Skip to content
BlueDot IT Start a conversation

Selected work

Take a look at the work.

Here are a few projects and security reports, with links so you can look through them yourself.

Public security research

Security issues I've reported.

01

OpenClaw

Browser CDP discovery network-policy bypass

Browser discovery could reach destinations prohibited by OpenClaw's network policy. Impact depended on configuration and whether lower-trust input could reach the affected feature.

Read the public record

02

OpenClaw iOS

Unattended credentials exposed in iOS diagnostic logs

Sensitive unattended-agent link data could enter diagnostic logs, exposing credentials to someone with access to those logs.

Read the public record

Public repositories

Projects you can explore.

01

Application security

security-middleware

TypeScript middleware that checks security headers, CORS, and npm dependencies during development.

Developer-facing feedback keeps these checks near the code being changed.

Open public repository

02

AI automation and security

GhostMCP

A beta MCP server for authorized assessments with policy-guarded tools, workflows, and audit logging.

The repository documents the controls and the limits of the beta system.

Open public repository

03

AI systems

Odinn-Forge

A local-first, single-user AI assistant with inspectable memory, approved tools, and activity history.

The source shows how memory, approvals, and tool activity are represented.

Open public repository

These descriptions are a snapshot. Check the repositories for the latest code and project notes.