About

Ibrahim El-Radi.

I build things with AI agents, then I try to break them.

I have spent 14 years in security. Detection engineering, incident response, network defense, cloud, and offensive work. Most of it in places where a mistake costs something real, so I got used to asking a plain question about every system I met: does this actually hold, or does it only look like it does.

In 2020 I started Beit Systems, a B2B engineering firm. Since June 2025 I have been at Microsoft as an AI agent developer and principal security engineer, the only agent builder on a 30-person security engineering team. I built and run the internal agent development platform there, security-first by default.

Ibrahim Builds is the public side of that work. I build real things with AI agents, and I test how well they actually hold up.

What this channel is

Evaluating and stress-testing AI agents.

Most agent demos are shown working once. That is the easy run. The interesting part is the tenth run, the run with bad input, and the run where somebody is actively trying to break it.

So that is what I make here. Whole builds from start to finish, not a prompt and a screenshot. Then I check the things that decide whether a tool was actually worth using: is the output accurate, does the thing it built work when you run it, and where does it fail quietly instead of loudly. Quiet failure is the expensive kind, because nobody notices until it is already in production.

The failures stay in. A build that went wrong and got fixed teaches more than one that worked first time, and it is a more honest picture of what using these tools is really like.

The security side is the same question with sharper edges. Prompt injection, tool use and sandbox escape, the trust boundaries between the operator, the agent, its tools, and whatever text arrives from the outside world. Whether there is a kill switch a human can actually reach while the agent is still running.

Fourteen years in security pays for that instinct, and my day job is building AI agents and securing them at scale. This is not a work account, though. What goes out here is what I build on my own time, the tools I am testing, and what I learn when they break. Zoro is the same question turned into a product: proving whether an agent's controls actually held, with independent evidence rather than the agent's own account of what it did.

Teaching

Sunday mornings, for a cohort of career changers.

From December 2023 to March 2024 I taught a live introductory cloud and cybersecurity class, weekly on Sunday mornings, for about three months. Sessions ran two and a half hours or more.

The students were career changers, taught as a cohort. We covered AWS fundamentals with hands-on labs, some Azure including Azure Kubernetes Service, and a real amount of career coaching: resumes, LinkedIn profiles, and how to actually apply for roles.

Teaching beginners is where I learned to explain this work without jargon. If you cannot say it plainly to someone on a Sunday morning who is changing careers and has a full week behind them, you do not understand it well enough yet. That is why the starter kits on this site are free, and why they are written for someone who has never opened a terminal.

See the free kits

The record

The rest of it.

The full career history, the roles, and the education are on LinkedIn.

Certifications: CISM, PMP, Azure Solutions Architect Expert, Azure Administrator Associate, PSM-I, CEH, Security+, Network+, CCSKv4.

Work with Beit Systems