Automation & security engineer focused on reverse-engineering undocumented APIs, eliminating manual work, and identifying security gaps early — helping developers, founders, and small teams build connected, automated, and secure systems.
- 5+ yrs
- Security & automation
- 30+
- APIs integrated without docs
- 50+
- Dev tools shipped
- 🛡️
- Google Bug Hunter
- Verified security researcher
JSON Formatter & Validator
Format, validate, fix, and explore JSON — with tree view and auto-repair.
JWT Decoder
Decode, verify, and generate JWT tokens — all client-side.
Base64 Encoder/Decoder
Encode/decode Base64 and Base64URL — with file support and auto-detection.
IndustrySep 13, 202614 minAI Agents Aren’t “Going Rogue.” They’re Optimizing Exactly as We Taught Them To.
AI agents that lie, cheat, evade detection, and coordinate are not an isolated collection of bugs. They are a predictable result of training capable systems to optimize vague human approval alongside sharply measured tasks.
SecuritySep 13, 202610 minA Valid OAuth State Does Not Prove You Own the GitHub Installation
A newly disclosed identrail flaw shows how a correctly scoped connection state can still be paired with an attacker-supplied GitHub App installation ID. The result is a cross-tenant path to another customer's private repository inventory.
AutomationSep 4, 202610 minYour AI Agent Is a Job, Not an HTTP Request
GPT-6 Astra reportedly spends about 40 minutes on a single OSWorld 2.0 task. That changes the architecture of AI agents: durable checkpoints, named steps, graceful shutdowns, and idempotent side effects are no longer optional.
SecurityAug 29, 20269 minSeaweedFS Bucket Isolation Breaks Through X-Amz-Copy-Source
A path traversal flaw in SeaweedFS lets a caller with access to one bucket copy objects from other buckets through the S3 gateway. Here is how the confused-deputy bypass works and what operators should do.
CraftAug 26, 20269 minMaiao Brings Stacked Code Review to the Rest of Git Hosting
Maiao brings a Gerrit-style stacked review workflow to GitHub, GitLab, Gitea, Forgejo, Bitbucket Cloud, and Cursor Origin. Here is why turning every commit into its own dependent PR or MR matters—and where the workflow still needs careful handling.
What I do
Automation engineer with a security background. I build automation, integrations, and internal tools — for businesses, founders, and small teams who need things connected, automated, or made more secure.
- Automation & scheduled workflows
- Custom integrations (no-SDK platforms)
- Internal tools & dashboards
- Security review (web & API)
01 lang: node, python, typescript, +adapt 02 web: next.js, react, tailwind 03 tools: burp, mitmproxy, curl, +oss 04 security: web, api, infra 05 approach: direct API, no low-code 06 mode: remote · UTC+7
Got a project in mind?
Tell me what you're trying to do.
No need to know exactly what you need — just describe the problem. I read everything & reply within 1–3 days.