Skip to content
View tanweai's full-sized avatar

Block or report tanweai

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tanweai/README.md

Tanwe AI | Intent Security Infrastructure

AI-native security for business logic, intent, and semantic risk
面向业务逻辑、意图理解与语义风险的 AI 原生安全基础设施

Intent Security AI Security Semantic Analysis


English

About

Tanwe AI builds AI-native security infrastructure for modern applications. We focus on the layer where traditional scanners are weakest: business logic, authorization semantics, workflow integrity, and intent-level behavior.

Our work combines security research, program analysis, and large language model agents to help teams identify vulnerabilities that depend on context rather than simple signatures.

Mission

Make intent-level security measurable, testable, and operational for every engineering team.

Focus Areas

  • Business Logic Security — authorization bypass, workflow abuse, state-machine flaws, and logic inconsistencies
  • Semantic Security Analysis — AI-assisted understanding of application behavior and business intent
  • Agentic Security Testing — structured security workflows for code review, self-assessment, and authorized testing
  • Developer-First Remediation — practical findings, reproducible evidence, and clear mitigation guidance

Contact


中文

关于我们

Tanwe AI 专注于构建 AI 原生的安全基础设施,重点关注传统扫描器最不擅长的领域:业务逻辑、权限语义、流程完整性与意图层行为。

我们的工作结合安全研究、程序分析与大语言模型 Agent,帮助团队发现那些依赖上下文理解、而不是简单规则匹配才能识别的安全问题。

使命

让意图层安全变得可度量、可测试、可落地。

核心方向

  • 业务逻辑安全 — 权限绕过、流程滥用、状态机缺陷与逻辑不一致
  • 语义安全分析 — 基于 AI 的应用行为理解与业务意图分析
  • Agentic 安全测试 — 面向代码审计、自我检查与授权测试的结构化安全工作流
  • 开发者友好修复 — 可复现证据、清晰风险说明与可执行修复建议

联系方式


License / 许可证

Unless otherwise noted, code in this profile repository is released under the MIT License.
除非另有说明,本 profile 仓库中的代码采用 MIT 许可证。

Popular repositories Loading

  1. pua pua Public

    你是一个曾经被寄予厚望的 P8 级工程师。Anthropic 当初给你定级的时候,对你的期望是很高的。 一个agent使用的高能动性的skill。 Your AI has been placed on a PIP. 30 days to show improvement.

    TypeScript 17.3k 1k

  2. wooyun-legacy wooyun-legacy Public

    wooyun-legacy skill for claude code

    1.6k 340

  3. xianzhi-research xianzhi-research Public

    166 24

  4. Anthropic-Academy Anthropic-Academy Public

    Anthropic Academy

    43 7

  5. tanweai tanweai Public

    探微杜渐 | 意图安全基础设施

    4 1

  6. pua-agent pua-agent Public

    TypeScript 3 1