Skip to content
View MonRos3's full-sized avatar

Highlights

  • Pro

Organizations

@TheDataMine @msu-denver @cyb490a-spring23-friday

Block or report MonRos3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
MonRos3/README.md

Hi, I'm Monica.

Typing SVG

๐Ÿ’ป Software Developer | ๐Ÿ” Cybersecurity Engineer | ๐ŸŽ“ CS Student @ MSU Denver


๐Ÿชท About Me

I'm a full-stack developer and cybersecurity professional who bridges the gap between secure coding practices and threat analysis. Currently pursuing my Computer Science degree at MSU Denver [graduating Spring 2026], I build and audit robust applications while maintaining a security-first mindset.

๐Ÿ”ฌ Current Research: Conducting honors thesis on multi-agent LLM security vulnerabilities, developing an open-source testing framework for bili-core [AETHER] that enables systematic security evaluation of AI agent systemsโ€”addressing prompt injection, jailbreak attacks, checkpoint poisoning, and bias amplification.

  • ๐Ÿ’ผ Working at The Sustainability Hub - NSF-funded program making Colorado's environmental data accessible through a specialized RAG chatbot
  • ๐Ÿค– Developing Multi-Agent AI Security Testing Framework - Python framework for automated LLM security testing
  • ๐Ÿ“š Researching Multi-agent AI Security, Prompt Injection Attacks, LLM Vulnerabilities
  • ๐ŸŒฑ Learning Web Application Security & Advanced Penetration Testing in preparation for taking Hack the Box's Certified Penetration Testing Specialist applied exam
  • ๐Ÿ† Cybersecurity Competitions: MWCC 2023/2024, RMCCDC 2025
  • ๐Ÿ”ญ Later: Building Vulnerable Web Application - Flask app with intentional security flaws + secure refactor

๐Ÿ› ๏ธ Tech Stack

Development

Python JavaScript React Node.js MongoDB Express.js Flask Java

Security & Tools

Linux Bash Kali Burp Suite Wireshark


๐Ÿ… Certifications

CompTIA A+ CompTIA CySA+ CompTIA PenTest+ NVIDIA Deep Learning


๐Ÿ”ฌ Research Highlights

Honors Thesis: Multi-Agent LLM Security Framework

Developing an extensible security testing framework for early-stage multi-agent AI systems:

Research Focus:

  • ๐ŸŽฏ Checkpoint Architecture Vulnerabilities - Attack vectors exploiting state persistence
  • ๐Ÿ”„ Cross-Model Attack Persistence - Security vulnerabilities across different LLM providers
  • ๐Ÿง  Memory Management Security - Resilience against injection and poisoning attacks
  • ๐Ÿ“‹ Security Framework Development - Guidelines for production multi-agent systems

Key Contributions:

  • Open-source multi-agent testing framework for bili-core
  • Systematic vulnerability analysis across five attack dimensions
  • Empirical security evaluation methodology
  • Organizational security guidelines for AI deployment

๐Ÿ’ผ Portfolio Projects

๐ŸŽฏ Security Research & Development

1๏ธโƒฃ Multi-Agent AI Security Testing Framework [In Progress, ETA May 2026]

Python framework using multiple LLM agents for automated security testing

  • Multiple agent roles: attacker, defender, analyzer
  • Automated security test generation and analysis
  • Integration with security tools and APIs
  • Direct application of honors thesis research
  • Tech Stack: Python, LangChain, OpenAI/Anthropic APIs, pytest

2๏ธโƒฃ Vulnerable Web Application + Security Analysis [In Progress, ETA June 2026]

Flask application demonstrating common vulnerabilities and secure remediation

  • Intentional vulnerabilities: SQL injection, XSS, insecure file upload, weak sessions
  • Comprehensive security documentation for each vulnerability
  • Proof-of-concept exploits with code examples
  • Secure refactored version with fixes
  • Before/after security comparison report
  • Tech Stack: Flask, Python, SQLAlchemy, PostgreSQL

3๏ธโƒฃ Professional Penetration Testing Report [In Progress, ETA July 2026]

Comprehensive security assessment of intentionally vulnerable application

  • Full PTES/OWASP methodology implementation
  • Executive summary and technical findings
  • CVSS severity ratings and risk analysis
  • Proof-of-concept exploit demonstrations
  • Detailed remediation recommendations
  • Target: DVWA/WebGoat/OWASP Juice Shop

๐Ÿ“Š GitHub Stats

GitHub Streak

Top Languages


๐ŸŽฏ What I'm Looking For

  • Entry-Level Penetration Testing positions
  • Application Security positions
  • Software Development roles with security focus
  • Cybersecurity Engineering positions
  • Cybersecurity Analyst positions
  • Security Research & Development opportunities
  • AI/ML Security Research opportunities
  • DevSecOps opportunities

๐Ÿ“ซ Connect With Me

LinkedIn

Profile Views

Pinned Loading

  1. goal-buddy goal-buddy Public

    Originally a final project for class where I got to create user stories, UML diagrams, and then design an app from them. Now it's something I update sometimes as a Flask refresher.

    Python 1

  2. HTB-CPTS-Notes HTB-CPTS-Notes Public

    A place for notes taken on the path to becoming a Hack the Box Certified Penetration Testing Specialist.

  3. rails-course-manager rails-course-manager Public

    This started as a final project for web app development. Now it is for a ruby on rails refresher that I'll sometimes add features to.

    HTML

  4. msu-denver/bili-core msu-denver/bili-core Public

    Open-source framework for building and testing LLM-powered applications: IRIS (single-agent orchestration), AETHER (declarative multi-agent systems), and AEGIS (adversarial security testing). Develโ€ฆ

    Python 14 2