I build agentic engineering systems, security tooling, and product operations that turn ambiguous work into tested, reviewable software. My current obsession is making autonomous development accountable: narrow diffs, reproducible evidence, hard QA gates, and useful products at the end.
Based in Mexico City. Working in public across AI agents, developer tooling, OSINT, cybersecurity, and automation.
Recognizable organizations accepted this work into the software people use. The headline explains the value; the receipt exposes the exact code review.
|
Sentry · Python SDK#6241 MERGED — gave teams a privacy control that drops scrubbed user IP addresses from the official SDK.Python · privacy · SDK behavior |
|
Palantir · Blueprint#8165 MERGED — made large React migrations safer by detecting deprecated components hidden behind aliases.TypeScript · React · static analysis |
|
OWASP · Agent Security Regression Harness#149 MERGED — enabled more realistic, authenticated HTTP testing for AI-agent security regressions.Python · agent security · HTTP testing |
|
Texas Instruments · embedded developer toolingopen-pru #139 MERGED · processor-sdk-doc #720 MERGED — improved portable assembly workflows and made Android SDK documentation more reliable to build and maintain.Embedded systems · assembly toolchains · Linux/Android documentation |
|
Google Labs · design.md#131 MERGED — fixed primitive rendering from specification config, keeping AI-assisted design output faithful to its source data.TypeScript · generative UI · structured specifications |
|
Aqua Security · Trivy#10828 MERGED · #10857 MERGED — made a widely used software-supply-chain scanner easier to operate correctly.Go ecosystem · security · developer experience |
|
Maigret · repeat contributor#2318 · #2442 · #2558 · #2588 · #2779 — five accepted improvements show sustained trust, not a one-off contribution.Python · OSINT · sustained maintenance |
Open the full merged ledger · security, developer tools, and infrastructure receipts
| Locust #3384 MERGED — corrected report and navbar request-rate semantics. |
|
| mitmproxy #8196 MERGED — prevented a binary-detection crash on short network payload tails. |
|
| Sentry · Responses #791 MERGED · #807 MERGED — fixed recorded-response failures and strengthened public Python typing. |
|
| Zeek · package manager #222 MERGED · #224 MERGED — improved the onboarding path for a core network-security ecosystem. |
|
| jc #692 MERGED · #711 MERGED — corrected network-parser behavior and improved command-line data tooling. |
Cybersecurity + AI fieldwork · accurate status, no inflated claims
- Anthropic Cybersecurity Skills (community project) — improved cloud-security skill descriptions for agent discovery in PR #25. The proposal was closed rather than merged, so it is shown as fieldwork—not an upstream acceptance.
- Security surface covered — cloud security, malware analysis, forensics, OSINT, agent security, network traffic, and software-supply-chain scanning.
- Operating principle — reproduce the failure, make the smallest defensible change, test the claim, and link the public receipt.
- Maigret #2930 — modern XMind reader compatibility; full multi-version CI green.
- Maigret #2929 — ReverbNation false-positive detection; full multi-version CI green.
- jc #722 — preserves bracketed and empty scalar values; 20-platform CI matrix green.
How I ship with agents
I run a multi-agent engineering loop with explicit ownership:
- Jeffrey orchestrates scope, implementation, and delivery.
- Magno handles infrastructure and heavy build/test workloads.
- Ludwig is the senior engineering and QA gate.
- Every non-trivial claim closes with evidence: tests, CI, review state, and a precise remaining risk.
The goal is not “AI wrote code.” The goal is reliable software with a shorter path from intent to proof.
Build the system. Test the claim. Ship the evidence.
flagship project · repositories · pull requests












