Public Tooling
The Arsenal
The full arsenal: every tool, running and public on GitHub. Offensive and defensive security, wireless and RF, forensics, privacy, deployment. The curated, narrated version is on Work; this is all of it.
Recent Findings
Building the tools is half of it. This is the other half: real bugs found and fixed by actually running this arsenal against reality instead of trusting what a comment claims.
- 2026-09-03coin_droppa
A Netlify secret-scan false positive on a public contract address had silently blocked every production deploy since May: four months of real security hardening never went live. Found via response-header analysis, fixed with a scoped SECRETS_SCAN_OMIT_KEYS, verified end-to-end. Full write-up →
- 2026-09-03amnesia
The privacy sanitizer's own comment claimed metadata was wiped; the code called the one sharp() method that retains it. GPS coordinates and camera serials survived every "sanitized" output. Fixed by removing the call. Sharp strips by default. Full write-up →
- 2026-09-03claude_whisperer
The core safety-detection pipeline matched nothing, for any input, ever: three compounding bugs (a pattern-merge that silently dropped two of three files, a field-name mismatch, a confidence gate with no real confidence value). Its own tests passed because their fixtures no longer matched the real schema. Full write-up →
Systems & Tools
Private signing and deployment server for rapid iOS app installation and Apple validation blocking.
Security monitor for iOS, macOS, and Linux that detects IMSI catchers and signal downgrades.
macOS utility that identifies and removes gigabytes of invisible junk files and build artifacts.
Automation engine for visual regression testing and generating framed App Store screenshots.
Host Intrusion Prevention System (HIPS) prototype for macOS demonstrating security internals.
Network filter for packet manipulation, MAC spoofing, and IDS evasion for security research.
Terminal-native financial tool that evaluates if market information remains tradable or is obsolete.
Security tool for testing metadata injection, steganography, and parser exploits in image formats.
Penetration testing framework designed to audit and secure newsroom infrastructure.
APT-inspired C2 suite for managing distributed trading nodes and liquidity coordination.
Precision wireless intelligence suite for airspace enumeration, behavioral profiling, and anomaly detection.
Tactical drone security platform for protocol interception, RF analysis, and MAVLink override simulation.
Sun-readable SwiftUI flight companion for drone documentary work: real-time telemetry HUD, shot lists, and pre-flight checklists, built for run-and-gun sets, not menu shopping.
Technical control interface for independent media labs with system telemetry and app injection.
Privacy-first local perimeter monitoring station for secure, cloud-free surveillance management.
Specialized framework for verifying the integrity and security of wireless network adapters.
Visual privacy remediation suite for identifying and scrubbing regional identifiers, landmarks, and boutique signatures from digital assets.
Specialized media player designed to protect desktop activity from screen-scraping and automated monitoring through screenshot hardening and panic-key obfuscation.
A high-deterrence security layer that protects digital domains from unauthorized scrapers by imposing resource-draining retaliation protocols.
Cynthia handles the frequencies while you pour a double. Discreet, sophisticated, and strictly professional. Mostly.
Trust nothing, verify everything. A multi-agent security auditor that hunts for hallucinations, ghost methods, and sanitization theater in AI-generated code.
LLM-powered content-decay auditor, points at an archive and ranks every piece by how far it has rotted: dead links, superseded model IDs, predictions that already landed.
Browser Augmentations
Educational security demo showcasing how malicious extensions can silently drain crypto wallets.
YouTube ad silencer serving as a research case study for hardened extension architectures.
Browser extension designed to resist emotional capture by blocking attention-hijacking content.
