I'm a security-minded software engineer from Iraq with a deep interest in vulnerability research, AI systems, and building software that solves real problems. I've reported 4 security advisories in production open-source projects through responsible disclosure. I enjoy breaking things responsibly and building them back stronger.
My work sits at the intersection of application security and AI engineering — I hunt for vulnerabilities in open-source projects through responsible disclosure, and I design systems where safety and privacy are first-class concerns.
- Security Research — Responsible vulnerability disclosure in open-source projects. I focus on web application security, server-side attack vectors, and authorization logic flaws.
- AI Engineering — Building intelligent systems with an emphasis on safety, privacy, and governance. I work with LLMs, AI routing, and agent orchestration.
- Full-Stack Development — Designing and shipping production applications across healthcare, education, and communication domains.
| Domain | Focus |
|---|---|
| 🧠 AI & Agents | Smart routing frameworks, governance-first AI orchestration, and AI-powered education platforms |
| 🏥 Healthcare Tech | Clinic management systems with AI assistance, intelligent chatbots for patient interaction |
| 🔒 Secure Communications | Privacy-focused messaging platforms with end-to-end encryption |
| 📊 Strategic Intelligence | Competitive analysis engines with simulation and decision-support capabilities |
Vulnerabilities I discovered and responsibly disclosed in open-source projects:
| CVE | Project | Vulnerability | Severity | Status |
|---|---|---|---|---|
| CVE-2026-27008 | OpenClaw | Arbitrary File Write via Path Traversal in Skill Download Installer | High | ✅ Fixed in v2026.2.15 |
| CVE-2026-27009 | OpenClaw | Stored XSS via Assistant Name/Avatar in Control UI | Moderate | ✅ Fixed in v2026.2.15 |
| CVE-2026-27488 | OpenClaw | SSRF in Cron Webhook Delivery via Missing SSRF Guard | Moderate | ✅ Fixed in v2026.2.18 |
| GHSA (CVE Pending) | OpenClaw | Owner-only Gateway Tool Access Checks Incomplete in Authenticated DM Flows | Low | ✅ Fixed in v2026.2.19 |
More advisories in progress — responsible disclosure in action.
- Security First — Every system I build starts with a threat model
- Responsible Disclosure — I report vulnerabilities ethically, always
- Privacy by Design — User data protection is non-negotiable
- Open Source — I believe in contributing back to the community
"Break it to understand it. Fix it to make it stronger."