At OWASP Foundation, I architected and shipped BLT-Toasty, an AI-assisted gatekeeper that evaluates GitHub pull requests in real time. I also engineered automated policy, formatting, test-coverage, and CI/CD checks.
On Cavix, I built a code review platform that turns suspected defects into executable checks and verifies findings using evidence from isolated sandboxes. Its pipeline uses Go and Redis for concurrent event processing, with Docker and gVisor for isolation.
I also built Velra, a Rust continuation layer that preserves coding-work state across Claude Code sessions. It records events in SQLite and reconstructs deterministic snapshots without relying on an LLM.
As an independent security researcher at HackerOne, I built a repeatable Claude-assisted workflow for vulnerability research and responsible disclosure. I reported three vulnerabilities across two organizations, including GitLab and Vercel, and have contributed to open-source projects through 37+ merged pull requests.

