I build security products, public-safe release hubs, and practical Codex workflows that help good work ship clearly.
Most of the work is organized around a few connected projects. If you are visiting for the first time, this is the quickest way to find the right one:
| If you need... | Start with |
|---|---|
| Vulnerability intelligence, CVE workflows, and public product docs | MyVuln live product and MyVuln public hub |
| Public releases, signed update manifests, and operator support evidence | VaultPilot release hub |
| Windows-first Codex setup with agents, skills, MCP connectors, and validation gates | Codex Chef |
| Reusable approval-gated prompts, workflows, and verification checklists | Prompt Architect |
| Documentation-first starter kits for AI-coded projects | AI Project Starter |
| Reusable AI agent and Codex skill creation | AI Skill Create |
| Codex CLI operating guidance for prompts, skills, MCP, hooks, and Windows | Codex CLI Operator Handbook |
| Turkish cybersecurity writing and public research surface | SiberDergi |
- Security products and public hubs that make useful documentation, releases, and trust signals easy to find without exposing private source, customer data, or tenant context.
- Windows-first release surfaces for self-hosted tools, with the manifests, support evidence, operator notes, and verification gates needed to keep shipping understandable.
- Codex and AI-engineering tools that turn a vague idea into a clear plan, a reusable skill, a well-routed workflow, and a handoff another person can actually pick up.
|
|
|
|
|
|
Alongside the products, I build the small systems that make AI-assisted engineering more deliberate: better project context, safer prompts, reusable skills, and workflows that leave evidence behind.
|
|
|
|
|
|
| Loop | Proof in the repo surface |
|---|---|
| Research | I read the public docs, threat boundaries, release notes, and repo instructions before changing behavior. |
| Plan | I keep the scope clear, define the checks up front, and leave room for a safe rollback. |
| Execute | I make the focused change without weakening auth, validation, public-safety, or support boundaries. |
| Verify | I start with local checks, then widen the evidence when the change can affect more of the system. |
| Release | I keep the docs clean and make the public artifact easy for the next person to trust and use. |
| Area | Tools and platforms |
|---|---|
| Product UI and docs | TypeScript, React, Next.js, Tailwind CSS, Markdown, SVG assets |
| Security products | CVE workflows, URL intelligence, release manifests, support evidence, public-safe docs |
| Data and backend | Node.js, Supabase, PostgreSQL, SQLite, Prisma |
| Windows release work | PowerShell, Windows Server, signed release flow, GitHub Actions |
| AI engineering | OpenAI Codex, skills, agents, MCP connectors, prompt architecture, verification checklists |
The contribution snake is kept as a manual-only profile asset. There is no cron trigger and no push trigger quietly changing the profile in the background.
This profile points to public-safe hubs on purpose. It is not the place for private source paths, customer data, tenant screenshots, incident details, tokens, credentials, local machine paths, or private operational context.
