Note
I build sharp, single-purpose tools — mostly in Rust, sometimes in Go or Zig. Security scanners, developer utilities, AI infrastructure, and the occasional absurd experiment. 560+ public repos. Everything ships.
gitmesh.app · don@codetestcode.io · linkedin
I'm a systems-level software engineer focused on security tooling, developer infrastructure, and AI-native systems. Most of my work lives at the intersection of offensive security, protocol engineering, and CLI design — shipping single-binary tools with minimal dependencies that solve one problem well.
- Security research — building distributed scanners, web fuzzers, OSINT frameworks, and adversarial evaluation harnesses for LLMs
- Developer tools — self-hosted tunnel servers, webhook inspectors, credential managers, and CI/CD automation
- AI infrastructure — Model Context Protocol (MCP) servers, sampling policy engines, and DSLs for composable AI systems
- Systems programming — Rust-first, with production work in Go, Zig, Python, TypeScript, and Nim
- Open source — 560+ public repositories, all original tools designed to be auditable and forkable
I care about software that is small, correct, and observable. If it can't be deployed with scp and run without a runtime, it's probably too complicated.
Rust Go Zig Python TypeScript Nim Shell Docker PostgreSQL Redis SQLite
| Repository | Description | Language |
|---|---|---|
| fatt | Distributed async scanner for exposed files across millions of domains | |
| fuf | Fast next-generation web fuzzer | |
| blsmesh | Distributed adversarial behavioral security evaluation for LLMs | |
| robin-smesh | Decentralized dark web OSINT framework — Tor crawling, artifact extraction | |
| thinksec | Curated collection of security skill files for expert workflows | |
| chrono-dance-showcase | Temporal threat detection engine for security analysts | — |
| Repository | Description | Language |
|---|---|---|
| hook-bin | Single-binary webhook inbox — embedded SQLite, live dashboard, zero deps | |
| zgrok | Self-hosted ngrok alternative built on Tokio | |
| corey | CLI for managing GitHub credentials, secrets, and variables | |
| print-service-go | HTML-to-PDF conversion service with advanced rendering | |
| workflow-showcase | Minimal app showcasing powerful GitHub Actions CI/CD patterns | |
| pdfvec | High-performance PDF text extraction for vectorization pipelines | — |
| Repository | Description | Language |
|---|---|---|
| sigmos | DSL for defining AI-native, composable, reactive systems | |
| mcp-flow | WebTransport binding for MCP — QUIC streams, no head-of-line blocking | |
| nektor | AI-native sampling policy engine for Honeycomb Refinery | |
| polymcp | MCP server for the Polygon.io financial data API | |
| sk1llz | Legendary engineer philosophies encoded as Anthropic-compatible Skills |
| Repository | Description | Language |
|---|---|---|
| humanlang | Token bucket rate limiter implemented in 37 languages (1957–2016) | |
| gen3s1s | Synthetic world generator compiled from declarative Genesis files | |
| kirsch | Content fingerprinting & provenance engine — CLIP ViT-B/32, ONNX | |
| nimtrace | Zero-cost structured tracing framework for Nim | |
| toon-zig | TOON (Token-Oriented Object Notation) — 30-60% token reduction for LLMs | |
| gitfoo_episode_1 | Git Black Belt Masterclass — the other 90% of git most devs never use | |
| OverHelloWorld | Intentionally over-engineered Hello World — DDD, CQRS, event sourcing, telemetry | |
| vibe-rules-collection | Curated rules for AI coding assistants1 |
Footnotes
-
45 stars — the most-starred original repo in the collection. ↩






