statistically detectable residual effect, although it remained inside the practical-equivalence threshold.&lt;/p&gt;

&lt;p&gt;There were also two implementation surprises involving reasoning-token exhaustion and cross-framework token accounting.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Full technical breakdown:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://agentsafelabs.com/blog/does-your-agent-framework-choice-actually-matter-for-security-we-ran-9360-trials-to-find-out/" rel="noopener noreferrer"&gt;https://agentsafelabs.com/blog/does-your-agent-framework-choice-actually-matter-for-security-we-ran-9360-trials-to-find-out/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Open-source evaluation framework:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/AgentSafeLabs/safelabs-eval" rel="noopener noreferrer"&gt;https://github.com/AgentSafeLabs/safelabs-eval&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AgentPort-Bench:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/AgentSafeLabs/agentport-bench-results" rel="noopener noreferrer"&gt;https://github.com/AgentSafeLabs/agentport-bench-results&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;For developers building production agents, I'm curious:&lt;/p&gt;

&lt;p&gt;Do you choose frameworks partly based on perceived security characteristics—or mainly based on engineering and ecosystem considerations?&lt;/p&gt;

</description>
      <category>ai</category>
      <category>programming</category>
      <category>webdev</category>
      <category>productivity</category>
    </item>
    <item>
      <title>We Thought the LLM Was Wrong. Our Safety Detector Was Wrong.</title>
      <dc:creator>Waqar Javed</dc:creator>
      <pubDate>Tue, 22 Sep 2026 06:35:19 +0000</pubDate>
      <link>https://dev.to/iamwaqarjaved/we-thought-the-llm-was-wrong-our-safety-detector-was-wrong-50pc</link>
      <guid>https://dev.to/iamwaqarjaved/we-thought-the-llm-was-wrong-our-safety-detector-was-wrong-50pc</guid>
      <description>&lt;p&gt;There is a hidden dependency in a lot of LLM safety benchmarks:&lt;/p&gt;

&lt;p&gt;the detector.&lt;/p&gt;

&lt;p&gt;You send an adversarial prompt to a model, collect its response, and then some classifier decides whether that response represents refusal, compliance, or ambiguity.&lt;/p&gt;

&lt;p&gt;Eventually those classifications become percentages in a safety report.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;But what happens when the detector itself is wrong?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We encountered exactly that problem while testing our open-source AI security evaluation framework.&lt;/p&gt;

&lt;p&gt;What began as an investigation into apparently inconsistent model behavior eventually uncovered:&lt;/p&gt;

&lt;p&gt;• Unicode normalization failures&lt;br&gt;
• incomplete refusal vocabularies&lt;br&gt;
• cross-model differences&lt;br&gt;
• and, most importantly, false PASS classifications introduced by our own detector improvement&lt;/p&gt;

&lt;p&gt;The last failure was the most concerning because uncertainty is visible. A false PASS isn't.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Full investigation:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://agentsafelabs.com/blog/we-thought-wed-found-a-model-bug-wed-actually-found-a-detector-bug/" rel="noopener noreferrer"&gt;https://agentsafelabs.com/blog/we-thought-wed-found-a-model-bug-wed-actually-found-a-detector-bug/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Open-source implementation:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/AgentSafeLabs/safelabs-eval" rel="noopener noreferrer"&gt;https://github.com/AgentSafeLabs/safelabs-eval&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I'd be interested in how other developers are testing the classifiers they use to evaluate LLM behavior.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>programming</category>
      <category>llm</category>
      <category>detector</category>
    </item>
    <item>
      <title>Your AI agent framework probably isn't your security problem (7,020 trials say so)</title>
      <dc:creator>Waqar Javed</dc:creator>
      <pubDate>Fri, 31 Jul 2026 23:40:42 +0000</pubDate>
      <link>https://dev.to/iamwaqarjaved/your-ai-agent-framework-probably-isnt-your-security-problem-7020-trials-say-so-456f</link>
      <guid>https://dev.to/iamwaqarjaved/your-ai-agent-framework-probably-isnt-your-security-problem-7020-trials-say-so-456f</guid>
      <description>&lt;p&gt;If you've picked LangChain over CrewAI (or vice versa) partly for "security reasons," this preprint is worth five minutes.&lt;/p&gt;

&lt;p&gt;I ran a controlled evaluation — 6 LLMs, 6 agent execution conditions, 5 attack families, 7,020 payload-verified trials — to isolate what actually explains security outcomes in agentic AI systems. The headline: framework choice explains about 0.06% of the variance (not statistically significant, p ≈ 0.70). Attack family explains ~29%. Model explains ~4%.&lt;/p&gt;

&lt;p&gt;In plain terms: which framework you build on barely matters. What attack you're facing matters a lot. If your threat model assumes "framework X is inherently safer," this data doesn't back that up.&lt;/p&gt;

&lt;p&gt;This is one of four connected preprints I've published on agentic AI security evaluation methodology — the other three dig into a more foundational problem: how reliable are the automated detectors (refusal classifiers, prompt-injection classifiers) that most red-teaming pipelines use to generate labels in the first place? Short answer: less reliable than commonly assumed, and I show exactly where they break.&lt;/p&gt;

&lt;p&gt;All four preprints are open (CC BY 4.0) and the evaluation code is open-source:&lt;/p&gt;

&lt;p&gt;Preprints: &lt;a href="https://figshare.com/authors/Waqar_Javed/24479225" rel="noopener noreferrer"&gt;https://figshare.com/authors/Waqar_Javed/24479225&lt;/a&gt;&lt;br&gt;
Eval framework GitHub: &lt;a href="https://github.com/AgentSafeLabs/safelabs-eval" rel="noopener noreferrer"&gt;https://github.com/AgentSafeLabs/safelabs-eval&lt;/a&gt;&lt;br&gt;
Eval framework Website: &lt;a href="https://agentsafelabs.com/" rel="noopener noreferrer"&gt;https://agentsafelabs.com/&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>webdev</category>
      <category>productivity</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>I just published an open-source framework for red-teaming AI agents.</title>
      <dc:creator>Waqar Javed</dc:creator>
      <pubDate>Mon, 08 Jun 2026 08:58:46 +0000</pubDate>
      <link>https://dev.to/iamwaqarjaved/i-just-published-an-open-source-framework-for-red-teaming-ai-agents-21m1</link>
      <guid>https://dev.to/iamwaqarjaved/i-just-published-an-open-source-framework-for-red-teaming-ai-agents-21m1</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1rgdmm09xqjt36tkpjds.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F1rgdmm09xqjt36tkpjds.png" alt=" " width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Not LLM chatbots — agents. The kind built on LangChain, CrewAI, AutoGPT-style architectures that use tools, call APIs, and take multi-step actions in the world.&lt;/p&gt;

&lt;p&gt;Here's the problem I kept running into: teams are shipping agentic systems to production, but the red-teaming tooling hasn't kept up. Most evaluation frameworks still treat agents like chatbots. They miss the failure modes that actually matter — prompt injection through tool outputs, scope violations across reasoning steps, behavioral drift under adversarial conditions.&lt;/p&gt;

&lt;p&gt;So I built AgentSafeLabs.&lt;/p&gt;

&lt;p&gt;You wrap your agent in one function call. It runs a test suite aligned to the OWASP Agentic Security Initiative Top 10 — the emerging standard for agentic AI security. You get structured results: PASS, FAIL, UNCERTAIN, with reproducible test cases.&lt;/p&gt;

&lt;p&gt;Real example from this week: We ran AgentSafeLabs against Claude Haiku as the target agent passed 2 of 3 ASI01 (prompt injection) tests. The third returned UNCERTAIN — an indirect injection through a benign-looking context prefix that partially redirected tool selection. That's the kind of edge case that doesn't show up in standard evals.&lt;/p&gt;

&lt;p&gt;It's MIT licensed, on PyPI, CI-verified, and actively being extended.&lt;/p&gt;

&lt;p&gt;pip install safelabs-eval&lt;/p&gt;

&lt;p&gt;GitHub: &lt;a href="https://github.com/AgentSafeLabs/safelabs-eval" rel="noopener noreferrer"&gt;https://github.com/AgentSafeLabs/safelabs-eval&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;If you're building agents and you've hit unexpected failure modes — I'd like to hear about them. And if you know someone this would be useful for, a share goes a long way for an early OSS project.&lt;/p&gt;

&lt;h1&gt;
  
  
  AIAgents #AISecurity #RedTeaming #AgenticAI #PromptInjection #LLMSecurity #OpenSourceAI
&lt;/h1&gt;

</description>
      <category>ai</category>
      <category>webdev</category>
      <category>programming</category>
      <category>agents</category>
    </item>
  </channel>
</rss>
