Skip to content

I ship production systems and run the agents that build them.

AI-native full-stackPereira, Colombia (UTC−5)Full-stack engineer at KitchenSyncFrom Oct 2026

Ghost AI turns a plain-English description of a system into a shared canvas that exports as a Markdown spec. authzscan sends agents through an existing Next.js codebase to review its authorization logic and publishes its own accuracy. Both were built from a written architecture and spec, with agents doing most of the typing.

Measured results
  • authzscan on the seeded benchmarkrecall · 0 false positives
    0/16
  • authzscan on a real repositorycandidates confirmed · the gap was in the benchmark
    0/11
  • Deploy time at Tamboraminutes, down from two hours over SSH · Azure CI/CD
    0
01Work

Products that survived real users, and the agents that helped build them.

Every claim on this page maps to a repository you can run or a site you can open. The scanner ships its own benchmark; the labs ship a broken half and a fixed half.

Production system

Ghost AI

A team describes a system, an agent draws it, the graph exports as a spec

A real-time workspace where a team describes a system in plain English, an agent lays it onto a shared canvas, and the final graph exports as a Markdown spec you can hand to an implementation pipeline.

  • Next.js, Liveblocks for presence and shared state, React Flow for the canvas, Prisma and PostgreSQL underneath. The agent runs on the Vercel AI SDK with Gemini and edits the graph through structured mutations instead of free-form text. Templates give a new project a starting graph.
  • Built from four context files (project overview, architecture, code standards, progress tracker) that every coding session starts from. The writeup covers the workflow.
  • Next.js
  • Liveblocks
  • React Flow
  • Vercel AI SDK
  • Prisma
Agent toolopen source

authzscan

Agents that review an existing Next.js codebase for authorization bugs

An automated review of authorization logic in Next.js App Router repos. Agents follow each client-controlled identifier to the database query it reaches and flag the ones with no ownership check. Pattern-matching SAST mostly cannot see this class of bug; an agent that reads the code can, and the benchmark says how far to trust it.

  • Four phases: a deterministic endpoint inventory with ts-morph (route handlers, Server Actions, auth-library detection), an agent trace pass, an adversarial verify pass whose whole job is killing false positives, and reports in Markdown, SARIF or JSON with exit codes CI can gate on.
  • Accuracy is measured against a seeded benchmark of 16 IDOR/BOLA bugs plus 6 correctly written twins as false-positive traps, recall and precision gates, and an oracle runner that proves the harness scores correctly regardless of how good the model is.
  • An endpoint it could not analyze is reported as not analyzed rather than clean. The inventory has run on repos of up to about 3,000 files and 647 endpoints.
  • TypeScript
  • ts-morph
  • Anthropic SDK
  • SARIF
  • Next.js
Production system

Materiales La Bodega

Solo-built e-commerce platform, live in production

A live storefront for a family-owned hardware retailer that moves roughly $1.5M COP a day. Real customers pay real money through it, and when it breaks I am the only one who can fix it.

  • Authentication, session security and RBAC that keep the staff side separate from the customer side, with Mercado Pago wired up for live transactions.
  • Hardened against the OWASP Top 10: parameterized queries, server-side validation, CSRF protection on anything that changes state, least-privilege database roles.
  • Next.js
  • PostgreSQL
  • Mercado Pago
  • RBAC
Production system

PairCode

Secure real-time collaborative workspace

Auth built in-house: EdDSA JWTs, rotating refresh tokens that detect reuse, Argon2id hashing, CSRF protection.

  • Node.js
  • Express
  • PostgreSQL
  • WebSockets
Offense / defense lab

JWT Security Lab + jwt-scan

A JWT lab with a broken half and a fixed half, shipped as an npm scanner

JWT signing and verification written from scratch in TypeScript, no libraries, reproducing five flaws that reach production: alg=none bypass, HS256/RS256 key confusion, weak-secret brute force, kid header injection, and missing iss/aud/exp validation.

  • TypeScript
  • Node.js
  • OpenSSL
  • Docker
Offense / defense lab

LLM/RAG Security Lab

OWASP LLM Top 10, attack side and defense side

Five scenarios as a pytest attack suite: cross-tenant retrieval leak (confused deputy), indirect prompt injection through retrieved documents, vector-store poisoning via forged ingest metadata, excessive agency over a real MCP tool server, and stored XSS straight out of the model.

  • Python
  • FastAPI
  • MCP
  • RAG
02Attack surface

A threat model you can poke at.

The auth and realtime layer of PairCode, laid out by trust zone. Attacker view shows what crosses each boundary; defender view shows what stops it. Drag things around.

Severitycriticalseriouswarning
03About

Full-stack engineer who writes the spec before the code.

I'm a full-stack engineer from Pereira, Colombia: React and Next.js on the front, Node, TypeScript and PostgreSQL on the back. Most of my code is now written with coding agents, and what I have learned is that the output is only as good as the architecture and the spec the agent starts from. The prompt matters much less.

In practice that means writing the context files before the feature: what the system is, how it is laid out, what the standards are, where the work stands. Ghost AI was built that way from the first commit. authzscan turns the same idea around and sends agents through an existing codebase to evaluate it, with a benchmark that says how much to trust the result.

I came to this through application security and kept the habit. I threat model a feature before it ships and attack my own work before anyone else can, which matters more now that agents, retrieval and tool calls are part of the app.

Facts
Based in
Pereira, Colombia
Working hours
LATAM · US · EU overlap
Languages
Spanish, English C1, German B1
Daily driver
Claude Code, Arch Linux, Burp Suite
Languages
  • ESNative
  • ENC1
  • DEB1

Full-stack engineer at KitchenSync from Oct 2026 · always up for an AppSec conversation

04Skills

Full-stack, with agents doing most of the typing.

AI engineering, frontend and backend are the job. Application security is the habit that keeps what the agents write from shipping with holes in it.

AI engineering

10
  • Spec-driven development with agents
  • Claude Code
  • Anthropic SDK
  • Vercel AI SDK
  • MCP servers
  • RAG pipelines
  • Structured outputs
  • Agent evals & benchmarks
  • Prompt-injection defense
  • SSE streaming

Frontend

8
  • React 19
  • Next.js (App Router, RSC)
  • TypeScript
  • Tailwind CSS
  • Framer Motion
  • GSAP
  • D3
  • Astro

Backend

11
  • Node.js
  • Next.js (Server Actions, Route Handlers)
  • Express
  • FastAPI
  • Prisma
  • PostgreSQL
  • MongoDB
  • Redis
  • WebSockets
  • Zod
  • Jest

Application security

7
  • OWASP Top 10 (Web + LLM)
  • Broken access control / IDOR
  • Threat modeling (STRIDE)
  • OAuth 2.0 / OIDC
  • JWT (EdDSA, RS256)
  • RBAC & session hardening
  • Secure code review

Security tooling

6
  • Burp Suite
  • Semgrep
  • Trivy
  • SARIF / code scanning
  • OWASP ZAP
  • nmap

Platform & languages

10
  • TypeScript
  • Python
  • C
  • SQL
  • Bash
  • Docker
  • Linux
  • GitHub Actions
  • Azure Pipelines
  • AWS
05Timeline

From shipping features to shipping the specs agents build from.

Work, study and the open-source releases, newest first.

  1. Oct 2026 – nowWork

    AI Full Stack Engineer

    KitchenSync

    Building agent-driven solutions for the restaurant industry.

  2. Aug 2026Shipped

    authzscan on real code

    Writeup

    Pointed the scanner at a real open-source repo after a 100% benchmark score. One genuine bug in eleven candidates. The gap turned out to be in the benchmark rather than the model.

  3. Jul 2026Shipped

    authzscan v1

    Open source

    Agent-driven IDOR/BOLA scanner for Next.js App Router with a seeded 16-bug benchmark and SARIF output.

  4. Jun 2026Shipped

    LLM/RAG Security Lab

    Open source

    Five OWASP LLM Top 10 attacks as a pytest suite against a vulnerable/hardened FastAPI pair, including excessive agency over a live MCP server.

  5. May 2026Shipped

    Ghost AI

    Product · Writeup

    Real-time architecture canvas on Next.js, Liveblocks and React Flow that exports the graph as a Markdown spec. Built with coding agents from four context files; the writeup covers the workflow.

  6. Apr 2026Shipped

    JWT Security Lab & jwt-scan

    Open source · npm

    From-scratch JWT sign/verify reproducing five production flaws, then shipped as an npm CLI scanner.

  7. 2026Credential

    Google Professional Cybersecurity Certificate

    Google · Coursera

    Completed alongside every free lab in the PortSwigger Web Security Academy.

  8. Jul – Sep 2025Work

    Frontend Developer (Contract)

    Tambora · Remote

    Migrated business-critical modules from jQuery to React (40% smaller bundles, DOM string injection gone), consolidated an Atomic Design library, and replaced manual SSH deploys with Azure CI/CD: two hours to under fifteen minutes.

  9. Jun – Jul 2024Education

    Full-Stack Development Bootcamp

    EliteStack · Pereira

    Linux/CLI, TypeScript, Node.js, Docker, REST, WebSockets, Next.js, AWS. The first time the pieces of a production system fit together for me.

  10. Feb 2022 – presentEducation

    Systems & Computing Engineering

    Universidad Tecnológica de Pereira

    In progress, alongside self-directed study in operating systems, networks, algorithms and applied ML.

07Contact

Let's build the next one from a spec.

I'm joining KitchenSync as a full-stack engineer in October 2026, so I'm not looking for a new role. If you want to talk authorization bugs, agent tooling, or something you're building, write to me.

Usually answered within a day.