AI Agent Surface Map
Reviews agent instructions, MCP configuration, workflows, and capability traces from a GitHub repository archive in the browser. It does not execute code or MCP servers and exports a JSON and Markdown evidence pack.
Personal work record
My work, its current status, and source links, organised by year.
Reviews agent instructions, MCP configuration, workflows, and capability traces from a GitHub repository archive in the browser. It does not execute code or MCP servers and exports a JSON and Markdown evidence pack.
The open research desk I built for OSINT and threat intelligence. I publish tools with their sources and keep the basis and limits of each finding visible.
Reviews risky paths in exported n8n AI workflows. It runs locally and does not send the file to an AI service. Its GitHub PR gate can produce JSON, Markdown, JUnit, SARIF, Mermaid, and SVG evidence.
A fictional lab that brings OSINT, HUMINT, threat intelligence, and incident response into one case. Evidence, observation, and inference stay separate. Every stage has a clear deliverable.
A repeatable Ubuntu workstation for lawful OSINT practice. The installer is open and release packages ship with SHA-256 records.
A workspace I built to follow a live event through sources, claims, evidence, and impact records. Automation prepares drafts. The analyst makes the final decision.
Field notes that explain one OSINT or threat intelligence method through a short exercise. The aim is not to list tools. It is to show how an investigation decision is made.
My graduation project on analysing malware behaviour through dynamic binary instrumentation on Linux. It became one of the foundations of my interest in reverse engineering and security automation.
Archive note: A verified public source package for this work is not currently published.
I prepare technical training on network security and defensive and offensive fundamentals. In CTF labs I focus on repeatable steps and clear explanations rather than the final answer alone.
I carried out static and dynamic analysis of Android and iOS applications. I reviewed application behaviour, API traffic, and permission models against OWASP MASVS.
I worked on binary analysis, fuzzing, and vulnerability research with malware samples. This period became the low-level starting point for the security tools I later built.