Security engineer, out of red teaming and penetration testing. What I have been doing these last few years is writing the attacker's way of thinking into open source: an autonomous red-team platform where the AI picks its own targets and techniques, a protocol that compiles a development playbook into guardrails for AI, and the automation behind Taiwan's security content. You cannot defend what you do not understand attacking — and tools are how that understanding gets handed to the next person.
- 🔭 Building Athena - open-core, source-available C5ISR + OODA autonomous red-team platform (Rust): an LLM-driven OODA loop that picks the next target and technique, with scope / opsec / rules-of-engagement gates welded into the execution path
- athena-sdk - Apache-2.0 Rust contract traits for hot-pluggable OODA modules
- athena-tools - Apache-2.0 data-driven MCP tool catalog ("add tools without touching the core")
- 📐 Created AI-SOP-Protocol - compiles your dev playbook into guardrails Claude auto-loads every session (TDD, ADRs, commit gates, release checks); v5 three-tier maturity + G1–G6 quality gates, shipped as a Claude Code plugin
- 🛡️ Taiwan security content automation
- security-weekly-mcp - MCP Server-powered security weekly report (32 intl & TW sources)
- security-glossary-tw - Taiwan cybersecurity terminology, 470+ standardized terms
- 🌐 Security Glossary site - Searchable web glossary of 470+ Taiwan security terms
- 🧰 AI tooling — skills, registries and research for agent-assisted work
- starseam - personal design system shipped as a shadcn registry — plates rivetted by stars, first-class Traditional Chinese typography; this blog wears it
- Ghidra-MCP-WSL-Auto - one-click Ghidra + GhidraMCP on WSL2 — an AI-assisted reverse engineering setup for security researchers
- skill-quality-research - star-gradient analysis across 97 Agent Skill repos: popularity tracks installability, not craft — ships a runnable skill-reviewer
- Claude Code skills — writing rules and recipes I actually use: talk-craft · slidev-deck-stack · visual-web-stack
- 🔧 Tooling — smaller things that solved one specific problem
- outline-terraform-aws - deploys Outline Wiki on AWS with Terraform and Ansible
- zst2vmdk - converts Zstandard-compressed VMA files to VMDK for virtual machine migrations
- extension-guard - VS Code extension supply chain security scanner
Offensive tooling Metasploit · Cobalt Strike · Burp Suite · BloodHound · Mimikatz · Impacket · Nuclei
Cloud & containers ·
·
· AWS · Azure
Focus areas Red Team · Penetration Testing · Cloud Security · Zero Trust · Supply Chain Security · Reverse Engineering
GitHub · LinkedIn · Credly · Blog
"Stay curious, stay paranoid."




