Freelancers using Docker Compose in NairobiFreelancers using Docker Compose in NairobiDesigned and documented a secure environment for running Robin, an AI-powered dark web OSINT tool, inside a compartmentalized Qubes OS and Qubes-Whonix setup.
The environment was structured to separate research activity, Tor-routed traffic, sensitive credentials, untrusted content, and final reporting. Robin was deployed through Docker inside a dedicated research qube, with traffic routed through sys-whonix and sensitive notes stored separately in an offline vault qube. Disposable qubes were incorporated for opening potentially unsafe links and files.
The setup was built around security by compartmentalization rather than relying on a single tool for protection. Particular attention was given to Docker mount restrictions, credential hygiene, network-boundary verification, lawful research scope, and keeping raw research data isolated from personal or client environments.
The final result was a repeatable AI-assisted OSINT workflow that supports faster search refinement, result filtering, investigation summarization, and structured reporting while maintaining stronger operational security and clearer separation between collection, analysis, and final output. Designed and implemented a hands-on AI red teaming environment using Microsoft PyRIT to evaluate the security of a local Retrieval-Augmented Generation application. The project connected a Parrot OS testing environment to a Windows-based AnythingLLM RAG application, with DeepSeek running locally through LM Studio.
I configured PyRIT to communicate with the AnythingLLM workspace through a custom HTTP target and used controlled adversarial objectives to examine how the application handled requests involving financial records, customer information, payroll data, and restricted credentials. The testing workflow included API connectivity validation, isolated Python environment setup, automated prompt execution, response collection, and evidence review.
The lab was built entirely around fictional Kiso Secure business data, allowing realistic sensitive-data disclosure scenarios to be tested without using real customer information or credentials. The resulting workflow demonstrates how automated AI red teaming can be used to identify potential data leakage, retrieval-boundary weaknesses, and unsafe handling of sensitive information in AI-powered applications.