Building Redmai — autonomous API and agent security scanning.
Pentester working across two surfaces: classic AppSec on web infrastructure and Web3 smart contracts, and AI / LLM security (MCP servers, agent tooling, prompt injection, OWASP LLM Top 10). Most code in my repos is built by multi-agent pipelines I orchestrate; I design what they build and review what ships.
13 atomic MCP tools for AppSec and AI Security engineers: recon, HTTP introspection, JWT and crypto inspection, MCP server audit, prompt-injection audit, OWASP LLM Top 10 classification. SSRF and path-traversal guards on every network and filesystem tool. Opt-in gate on offensive primitives. Published to PyPI via Trusted Publishing with Sigstore provenance.
- Product: redmai.io
- Open source: pinned below.
Based in Bangkok, GMT+7. Async-friendly.