Services
Services
Short, scoped work built from what is already proven in public. Each service below links to the real DEV.to articles and repositories it is drawn from, not to a claim.
Short, scoped engagements. Typically 1 to 2 weeks. Fixed scope agreed after an initial conversation, not a fixed price list.
-
01 / Services
AI / MCP Security Review
Who this is for
Teams shipping an MCP server, an AI agent with tool access, or a Claude/Copilot-integrated product, especially before exposing it to other users or tenants.
The problem
A happy-path demo is not evidence that an MCP surface is safe. Tool poisoning, path traversal on the write side, tenant isolation gaps, and CI token reuse are the exact bug classes behind 2026's worst MCP CVEs, including a CVSS 9.1 unauthenticated RCE chain. Most teams have never run an adversarial pass against their own tools.
What you get
- A static scan of your MCP manifests, tool definitions, and .claude/ directory against 22 documented rule classes: tool poisoning, command injection, path traversal, SSRF, secrets, and CI/CD workflow risks.
- Behavioral tests for tenant isolation and write-tool approval, run against a fixture you control.
- A report with rule ID, severity, redacted evidence, and remediation, so each finding is an engineering task, not a vague warning.
- One scoped re-test after fixes ship.
Proof of work
Send the repo link for your MCP server or agent tool, and I will tell you what a scoped review actually finds before we talk about anything else.
Start this conversation → -
02 / Services
Security Automation Sprint
Who this is for
Small to mid-size security or IT teams that need a CI security gate, a SOC tooling integration, or an enterprise SaaS security automation, such as Copilot Studio or Power Automate, built without hiring a full-time automation engineer.
The problem
Free tools catch less than teams assume. A default Semgrep scan reported 3 of 10 planted vulnerabilities in one test. CI workflows quietly carry privileged-token reuse risk that a generic rule set will not catch. Manual triage does not scale past a handful of tickets a day.
What you get
- One scoped automation build: a detection rule, a CI security gate, or a security-relevant Power Automate or Copilot Studio integration.
- A test suite proving the automation catches what it claims to catch.
- A short honesty report on what the build catches and what it does not, so it never gets mistaken for a guarantee.
Proof of work
Tell me the one manual security task eating your team's time, and I will scope a short sprint to automate the part that is actually safe to automate.
Start this conversation → -
03 / Services
Security Technical Writing
Who this is for
Security or dev-tool vendors that need technical content developers actually trust, or engineering teams that want an internal security postmortem or advisory written up properly.
The problem
Most vendor security content is either thin marketing copy or too academic to act on. Developers trust writers who show their own tools failing and getting fixed, not writers who only show wins.
What you get
- One technical deep-dive: a CVE analysis, a benchmark write-up, or an incident postmortem, structured around evidence rather than adjectives.
- Code-level detail where it earns its place, and an explicit limitations section every time.
- Delivered ghostwritten or under your byline.
Proof of work
If your last security write-up got zero engagement from developers, send it over and I will tell you what is missing before you write the next one.
Start this conversation →