Skip to content
View li-jin-quan's full-sized avatar

Block or report li-jin-quan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
li-jin-quan/README.md

👋 Hi, I'm Li Jinquan (李金泉)

🛡️ Security Engineer · 🤖 AI-native Builder · 🦀 Rust · 10+ yrs in software engineering

📄 View my Resume · Online Preview


🛡️ About Me

Offensive-security-minded engineer who builds and breaks systems for a living — then ships the fixes.

  • 🕵️ Bug bounty hunter — reported high / critical vulnerabilities on HackerOne and Immunefi (Web3 / smart-contract security), verified on international platforms.
  • 🦀 Rust deep-diver — using Rust since the 1.0 era; strong on ownership, borrowing, unsafe, FFI, and system-level security.
  • 🤖 AI-native — private LLM deployment, AI coding assistants, RAG-based customer service, DevSecOps.
  • 🏗️ 10+ years experience since 2016: chip test systems, security tooling, microservices architecture.
  • 🌱 Building an AI Security venture — guardrails, red-team automation, secure-by-design AI products.
  • 💬 Ask me about Rust · Web3 security · AI security · DevSecOps · Reverse engineering.

🚀 Open-Source Contribution

RustSec PR #1686

Fixed a panic / DoS vulnerability in RustSec / cargo-audit — the de-facto dependency-security auditor of the Rust ecosystem.

  • Found & fixed an input-validation crash in rustsec_refs_imported() (#1681): malformed OSV reference URLs caused a panic, crashing cargo-audit / cargo-deny for downstream users.
  • Replaced a hard-coded byte-slice + .expect() with strip_prefix() + filter_map() — malformed URLs are now safely skipped instead of crashing.
  • Added unit tests covering valid, truncated, malformed, and mixed reference URLs.
  • Single-file patch, +79 / −5, zero behavioural change for valid input.

🛠️ Tech Stack

Languages Rust Python Java Go TypeScript JavaScript C# C++

Security HackerOne Immunefi OWASP Web3 DevSecOps

AI / Backend / Frontend LLM RAG Spring Boot Vue Docker PostgreSQL


🧠 Building

An AI Security ventureguardrails, red-team automation, and secure-by-design AI products.

I think like an attacker (white-hat) and build like an engineer — the combination AI security actually needs.


Security isn't a feature — it's a mindset.

Popular repositories Loading

  1. Python-UIAutomation-for-Windows Python-UIAutomation-for-Windows Public

    Forked from yinkaisheng/Python-UIAutomation-for-Windows

    Python wrapper of Microsoft UI Automation (IUIAutomation) — Windows GUI automation, py2/py3.

    Python 1

  2. lijinquan-p2p lijinquan-p2p Public archive

    P2P 网络项目

    Java 1

  3. tgbot-front tgbot-front Public

    Telegram search bot frontend built with Vue.js.

    Vue 1

  4. rustsec rustsec Public

    Forked from rustsec/rustsec

    RustSec ecosystem: security advisory database analysis & tooling for Rust dependencies.

    Rust 1

  5. li-jin-quan li-jin-quan Public

    Li Jinquan (李金泉) — AI Security · DevSecOps · Rust · Full-stack. Personal GitHub profile.

    1

  6. resume resume Public

    Public resume of Li Jinquan (李金泉) — AI Security & DevSecOps Engineer. Full PDF + online preview with HackerOne/Immunefi track record.

    HTML 1