Software × Security × Automation

Make your
systems
work for
you.

I build software, connect the tools you use,
and help you figure out where your systems
need better protection.

BlueDot IT / services

What can I help with?

Need a security review, less manual work, or software that fits your business? That's where I can help.

Services

Security, automation, and software.

01

Cybersecurity

Find security gaps in your applications and infrastructure, and work out what to fix first.

  • Application and infrastructure review
  • Practical hardening and remediation planning
  • Defined scope and authorization

02

Intelligent automation

Connect your tools and cut down on repetitive tasks, with checks in place so you stay in control.

  • Workflow integrations
  • Purpose-built AI assistants
  • Human review and access controls

03

Software development

Build the application, integration, or internal tool your team needs, shaped around the way you work.

  • TypeScript and Python development
  • Backend and integration work
  • Testing, documentation, and handoff

Not sure where to start?

Tell me what's getting in the way.

You might know exactly what needs fixing, or just know that something isn't working well. We can start there, talk through the options, and agree on the work before it begins.

Let's talk

Security research / public record

Security Research & Disclosures

Security issues I've reported, with links to the published advisories and reporter credits.

Published research

2 published advisory credits, including 1 associated CVE.

A GHSA and its associated CVE count as one finding. My credit here is for reporting the issue, not writing or independently verifying the fix. This work does not imply an affiliation with the project.

Public sources reviewed .

01

OpenClaw

Browser CDP discovery network-policy bypass

GHSA-3x84-qq85-fj65 CVE-2026-62197

Role
Reporter, Jason O'Neal
Advisory published
CVE record
First patched
2026.6.6

Impact. Browser discovery could reach destinations prohibited by OpenClaw's network policy. Impact depended on configuration and whether lower-trust input could reach the affected feature.

Boundary

Network restrictions should apply to the destination selected during browser discovery.

Documented failure

The public advisory documents acceptance of WebSocket destinations that policy should have blocked.

Contribution

GitHub and the official CVE record credit Jason O'Neal as the reporter. These records do not establish fix authorship.

Remediation

The advisory identifies 2026.6.6 as the first stable patched version. The CVE and GHSA describe the same finding.

02

OpenClaw iOS

Unattended credentials exposed in iOS diagnostic logs

GHSA-5j57-84cx-r295

Role
Reporter, Jason O'Neal
Advisory published
First patched
2026.8.11

Impact. Sensitive unattended-agent link data could enter diagnostic logs, exposing credentials to someone with access to those logs.

Boundary

Diagnostic output should not expose credentials used for unattended agent requests.

Documented failure

The public advisory documents logging of complete deep links, including a persistent credential and private request data.

Contribution

GitHub credits Jason O'Neal as the reporter. Reporter credit is distinct from developing or independently verifying the repair.

Remediation

The advisory identifies 2026.8.11 as the first stable patched version and advises rotating exposed keys and removing affected diagnostic archives. No CVE is listed in that advisory as of this review.

What's included

Published reports only.

Everything here is based on published advisories and CVE records. Private discussions and unpublished reports stay private.

Ask about a security review

About BlueDot IT

Hi, I'm Jason.

I founded BlueDot IT LLC to bring together the work I do in software, security, and automation. I'm also studying cybersecurity at DeVry.

The founder

Jason O'Neal

I work with web applications, Linux infrastructure, AI agents, and the integrations that connect them.

I've also reported security issues in OpenClaw. You can read the published advisories and see my reporter credits in the research section.

Read the public research

How I work

Know what you're getting.

I want you to understand what we're changing and why. Before work starts, we agree on the scope. At the end, you get an explanation of what changed, what still needs attention, and how to use it.

Getting started

What's on your mind?

Tell me about the project or the problem. Leave sensitive information out of the form; if I need it, we'll agree on a safe way to share it.

Tell me about it

Tell me about it

What are you working on?

Tell me what you're working on and where you're stuck. You don't need to have all the technical details figured out.

Get in touch

A few details are enough to start.

I'll read your message and get back to you. If I need more detail, I'll ask.

Please leave out passwords, access tokens, customer records, and other sensitive data. Don't include details of an unpatched security issue here.

Preparing the scene...

Start a conversation

A starting point

What are you
working toward?

Prepare a project brief on your device. Nothing is sent. When you are ready, use the contact form to send an inquiry.

Leave out passwords, tokens, customer records, and other sensitive information.