Security researcher & builder focused on ProdSec/AppSec, with interests in NatSec, OSINT, and applied security systems.
mcp-pentest. MCP server for authorized pentest workflows: Nmap/Gobuster orchestration, context aggregation, AI-assisted triage, and reporting.
22vuln-scout. AI-powered whitebox penetration testing plugin for Claude Code. 9 languages, 22 skills, 7 autonomous agents. STRIDE threat modeling, OWASP 2025 coverage, polyglot monorepo support.
22blackbox-claude-plugin. Claude Code plugin for black-box and grey-box penetration testing on HackTheBox machines
4Kuzushi. Kuzushi — Agentic SAST scanner with AI triage
4SignalTrace. TypeScript
2pwn-claude-plugin. Claude Code plugin for binary exploitation (pwn) challenges on HackTheBox and CTFs
2zkdpop-go. Go framework for zero-knowledge login and sender-constrained access tokens. Implements interactive Schnorr ZK auth, short-lived JWTs bound to client DPoP keys (cnf.jkt), and ready-to-use middleware for DPoP + JWT verification. Includes reference auth server and demo API.
1VolatilityAI. AI-Powered Memory Forensics Companion for Volatility3 — auto-analysis + interactive investigation chat
1