Building the map before building the weapon. 🗺️⚙️ The Threat Cartographer’s Atlas is taking shap...Building the map before building the weapon. 🗺️⚙️ The Threat Cartographer’s Atlas is taking shap...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Building the map before building the weapon. 🗺️⚙️
The Threat Cartographer’s Atlas is taking shape — a structured way to understand, audit, attack, and defend the modern API ecosystem.
REST. GraphQL. Authentication. Authorization. Injection. Reconnaissance. Defensive controls.
Instead of treating these as disconnected techniques, I’m mapping them as one system:
What I built: ShayanLabs, a next-generation AI-driven developer workspace featuring a futuristic dark-mode dashboard, multi-model chat architecture, a one-prompt web app builder with instant live previews, and a built-in prompt library for managing code snippets and stack traces.
Why I built it: To eliminate developer friction and empower indie hackers with a centralized engineering stack that takes projects from initial idea to production-ready deployment with absolute speed.
This project focused on building and testing a practical AI security assessment lab for evaluating LLM defenses against prompt injection and jailbreak attacks.
I integrated Spikee by Reversec with a locally hosted cybersecurity model running through LM Studio, then added NVIDIA NeMo Guardrails to compare model behavior under three conditions: no guardrails, input filtering, and combined input/output protection.
The work included configuring the local model environment, building a custom FastAPI gateway, integrating NeMo Guardrails, troubleshooting model latency and timeout issues, creating a reusable Spikee target, and analyzing attack results using Spikee’s built-in reporting tools.
The project also explored different adversarial testing approaches, including prompt injection datasets, obfuscation, encoded attacks, Best-of-N testing, synthetic canary leakage tests, and structured benchmark comparisons.
The objective was to measure how much the guardrails reduced successful attacks while keeping the model, dataset, and testing conditions consistent.
This project demonstrates a hands-on approach to LLM red teaming, AI safety testing, prompt-injection assessment, and guardrail validation for organizations deploying generative AI systems.
SentriGo is a security-tech SaaS landing page built to help teams manage reporting, monitoring, and incident resolution from one connected workflow.
The design focuses on clarity, fast decision-making, and operational visibility. Large typography, industrial imagery, incident markers, and compact metrics help communicate the product without making the page feel too technical or overloaded.