My OSS Projects
- NPM | is-path-inside-secure
- NPM | spotlighting-datamarking
- NPM Package Blast Radius | OpenSecure
OSS Project Contributions
- 2020: Helped build the brute force list for GraphQL in the largest list set used for security assessments, SecLists
W3C Standards Reviews
Security and privacy reviews, threat models, and recommendations for web standards:
- Autoplay Policy Detection: Reviewed private browsing detection risks, safeguards against programmatic unmuting, and accessibility guidance for muted autoplay.
- CSS Color Adjustment Level 1: Reviewed fingerprinting and cross-origin timing risks, with recommendations on forced-colors emulation and privacy considerations.
- Screen Orientation: Assessed security and privacy protections; raised discussion points on rapid lock/unlock requests and user-visible orientation-lock indicators.
- WebMCP: Developed a stakeholder inventory and analyzed 16 threats, including prompt injection, data exfiltration, tool registration, invocation accountability, and excessive permissions.