Systems · Security · Developer Tooling
I build local-first AI infrastructure, instrumentation tools, and Android runtime experiments. I focus on explicit trust boundaries, testable contracts, and reproducible evidence.
- #3 · Harden Luma bug paths: improved build reliability, instrument-path validation, error reporting, and handling of malformed input or unavailable runtime resources.
- #4 · Fix mission session providers: fixed live assistant-text continuity and added an OpenAI-compatible mission provider with optional API keys and corrected URL handling.
Both contributions were merged into frida/luma.
Ditto · Local-first personal AI
- Problem: Keep long-running personal AI work manageable as memory, capabilities, and scheduled tasks grow.
- Core: A Rust runtime with an append-only event spine, scoped memory, bounded context retrieval, content-addressed artifacts, and explicit effect permissions.
- Evidence & stage: An executable foundation with offline memory-correction and restart evidence. The synthetic checks cover corrected-memory inclusion and irrelevant or cross-session memory exclusion; they do not establish general live-agent quality. Broader tool execution and efficiency goals remain in development.
flab · Reproducible instrumentation
- Problem: Keep authorized runtime research repeatable across manual and automated interfaces, with explicit session ownership and cleanup.
- Core: A shared TypeScript engine behind a guided TUI, CLI, and MCP/ACP interfaces, with bounded recording and descriptor-driven instruments.
- Evidence & stage: The Android live-verification report records device-specific results, restoration and cleanup, excluded targets, and remaining blockers. Coverage is limited to the documented authorized offline tests.
RexPlayer · Android runtime research
- Problem: Explore a small native host for container-based Android on Windows/WSL2 and Linux.
- Core: Android substrate experiments, a native input path, host capability inspection, and an early Rust host UI.
- Evidence & stage: The runtime verification report documents Android 14 boot, ADB, and raw touchscreen-input delivery on two lab substrates. This is a pre-alpha research project; integrated rendering, audio, production packaging, and performance remain unverified.
- remotepad: Rust remote-input server, binary UDP protocol, and web layout editor.
- Spellwire: TypeScript-to-native input automation with a Rust runtime, stateful hotkeys, and overlays.
- Vlitz: Frida-based dynamic debugging and process-analysis CLI in Rust.
- DreamHack profile: 16,550 points, rank #28, 76 challenges, with a focus on reversing and systems security
- Paid client delivery across web, automation, and systems projects; detailed scope and redacted evidence are available in a role-specific resume
- Languages: Rust, TypeScript/JavaScript, Python, C, Shell
- Platforms: Linux, Android, Windows/WSL2, containers, GitHub Actions
- Focus: platform engineering, developer experience, runtime security, reverse engineering, automation, and reliable operations
- Workflow: agent-assisted where useful, with human-owned architecture, explicit attribution, executable checks, and reproducible evidence
Security work shown here is limited to systems I own or am authorized to test, offline targets, and isolated research environments. The goal is defensive, reproducible engineering—not unauthorized access or interference with other users, services, or economies.




