Find and remove a concrete security risk in one bounded source area before it becomes an incident.
I review one component or execution path of roughly 2,000 lines of code. This is a focused engineering engagement, not an open-ended penetration test.
You receive:
• Threat-focused source review
• Deterministic local reproduction or proof of concept for confirmed issues
• Minimal, production-ready patch
• Regression tests and verification evidence
• Concise severity, impact, and remediation report
Process:
Confirm scope, trust boundaries, and build steps
Reproduce suspicious behavior locally
Review the reachable code path and relevant history
Patch the root cause and add regression coverage
Deliver findings, limitations, and exact verification commands
To begin, I need the source repository or archive, build/test instructions, the target component, and any relevant threat assumptions. I will not test production systems or access third-party data without separate written authorization.
Find and remove a concrete security risk in one bounded source area before it becomes an incident.
I review one component or execution path of roughly 2,000 lines of code. This is a focused engineering engagement, not an open-ended penetration test.
You receive:
• Threat-focused source review
• Deterministic local reproduction or proof of concept for confirmed issues
• Minimal, production-ready patch
• Regression tests and verification evidence
• Concise severity, impact, and remediation report
Process:
Confirm scope, trust boundaries, and build steps
Reproduce suspicious behavior locally
Review the reachable code path and relevant history
Patch the root cause and add regression coverage
Deliver findings, limitations, and exact verification commands
To begin, I need the source repository or archive, build/test instructions, the target component, and any relevant threat assumptions. I will not test production systems or access third-party data without separate written authorization.