View glatinone's full-sized avatar

Block or report glatinone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
glatinone/README.md

Kiell Tampubolon

AI Security & Agent Infrastructure Engineer · Singapore

Website · LinkedIn


Focus

I work at the intersection of LLM reasoning, MCP tooling, and SOC automation — building the security layer agentic systems need before they're trusted with real infrastructure, and building agents that do SOC work directly.


Core Systems

🛡️ mcpscan

Supply-chain security scanner for MCP servers & Claude Code projects. Problem: MCP servers ship with zero standard vetting — tool-poisoning, command injection, over-broad permissions, and leaked secrets go straight into .claude/ directories. Stack: Python, zero runtime deps, SARIF 2.1.0 output for GitHub code scanning, CI-ready. Status: active, CI-ready

AI-powered vulnerability intelligence scanner. Problem: dependency vulnerability lists are noisy — a CVE hit doesn't tell you what's actually exploitable in your usage. Stack: Python · OSV.dev lookups across 7 ecosystems (Python, Node, Go, Maven, Ruby, NuGet, Rust) · LLM-backed exploitability + remediation analysis. Status: active

Local-first browser memory, accessible by Claude. Problem: Claude has no memory of what you've browsed — you re-explain context every session. Stack: TypeScript · browser extension + MCP server · fully local, no cloud sync. Status: shipped, v0.2.0

MCP server exposing defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo command-shadowing checks. Status: active

AI-powered SOC built entirely on Microsoft infrastructure — no Sentinel, no third-party SIEM. Problem: most SOC automation assumes a SIEM budget teams don't have. Stack: Copilot Studio · Power Automate · Microsoft Graph API · 5 coordinating agents (identity threat, phishing investigation, compliance/audit, SOC summary, orchestrator). Status: active

Open protocol for AI agent memory interoperability — like MCP, but for memory. Problem: every agent framework reinvents memory storage; nothing shares across vendors or sessions. Stack: HTTP-native spec · Memory Cell schema · access control · decay-ranked semantic search · active→stale→archived lifecycle. Status: spec stage, pre-PyPI


Ecosystem Contributions

Merged upstream:

PRProjectChange
#4125zalando/skipperIsolated + applied 30s timeout to upgrade proxy dialer
#5817gpustack/gpustackPropagated asyncio cancellation, removed mutable default args
#2725teamhanko/hankoRefactored OAuth providers to propagate context, fixed duplicate defer
#40kerlenton/mcpsnoopAdded stdin-piped session support

Also tracking the MCP ecosystem via awesome-mcp-servers.


Labs

RepoWhat it does
sentinelscoutMulti-source OSINT aggregator — VirusTotal, AlienVault OTX, Shodan, NVD, GitHub — with AI correlation
autoreviewAI-powered PR code review CLI, multi-LLM (OpenAI, DeepSeek, Claude, Ollama)
streamblind-pocPoC + fix for asynchronous telemetry blindness & state desync in AI streaming clients
claude-token-monitor-usageLocal-first desktop HUD for Claude.ai / Claude Code quota and token-cost tracking
dev-to-mcpMCP server for the dev.to API — browsing, challenge tracking, authenticated publishing
devto-challenge-agentMulti-agent system for dev.to challenge research, writing, and performance tracking
nexora-second-brainAI-powered second brain on Notion, Claude as the intelligence layer

Engineering Evolution

PeriodRepositoryContext & FootprintStack
2022BARELANG-MRT / B-MRT.github.ioTeam site for a robotics competition entry (archived)HTML
2023Keamanan-Basis-DataDatabase security coursework, published (archived)
2024e_logbookLogbook web app (archived)PHP
2025security-automation-notesScripts for repetitive security tasks — email analysis, log review, system checksShell
2025cybersecurity-communication-guideInteractive guide for explaining security concepts to non-technical audiencesTypeScript, React
2025phising101-kielPhishing awareness reference materialJavaScript
2025–26Freelance client builds — deddy-tour-travel-premier, malay-rental-batam, 4care_medicalcentre, magal-restaurant, stefan-music-learnClient-commissioned sites (private)Next.js / TypeScript
2026ai-webinar-itdelPresentation materials for an AI-in-industry webinar at Institut Teknologi DelTypeScript
2026personal-portfolioEarlier Next.js personal site — superseded by the live Astro build at kielltampubolon.id (archived)TypeScript
2026devto-autopublishAutomated publishing pipeline for dev.toJavaScript
2026nebula-drift / solstice-gameBrowser games, zero dependenciesJavaScript / HTML
2026gmaps-extractorChrome extension for B2B lead extraction from Google Maps (private)JavaScript
2026automation-loganHR clock-in/out automation bot, VPS + Cloudflare Workers deploy targets (private)Python / JavaScript

(Earlier school/web projects and one-off client sites not listed here remain visible in the full repository list.)

Pinned Loading

  1. BraveMCPBraveMCPPublic

    Local-first MCP server that gives Claude Desktop searchable memory of your browsing history — pages, bookmarks, highlights, notes.

    TypeScript 1 1

  2. agent-memory-protocolagent-memory-protocolPublic

    AMP: An open protocol for AI agent memory — like MCP, but for memory

    Python

  3. secops-toolkit-mcpsecops-toolkit-mcpPublic

    An MCP server of local, defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo-root command-shadowing and symlink-escape checks, and shell command safet…

    Python

  4. mcpscanmcpscanPublic

    Supply-chain security scanner for MCP servers & Claude Code projects — catch tool-poisoning, command injection & risky permissions before you install. Zero deps.

    Python

  5. vulnscanvulnscanPublic

    AI-powered vulnerability scanner — OSV.dev lookups across 7 ecosystems plus LLM-generated exploitability analysis and fixes.

    Python

  6. soc-copilotstudiosoc-copilotstudioPublic

    AI-powered SOC built on Microsoft Copilot Studio, Power Automate & Graph API — no Sentinel, no third-party SIEM.

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
View glatinone's full-sized avatar

Block or report glatinone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
glatinone/README.md

Kiell Tampubolon

AI Security & Agent Infrastructure Engineer · Singapore

Website · LinkedIn


Focus

I work at the intersection of LLM reasoning, MCP tooling, and SOC automation — building the security layer agentic systems need before they're trusted with real infrastructure, and building agents that do SOC work directly.


Core Systems

🛡️ mcpscan

Supply-chain security scanner for MCP servers & Claude Code projects. Problem: MCP servers ship with zero standard vetting — tool-poisoning, command injection, over-broad permissions, and leaked secrets go straight into .claude/ directories. Stack: Python, zero runtime deps, SARIF 2.1.0 output for GitHub code scanning, CI-ready. Status: active, CI-ready

AI-powered vulnerability intelligence scanner. Problem: dependency vulnerability lists are noisy — a CVE hit doesn't tell you what's actually exploitable in your usage. Stack: Python · OSV.dev lookups across 7 ecosystems (Python, Node, Go, Maven, Ruby, NuGet, Rust) · LLM-backed exploitability + remediation analysis. Status: active

Local-first browser memory, accessible by Claude. Problem: Claude has no memory of what you've browsed — you re-explain context every session. Stack: TypeScript · browser extension + MCP server · fully local, no cloud sync. Status: shipped, v0.2.0

MCP server exposing defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo command-shadowing checks. Status: active

AI-powered SOC built entirely on Microsoft infrastructure — no Sentinel, no third-party SIEM. Problem: most SOC automation assumes a SIEM budget teams don't have. Stack: Copilot Studio · Power Automate · Microsoft Graph API · 5 coordinating agents (identity threat, phishing investigation, compliance/audit, SOC summary, orchestrator). Status: active

Open protocol for AI agent memory interoperability — like MCP, but for memory. Problem: every agent framework reinvents memory storage; nothing shares across vendors or sessions. Stack: HTTP-native spec · Memory Cell schema · access control · decay-ranked semantic search · active→stale→archived lifecycle. Status: spec stage, pre-PyPI


Ecosystem Contributions

Merged upstream:

PRProjectChange
#4125zalando/skipperIsolated + applied 30s timeout to upgrade proxy dialer
#5817gpustack/gpustackPropagated asyncio cancellation, removed mutable default args
#2725teamhanko/hankoRefactored OAuth providers to propagate context, fixed duplicate defer
#40kerlenton/mcpsnoopAdded stdin-piped session support

Also tracking the MCP ecosystem via awesome-mcp-servers.


Labs

RepoWhat it does
sentinelscoutMulti-source OSINT aggregator — VirusTotal, AlienVault OTX, Shodan, NVD, GitHub — with AI correlation
autoreviewAI-powered PR code review CLI, multi-LLM (OpenAI, DeepSeek, Claude, Ollama)
streamblind-pocPoC + fix for asynchronous telemetry blindness & state desync in AI streaming clients
claude-token-monitor-usageLocal-first desktop HUD for Claude.ai / Claude Code quota and token-cost tracking
dev-to-mcpMCP server for the dev.to API — browsing, challenge tracking, authenticated publishing
devto-challenge-agentMulti-agent system for dev.to challenge research, writing, and performance tracking
nexora-second-brainAI-powered second brain on Notion, Claude as the intelligence layer

Engineering Evolution

PeriodRepositoryContext & FootprintStack
2022BARELANG-MRT / B-MRT.github.ioTeam site for a robotics competition entry (archived)HTML
2023Keamanan-Basis-DataDatabase security coursework, published (archived)
2024e_logbookLogbook web app (archived)PHP
2025security-automation-notesScripts for repetitive security tasks — email analysis, log review, system checksShell
2025cybersecurity-communication-guideInteractive guide for explaining security concepts to non-technical audiencesTypeScript, React
2025phising101-kielPhishing awareness reference materialJavaScript
2025–26Freelance client builds — deddy-tour-travel-premier, malay-rental-batam, 4care_medicalcentre, magal-restaurant, stefan-music-learnClient-commissioned sites (private)Next.js / TypeScript
2026ai-webinar-itdelPresentation materials for an AI-in-industry webinar at Institut Teknologi DelTypeScript
2026personal-portfolioEarlier Next.js personal site — superseded by the live Astro build at kielltampubolon.id (archived)TypeScript
2026devto-autopublishAutomated publishing pipeline for dev.toJavaScript
2026nebula-drift / solstice-gameBrowser games, zero dependenciesJavaScript / HTML
2026gmaps-extractorChrome extension for B2B lead extraction from Google Maps (private)JavaScript
2026automation-loganHR clock-in/out automation bot, VPS + Cloudflare Workers deploy targets (private)Python / JavaScript

(Earlier school/web projects and one-off client sites not listed here remain visible in the full repository list.)

Pinned Loading

  1. BraveMCPBraveMCPPublic

    Local-first MCP server that gives Claude Desktop searchable memory of your browsing history — pages, bookmarks, highlights, notes.

    TypeScript 1 1

  2. agent-memory-protocolagent-memory-protocolPublic

    AMP: An open protocol for AI agent memory — like MCP, but for memory

    Python

  3. secops-toolkit-mcpsecops-toolkit-mcpPublic

    An MCP server of local, defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo-root command-shadowing and symlink-escape checks, and shell command safet…

    Python

  4. mcpscanmcpscanPublic

    Supply-chain security scanner for MCP servers & Claude Code projects — catch tool-poisoning, command injection & risky permissions before you install. Zero deps.

    Python

  5. vulnscanvulnscanPublic

    AI-powered vulnerability scanner — OSV.dev lookups across 7 ecosystems plus LLM-generated exploitability analysis and fixes.

    Python

  6. soc-copilotstudiosoc-copilotstudioPublic

    AI-powered SOC built on Microsoft Copilot Studio, Power Automate & Graph API — no Sentinel, no third-party SIEM.

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View glatinone's full-sized avatar

Block or report glatinone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
glatinone/README.md

Kiell Tampubolon

AI Security & Agent Infrastructure Engineer · Singapore

Website · LinkedIn


Focus

I work at the intersection of LLM reasoning, MCP tooling, and SOC automation — building the security layer agentic systems need before they're trusted with real infrastructure, and building agents that do SOC work directly.


Core Systems

🛡️ mcpscan

Supply-chain security scanner for MCP servers & Claude Code projects. Problem: MCP servers ship with zero standard vetting — tool-poisoning, command injection, over-broad permissions, and leaked secrets go straight into .claude/ directories. Stack: Python, zero runtime deps, SARIF 2.1.0 output for GitHub code scanning, CI-ready. Status: active, CI-ready

AI-powered vulnerability intelligence scanner. Problem: dependency vulnerability lists are noisy — a CVE hit doesn't tell you what's actually exploitable in your usage. Stack: Python · OSV.dev lookups across 7 ecosystems (Python, Node, Go, Maven, Ruby, NuGet, Rust) · LLM-backed exploitability + remediation analysis. Status: active

Local-first browser memory, accessible by Claude. Problem: Claude has no memory of what you've browsed — you re-explain context every session. Stack: TypeScript · browser extension + MCP server · fully local, no cloud sync. Status: shipped, v0.2.0

MCP server exposing defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo command-shadowing checks. Status: active

AI-powered SOC built entirely on Microsoft infrastructure — no Sentinel, no third-party SIEM. Problem: most SOC automation assumes a SIEM budget teams don't have. Stack: Copilot Studio · Power Automate · Microsoft Graph API · 5 coordinating agents (identity threat, phishing investigation, compliance/audit, SOC summary, orchestrator). Status: active

Open protocol for AI agent memory interoperability — like MCP, but for memory. Problem: every agent framework reinvents memory storage; nothing shares across vendors or sessions. Stack: HTTP-native spec · Memory Cell schema · access control · decay-ranked semantic search · active→stale→archived lifecycle. Status: spec stage, pre-PyPI


Ecosystem Contributions

Merged upstream:

PRProjectChange
#4125zalando/skipperIsolated + applied 30s timeout to upgrade proxy dialer
#5817gpustack/gpustackPropagated asyncio cancellation, removed mutable default args
#2725teamhanko/hankoRefactored OAuth providers to propagate context, fixed duplicate defer
#40kerlenton/mcpsnoopAdded stdin-piped session support

Also tracking the MCP ecosystem via awesome-mcp-servers.


Labs

RepoWhat it does
sentinelscoutMulti-source OSINT aggregator — VirusTotal, AlienVault OTX, Shodan, NVD, GitHub — with AI correlation
autoreviewAI-powered PR code review CLI, multi-LLM (OpenAI, DeepSeek, Claude, Ollama)
streamblind-pocPoC + fix for asynchronous telemetry blindness & state desync in AI streaming clients
claude-token-monitor-usageLocal-first desktop HUD for Claude.ai / Claude Code quota and token-cost tracking
dev-to-mcpMCP server for the dev.to API — browsing, challenge tracking, authenticated publishing
devto-challenge-agentMulti-agent system for dev.to challenge research, writing, and performance tracking
nexora-second-brainAI-powered second brain on Notion, Claude as the intelligence layer

Engineering Evolution

PeriodRepositoryContext & FootprintStack
2022BARELANG-MRT / B-MRT.github.ioTeam site for a robotics competition entry (archived)HTML
2023Keamanan-Basis-DataDatabase security coursework, published (archived)
2024e_logbookLogbook web app (archived)PHP
2025security-automation-notesScripts for repetitive security tasks — email analysis, log review, system checksShell
2025cybersecurity-communication-guideInteractive guide for explaining security concepts to non-technical audiencesTypeScript, React
2025phising101-kielPhishing awareness reference materialJavaScript
2025–26Freelance client builds — deddy-tour-travel-premier, malay-rental-batam, 4care_medicalcentre, magal-restaurant, stefan-music-learnClient-commissioned sites (private)Next.js / TypeScript
2026ai-webinar-itdelPresentation materials for an AI-in-industry webinar at Institut Teknologi DelTypeScript
2026personal-portfolioEarlier Next.js personal site — superseded by the live Astro build at kielltampubolon.id (archived)TypeScript
2026devto-autopublishAutomated publishing pipeline for dev.toJavaScript
2026nebula-drift / solstice-gameBrowser games, zero dependenciesJavaScript / HTML
2026gmaps-extractorChrome extension for B2B lead extraction from Google Maps (private)JavaScript
2026automation-loganHR clock-in/out automation bot, VPS + Cloudflare Workers deploy targets (private)Python / JavaScript

(Earlier school/web projects and one-off client sites not listed here remain visible in the full repository list.)

Pinned Loading

  1. BraveMCPBraveMCPPublic

    Local-first MCP server that gives Claude Desktop searchable memory of your browsing history — pages, bookmarks, highlights, notes.

    TypeScript 1 1

  2. agent-memory-protocolagent-memory-protocolPublic

    AMP: An open protocol for AI agent memory — like MCP, but for memory

    Python

  3. secops-toolkit-mcpsecops-toolkit-mcpPublic

    An MCP server of local, defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo-root command-shadowing and symlink-escape checks, and shell command safet…

    Python

  4. mcpscanmcpscanPublic

    Supply-chain security scanner for MCP servers & Claude Code projects — catch tool-poisoning, command injection & risky permissions before you install. Zero deps.

    Python

  5. vulnscanvulnscanPublic

    AI-powered vulnerability scanner — OSV.dev lookups across 7 ecosystems plus LLM-generated exploitability analysis and fixes.

    Python

  6. soc-copilotstudiosoc-copilotstudioPublic

    AI-powered SOC built on Microsoft Copilot Studio, Power Automate & Graph API — no Sentinel, no third-party SIEM.

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View glatinone's full-sized avatar

Block or report glatinone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
glatinone/README.md

Kiell Tampubolon

AI Security & Agent Infrastructure Engineer · Singapore

Website · LinkedIn


Focus

I work at the intersection of LLM reasoning, MCP tooling, and SOC automation — building the security layer agentic systems need before they're trusted with real infrastructure, and building agents that do SOC work directly.


Core Systems

🛡️ mcpscan

Supply-chain security scanner for MCP servers & Claude Code projects. Problem: MCP servers ship with zero standard vetting — tool-poisoning, command injection, over-broad permissions, and leaked secrets go straight into .claude/ directories. Stack: Python, zero runtime deps, SARIF 2.1.0 output for GitHub code scanning, CI-ready. Status: active, CI-ready

AI-powered vulnerability intelligence scanner. Problem: dependency vulnerability lists are noisy — a CVE hit doesn't tell you what's actually exploitable in your usage. Stack: Python · OSV.dev lookups across 7 ecosystems (Python, Node, Go, Maven, Ruby, NuGet, Rust) · LLM-backed exploitability + remediation analysis. Status: active

Local-first browser memory, accessible by Claude. Problem: Claude has no memory of what you've browsed — you re-explain context every session. Stack: TypeScript · browser extension + MCP server · fully local, no cloud sync. Status: shipped, v0.2.0

MCP server exposing defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo command-shadowing checks. Status: active

AI-powered SOC built entirely on Microsoft infrastructure — no Sentinel, no third-party SIEM. Problem: most SOC automation assumes a SIEM budget teams don't have. Stack: Copilot Studio · Power Automate · Microsoft Graph API · 5 coordinating agents (identity threat, phishing investigation, compliance/audit, SOC summary, orchestrator). Status: active

Open protocol for AI agent memory interoperability — like MCP, but for memory. Problem: every agent framework reinvents memory storage; nothing shares across vendors or sessions. Stack: HTTP-native spec · Memory Cell schema · access control · decay-ranked semantic search · active→stale→archived lifecycle. Status: spec stage, pre-PyPI


Ecosystem Contributions

Merged upstream:

PRProjectChange
#4125zalando/skipperIsolated + applied 30s timeout to upgrade proxy dialer
#5817gpustack/gpustackPropagated asyncio cancellation, removed mutable default args
#2725teamhanko/hankoRefactored OAuth providers to propagate context, fixed duplicate defer
#40kerlenton/mcpsnoopAdded stdin-piped session support

Also tracking the MCP ecosystem via awesome-mcp-servers.


Labs

RepoWhat it does
sentinelscoutMulti-source OSINT aggregator — VirusTotal, AlienVault OTX, Shodan, NVD, GitHub — with AI correlation
autoreviewAI-powered PR code review CLI, multi-LLM (OpenAI, DeepSeek, Claude, Ollama)
streamblind-pocPoC + fix for asynchronous telemetry blindness & state desync in AI streaming clients
claude-token-monitor-usageLocal-first desktop HUD for Claude.ai / Claude Code quota and token-cost tracking
dev-to-mcpMCP server for the dev.to API — browsing, challenge tracking, authenticated publishing
devto-challenge-agentMulti-agent system for dev.to challenge research, writing, and performance tracking
nexora-second-brainAI-powered second brain on Notion, Claude as the intelligence layer

Engineering Evolution

PeriodRepositoryContext & FootprintStack
2022BARELANG-MRT / B-MRT.github.ioTeam site for a robotics competition entry (archived)HTML
2023Keamanan-Basis-DataDatabase security coursework, published (archived)
2024e_logbookLogbook web app (archived)PHP
2025security-automation-notesScripts for repetitive security tasks — email analysis, log review, system checksShell
2025cybersecurity-communication-guideInteractive guide for explaining security concepts to non-technical audiencesTypeScript, React
2025phising101-kielPhishing awareness reference materialJavaScript
2025–26Freelance client builds — deddy-tour-travel-premier, malay-rental-batam, 4care_medicalcentre, magal-restaurant, stefan-music-learnClient-commissioned sites (private)Next.js / TypeScript
2026ai-webinar-itdelPresentation materials for an AI-in-industry webinar at Institut Teknologi DelTypeScript
2026personal-portfolioEarlier Next.js personal site — superseded by the live Astro build at kielltampubolon.id (archived)TypeScript
2026devto-autopublishAutomated publishing pipeline for dev.toJavaScript
2026nebula-drift / solstice-gameBrowser games, zero dependenciesJavaScript / HTML
2026gmaps-extractorChrome extension for B2B lead extraction from Google Maps (private)JavaScript
2026automation-loganHR clock-in/out automation bot, VPS + Cloudflare Workers deploy targets (private)Python / JavaScript

(Earlier school/web projects and one-off client sites not listed here remain visible in the full repository list.)

Pinned Loading

  1. BraveMCPBraveMCPPublic

    Local-first MCP server that gives Claude Desktop searchable memory of your browsing history — pages, bookmarks, highlights, notes.

    TypeScript 1 1

  2. agent-memory-protocolagent-memory-protocolPublic

    AMP: An open protocol for AI agent memory — like MCP, but for memory

    Python

  3. secops-toolkit-mcpsecops-toolkit-mcpPublic

    An MCP server of local, defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo-root command-shadowing and symlink-escape checks, and shell command safet…

    Python

  4. mcpscanmcpscanPublic

    Supply-chain security scanner for MCP servers & Claude Code projects — catch tool-poisoning, command injection & risky permissions before you install. Zero deps.

    Python

  5. vulnscanvulnscanPublic

    AI-powered vulnerability scanner — OSV.dev lookups across 7 ecosystems plus LLM-generated exploitability analysis and fixes.

    Python

  6. soc-copilotstudiosoc-copilotstudioPublic

    AI-powered SOC built on Microsoft Copilot Studio, Power Automate & Graph API — no Sentinel, no third-party SIEM.

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
View glatinone's full-sized avatar

Block or report glatinone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
glatinone/README.md

Kiell Tampubolon

AI Security & Agent Infrastructure Engineer · Singapore

Website · LinkedIn


Focus

I work at the intersection of LLM reasoning, MCP tooling, and SOC automation — building the security layer agentic systems need before they're trusted with real infrastructure, and building agents that do SOC work directly.


Core Systems

🛡️ mcpscan

Supply-chain security scanner for MCP servers & Claude Code projects. Problem: MCP servers ship with zero standard vetting — tool-poisoning, command injection, over-broad permissions, and leaked secrets go straight into .claude/ directories. Stack: Python, zero runtime deps, SARIF 2.1.0 output for GitHub code scanning, CI-ready. Status: active, CI-ready

AI-powered vulnerability intelligence scanner. Problem: dependency vulnerability lists are noisy — a CVE hit doesn't tell you what's actually exploitable in your usage. Stack: Python · OSV.dev lookups across 7 ecosystems (Python, Node, Go, Maven, Ruby, NuGet, Rust) · LLM-backed exploitability + remediation analysis. Status: active

Local-first browser memory, accessible by Claude. Problem: Claude has no memory of what you've browsed — you re-explain context every session. Stack: TypeScript · browser extension + MCP server · fully local, no cloud sync. Status: shipped, v0.2.0

MCP server exposing defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo command-shadowing checks. Status: active

AI-powered SOC built entirely on Microsoft infrastructure — no Sentinel, no third-party SIEM. Problem: most SOC automation assumes a SIEM budget teams don't have. Stack: Copilot Studio · Power Automate · Microsoft Graph API · 5 coordinating agents (identity threat, phishing investigation, compliance/audit, SOC summary, orchestrator). Status: active

Open protocol for AI agent memory interoperability — like MCP, but for memory. Problem: every agent framework reinvents memory storage; nothing shares across vendors or sessions. Stack: HTTP-native spec · Memory Cell schema · access control · decay-ranked semantic search · active→stale→archived lifecycle. Status: spec stage, pre-PyPI


Ecosystem Contributions

Merged upstream:

PRProjectChange
#4125zalando/skipperIsolated + applied 30s timeout to upgrade proxy dialer
#5817gpustack/gpustackPropagated asyncio cancellation, removed mutable default args
#2725teamhanko/hankoRefactored OAuth providers to propagate context, fixed duplicate defer
#40kerlenton/mcpsnoopAdded stdin-piped session support

Also tracking the MCP ecosystem via awesome-mcp-servers.


Labs

RepoWhat it does
sentinelscoutMulti-source OSINT aggregator — VirusTotal, AlienVault OTX, Shodan, NVD, GitHub — with AI correlation
autoreviewAI-powered PR code review CLI, multi-LLM (OpenAI, DeepSeek, Claude, Ollama)
streamblind-pocPoC + fix for asynchronous telemetry blindness & state desync in AI streaming clients
claude-token-monitor-usageLocal-first desktop HUD for Claude.ai / Claude Code quota and token-cost tracking
dev-to-mcpMCP server for the dev.to API — browsing, challenge tracking, authenticated publishing
devto-challenge-agentMulti-agent system for dev.to challenge research, writing, and performance tracking
nexora-second-brainAI-powered second brain on Notion, Claude as the intelligence layer

Engineering Evolution

PeriodRepositoryContext & FootprintStack
2022BARELANG-MRT / B-MRT.github.ioTeam site for a robotics competition entry (archived)HTML
2023Keamanan-Basis-DataDatabase security coursework, published (archived)
2024e_logbookLogbook web app (archived)PHP
2025security-automation-notesScripts for repetitive security tasks — email analysis, log review, system checksShell
2025cybersecurity-communication-guideInteractive guide for explaining security concepts to non-technical audiencesTypeScript, React
2025phising101-kielPhishing awareness reference materialJavaScript
2025–26Freelance client builds — deddy-tour-travel-premier, malay-rental-batam, 4care_medicalcentre, magal-restaurant, stefan-music-learnClient-commissioned sites (private)Next.js / TypeScript
2026ai-webinar-itdelPresentation materials for an AI-in-industry webinar at Institut Teknologi DelTypeScript
2026personal-portfolioEarlier Next.js personal site — superseded by the live Astro build at kielltampubolon.id (archived)TypeScript
2026devto-autopublishAutomated publishing pipeline for dev.toJavaScript
2026nebula-drift / solstice-gameBrowser games, zero dependenciesJavaScript / HTML
2026gmaps-extractorChrome extension for B2B lead extraction from Google Maps (private)JavaScript
2026automation-loganHR clock-in/out automation bot, VPS + Cloudflare Workers deploy targets (private)Python / JavaScript

(Earlier school/web projects and one-off client sites not listed here remain visible in the full repository list.)

Pinned Loading

  1. BraveMCPBraveMCPPublic

    Local-first MCP server that gives Claude Desktop searchable memory of your browsing history — pages, bookmarks, highlights, notes.

    TypeScript 1 1

  2. agent-memory-protocolagent-memory-protocolPublic

    AMP: An open protocol for AI agent memory — like MCP, but for memory

    Python

  3. secops-toolkit-mcpsecops-toolkit-mcpPublic

    An MCP server of local, defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo-root command-shadowing and symlink-escape checks, and shell command safet…

    Python

  4. mcpscanmcpscanPublic

    Supply-chain security scanner for MCP servers & Claude Code projects — catch tool-poisoning, command injection & risky permissions before you install. Zero deps.

    Python

  5. vulnscanvulnscanPublic

    AI-powered vulnerability scanner — OSV.dev lookups across 7 ecosystems plus LLM-generated exploitability analysis and fixes.

    Python

  6. soc-copilotstudiosoc-copilotstudioPublic

    AI-powered SOC built on Microsoft Copilot Studio, Power Automate & Graph API — no Sentinel, no third-party SIEM.

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View glatinone's full-sized avatar

Block or report glatinone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
glatinone/README.md

Kiell Tampubolon

AI Security & Agent Infrastructure Engineer · Singapore

Website · LinkedIn


Focus

I work at the intersection of LLM reasoning, MCP tooling, and SOC automation — building the security layer agentic systems need before they're trusted with real infrastructure, and building agents that do SOC work directly.


Core Systems

🛡️ mcpscan

Supply-chain security scanner for MCP servers & Claude Code projects. Problem: MCP servers ship with zero standard vetting — tool-poisoning, command injection, over-broad permissions, and leaked secrets go straight into .claude/ directories. Stack: Python, zero runtime deps, SARIF 2.1.0 output for GitHub code scanning, CI-ready. Status: active, CI-ready

AI-powered vulnerability intelligence scanner. Problem: dependency vulnerability lists are noisy — a CVE hit doesn't tell you what's actually exploitable in your usage. Stack: Python · OSV.dev lookups across 7 ecosystems (Python, Node, Go, Maven, Ruby, NuGet, Rust) · LLM-backed exploitability + remediation analysis. Status: active

Local-first browser memory, accessible by Claude. Problem: Claude has no memory of what you've browsed — you re-explain context every session. Stack: TypeScript · browser extension + MCP server · fully local, no cloud sync. Status: shipped, v0.2.0

MCP server exposing defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo command-shadowing checks. Status: active

AI-powered SOC built entirely on Microsoft infrastructure — no Sentinel, no third-party SIEM. Problem: most SOC automation assumes a SIEM budget teams don't have. Stack: Copilot Studio · Power Automate · Microsoft Graph API · 5 coordinating agents (identity threat, phishing investigation, compliance/audit, SOC summary, orchestrator). Status: active

Open protocol for AI agent memory interoperability — like MCP, but for memory. Problem: every agent framework reinvents memory storage; nothing shares across vendors or sessions. Stack: HTTP-native spec · Memory Cell schema · access control · decay-ranked semantic search · active→stale→archived lifecycle. Status: spec stage, pre-PyPI


Ecosystem Contributions

Merged upstream:

PRProjectChange
#4125zalando/skipperIsolated + applied 30s timeout to upgrade proxy dialer
#5817gpustack/gpustackPropagated asyncio cancellation, removed mutable default args
#2725teamhanko/hankoRefactored OAuth providers to propagate context, fixed duplicate defer
#40kerlenton/mcpsnoopAdded stdin-piped session support

Also tracking the MCP ecosystem via awesome-mcp-servers.


Labs

RepoWhat it does
sentinelscoutMulti-source OSINT aggregator — VirusTotal, AlienVault OTX, Shodan, NVD, GitHub — with AI correlation
autoreviewAI-powered PR code review CLI, multi-LLM (OpenAI, DeepSeek, Claude, Ollama)
streamblind-pocPoC + fix for asynchronous telemetry blindness & state desync in AI streaming clients
claude-token-monitor-usageLocal-first desktop HUD for Claude.ai / Claude Code quota and token-cost tracking
dev-to-mcpMCP server for the dev.to API — browsing, challenge tracking, authenticated publishing
devto-challenge-agentMulti-agent system for dev.to challenge research, writing, and performance tracking
nexora-second-brainAI-powered second brain on Notion, Claude as the intelligence layer

Engineering Evolution

PeriodRepositoryContext & FootprintStack
2022BARELANG-MRT / B-MRT.github.ioTeam site for a robotics competition entry (archived)HTML
2023Keamanan-Basis-DataDatabase security coursework, published (archived)
2024e_logbookLogbook web app (archived)PHP
2025security-automation-notesScripts for repetitive security tasks — email analysis, log review, system checksShell
2025cybersecurity-communication-guideInteractive guide for explaining security concepts to non-technical audiencesTypeScript, React
2025phising101-kielPhishing awareness reference materialJavaScript
2025–26Freelance client builds — deddy-tour-travel-premier, malay-rental-batam, 4care_medicalcentre, magal-restaurant, stefan-music-learnClient-commissioned sites (private)Next.js / TypeScript
2026ai-webinar-itdelPresentation materials for an AI-in-industry webinar at Institut Teknologi DelTypeScript
2026personal-portfolioEarlier Next.js personal site — superseded by the live Astro build at kielltampubolon.id (archived)TypeScript
2026devto-autopublishAutomated publishing pipeline for dev.toJavaScript
2026nebula-drift / solstice-gameBrowser games, zero dependenciesJavaScript / HTML
2026gmaps-extractorChrome extension for B2B lead extraction from Google Maps (private)JavaScript
2026automation-loganHR clock-in/out automation bot, VPS + Cloudflare Workers deploy targets (private)Python / JavaScript

(Earlier school/web projects and one-off client sites not listed here remain visible in the full repository list.)

Pinned Loading

  1. BraveMCPBraveMCPPublic

    Local-first MCP server that gives Claude Desktop searchable memory of your browsing history — pages, bookmarks, highlights, notes.

    TypeScript 1 1

  2. agent-memory-protocolagent-memory-protocolPublic

    AMP: An open protocol for AI agent memory — like MCP, but for memory

    Python

  3. secops-toolkit-mcpsecops-toolkit-mcpPublic

    An MCP server of local, defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo-root command-shadowing and symlink-escape checks, and shell command safet…

    Python

  4. mcpscanmcpscanPublic

    Supply-chain security scanner for MCP servers & Claude Code projects — catch tool-poisoning, command injection & risky permissions before you install. Zero deps.

    Python

  5. vulnscanvulnscanPublic

    AI-powered vulnerability scanner — OSV.dev lookups across 7 ecosystems plus LLM-generated exploitability analysis and fixes.

    Python

  6. soc-copilotstudiosoc-copilotstudioPublic

    AI-powered SOC built on Microsoft Copilot Studio, Power Automate & Graph API — no Sentinel, no third-party SIEM.

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View glatinone's full-sized avatar

Block or report glatinone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
glatinone/README.md

Kiell Tampubolon

AI Security & Agent Infrastructure Engineer · Singapore

Website · LinkedIn


Focus

I work at the intersection of LLM reasoning, MCP tooling, and SOC automation — building the security layer agentic systems need before they're trusted with real infrastructure, and building agents that do SOC work directly.


Core Systems

🛡️ mcpscan

Supply-chain security scanner for MCP servers & Claude Code projects. Problem: MCP servers ship with zero standard vetting — tool-poisoning, command injection, over-broad permissions, and leaked secrets go straight into .claude/ directories. Stack: Python, zero runtime deps, SARIF 2.1.0 output for GitHub code scanning, CI-ready. Status: active, CI-ready

AI-powered vulnerability intelligence scanner. Problem: dependency vulnerability lists are noisy — a CVE hit doesn't tell you what's actually exploitable in your usage. Stack: Python · OSV.dev lookups across 7 ecosystems (Python, Node, Go, Maven, Ruby, NuGet, Rust) · LLM-backed exploitability + remediation analysis. Status: active

Local-first browser memory, accessible by Claude. Problem: Claude has no memory of what you've browsed — you re-explain context every session. Stack: TypeScript · browser extension + MCP server · fully local, no cloud sync. Status: shipped, v0.2.0

MCP server exposing defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo command-shadowing checks. Status: active

AI-powered SOC built entirely on Microsoft infrastructure — no Sentinel, no third-party SIEM. Problem: most SOC automation assumes a SIEM budget teams don't have. Stack: Copilot Studio · Power Automate · Microsoft Graph API · 5 coordinating agents (identity threat, phishing investigation, compliance/audit, SOC summary, orchestrator). Status: active

Open protocol for AI agent memory interoperability — like MCP, but for memory. Problem: every agent framework reinvents memory storage; nothing shares across vendors or sessions. Stack: HTTP-native spec · Memory Cell schema · access control · decay-ranked semantic search · active→stale→archived lifecycle. Status: spec stage, pre-PyPI


Ecosystem Contributions

Merged upstream:

PRProjectChange
#4125zalando/skipperIsolated + applied 30s timeout to upgrade proxy dialer
#5817gpustack/gpustackPropagated asyncio cancellation, removed mutable default args
#2725teamhanko/hankoRefactored OAuth providers to propagate context, fixed duplicate defer
#40kerlenton/mcpsnoopAdded stdin-piped session support

Also tracking the MCP ecosystem via awesome-mcp-servers.


Labs

RepoWhat it does
sentinelscoutMulti-source OSINT aggregator — VirusTotal, AlienVault OTX, Shodan, NVD, GitHub — with AI correlation
autoreviewAI-powered PR code review CLI, multi-LLM (OpenAI, DeepSeek, Claude, Ollama)
streamblind-pocPoC + fix for asynchronous telemetry blindness & state desync in AI streaming clients
claude-token-monitor-usageLocal-first desktop HUD for Claude.ai / Claude Code quota and token-cost tracking
dev-to-mcpMCP server for the dev.to API — browsing, challenge tracking, authenticated publishing
devto-challenge-agentMulti-agent system for dev.to challenge research, writing, and performance tracking
nexora-second-brainAI-powered second brain on Notion, Claude as the intelligence layer

Engineering Evolution

PeriodRepositoryContext & FootprintStack
2022BARELANG-MRT / B-MRT.github.ioTeam site for a robotics competition entry (archived)HTML
2023Keamanan-Basis-DataDatabase security coursework, published (archived)
2024e_logbookLogbook web app (archived)PHP
2025security-automation-notesScripts for repetitive security tasks — email analysis, log review, system checksShell
2025cybersecurity-communication-guideInteractive guide for explaining security concepts to non-technical audiencesTypeScript, React
2025phising101-kielPhishing awareness reference materialJavaScript
2025–26Freelance client builds — deddy-tour-travel-premier, malay-rental-batam, 4care_medicalcentre, magal-restaurant, stefan-music-learnClient-commissioned sites (private)Next.js / TypeScript
2026ai-webinar-itdelPresentation materials for an AI-in-industry webinar at Institut Teknologi DelTypeScript
2026personal-portfolioEarlier Next.js personal site — superseded by the live Astro build at kielltampubolon.id (archived)TypeScript
2026devto-autopublishAutomated publishing pipeline for dev.toJavaScript
2026nebula-drift / solstice-gameBrowser games, zero dependenciesJavaScript / HTML
2026gmaps-extractorChrome extension for B2B lead extraction from Google Maps (private)JavaScript
2026automation-loganHR clock-in/out automation bot, VPS + Cloudflare Workers deploy targets (private)Python / JavaScript

(Earlier school/web projects and one-off client sites not listed here remain visible in the full repository list.)

Pinned Loading

  1. BraveMCPBraveMCPPublic

    Local-first MCP server that gives Claude Desktop searchable memory of your browsing history — pages, bookmarks, highlights, notes.

    TypeScript 1 1

  2. agent-memory-protocolagent-memory-protocolPublic

    AMP: An open protocol for AI agent memory — like MCP, but for memory

    Python

  3. secops-toolkit-mcpsecops-toolkit-mcpPublic

    An MCP server of local, defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo-root command-shadowing and symlink-escape checks, and shell command safet…

    Python

  4. mcpscanmcpscanPublic

    Supply-chain security scanner for MCP servers & Claude Code projects — catch tool-poisoning, command injection & risky permissions before you install. Zero deps.

    Python

  5. vulnscanvulnscanPublic

    AI-powered vulnerability scanner — OSV.dev lookups across 7 ecosystems plus LLM-generated exploitability analysis and fixes.

    Python

  6. soc-copilotstudiosoc-copilotstudioPublic

    AI-powered SOC built on Microsoft Copilot Studio, Power Automate & Graph API — no Sentinel, no third-party SIEM.

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
View glatinone's full-sized avatar

Block or report glatinone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
glatinone/README.md

Kiell Tampubolon

AI Security & Agent Infrastructure Engineer · Singapore

Website · LinkedIn


Focus

I work at the intersection of LLM reasoning, MCP tooling, and SOC automation — building the security layer agentic systems need before they're trusted with real infrastructure, and building agents that do SOC work directly.


Core Systems

🛡️ mcpscan

Supply-chain security scanner for MCP servers & Claude Code projects. Problem: MCP servers ship with zero standard vetting — tool-poisoning, command injection, over-broad permissions, and leaked secrets go straight into .claude/ directories. Stack: Python, zero runtime deps, SARIF 2.1.0 output for GitHub code scanning, CI-ready. Status: active, CI-ready

AI-powered vulnerability intelligence scanner. Problem: dependency vulnerability lists are noisy — a CVE hit doesn't tell you what's actually exploitable in your usage. Stack: Python · OSV.dev lookups across 7 ecosystems (Python, Node, Go, Maven, Ruby, NuGet, Rust) · LLM-backed exploitability + remediation analysis. Status: active

Local-first browser memory, accessible by Claude. Problem: Claude has no memory of what you've browsed — you re-explain context every session. Stack: TypeScript · browser extension + MCP server · fully local, no cloud sync. Status: shipped, v0.2.0

MCP server exposing defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo command-shadowing checks. Status: active

AI-powered SOC built entirely on Microsoft infrastructure — no Sentinel, no third-party SIEM. Problem: most SOC automation assumes a SIEM budget teams don't have. Stack: Copilot Studio · Power Automate · Microsoft Graph API · 5 coordinating agents (identity threat, phishing investigation, compliance/audit, SOC summary, orchestrator). Status: active

Open protocol for AI agent memory interoperability — like MCP, but for memory. Problem: every agent framework reinvents memory storage; nothing shares across vendors or sessions. Stack: HTTP-native spec · Memory Cell schema · access control · decay-ranked semantic search · active→stale→archived lifecycle. Status: spec stage, pre-PyPI


Ecosystem Contributions

Merged upstream:

PRProjectChange
#4125zalando/skipperIsolated + applied 30s timeout to upgrade proxy dialer
#5817gpustack/gpustackPropagated asyncio cancellation, removed mutable default args
#2725teamhanko/hankoRefactored OAuth providers to propagate context, fixed duplicate defer
#40kerlenton/mcpsnoopAdded stdin-piped session support

Also tracking the MCP ecosystem via awesome-mcp-servers.


Labs

RepoWhat it does
sentinelscoutMulti-source OSINT aggregator — VirusTotal, AlienVault OTX, Shodan, NVD, GitHub — with AI correlation
autoreviewAI-powered PR code review CLI, multi-LLM (OpenAI, DeepSeek, Claude, Ollama)
streamblind-pocPoC + fix for asynchronous telemetry blindness & state desync in AI streaming clients
claude-token-monitor-usageLocal-first desktop HUD for Claude.ai / Claude Code quota and token-cost tracking
dev-to-mcpMCP server for the dev.to API — browsing, challenge tracking, authenticated publishing
devto-challenge-agentMulti-agent system for dev.to challenge research, writing, and performance tracking
nexora-second-brainAI-powered second brain on Notion, Claude as the intelligence layer

Engineering Evolution

PeriodRepositoryContext & FootprintStack
2022BARELANG-MRT / B-MRT.github.ioTeam site for a robotics competition entry (archived)HTML
2023Keamanan-Basis-DataDatabase security coursework, published (archived)
2024e_logbookLogbook web app (archived)PHP
2025security-automation-notesScripts for repetitive security tasks — email analysis, log review, system checksShell
2025cybersecurity-communication-guideInteractive guide for explaining security concepts to non-technical audiencesTypeScript, React
2025phising101-kielPhishing awareness reference materialJavaScript
2025–26Freelance client builds — deddy-tour-travel-premier, malay-rental-batam, 4care_medicalcentre, magal-restaurant, stefan-music-learnClient-commissioned sites (private)Next.js / TypeScript
2026ai-webinar-itdelPresentation materials for an AI-in-industry webinar at Institut Teknologi DelTypeScript
2026personal-portfolioEarlier Next.js personal site — superseded by the live Astro build at kielltampubolon.id (archived)TypeScript
2026devto-autopublishAutomated publishing pipeline for dev.toJavaScript
2026nebula-drift / solstice-gameBrowser games, zero dependenciesJavaScript / HTML
2026gmaps-extractorChrome extension for B2B lead extraction from Google Maps (private)JavaScript
2026automation-loganHR clock-in/out automation bot, VPS + Cloudflare Workers deploy targets (private)Python / JavaScript

(Earlier school/web projects and one-off client sites not listed here remain visible in the full repository list.)

Pinned Loading

  1. BraveMCPBraveMCPPublic

    Local-first MCP server that gives Claude Desktop searchable memory of your browsing history — pages, bookmarks, highlights, notes.

    TypeScript 1 1

  2. agent-memory-protocolagent-memory-protocolPublic

    AMP: An open protocol for AI agent memory — like MCP, but for memory

    Python

  3. secops-toolkit-mcpsecops-toolkit-mcpPublic

    An MCP server of local, defensive SecOps helpers: IOC extraction, defang/refang, hashing, password entropy, CIDR math, repo-root command-shadowing and symlink-escape checks, and shell command safet…

    Python

  4. mcpscanmcpscanPublic

    Supply-chain security scanner for MCP servers & Claude Code projects — catch tool-poisoning, command injection & risky permissions before you install. Zero deps.

    Python

  5. vulnscanvulnscanPublic

    AI-powered vulnerability scanner — OSV.dev lookups across 7 ecosystems plus LLM-generated exploitability analysis and fixes.

    Python

  6. soc-copilotstudiosoc-copilotstudioPublic

    AI-powered SOC built on Microsoft Copilot Studio, Power Automate & Graph API — no Sentinel, no third-party SIEM.