Skip to content
View ucsahinn's full-sized avatar

Block or report ucsahinn

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ucsahinn/README.md

I build security products, public-safe release hubs, and practical Codex workflows that help good work ship clearly.


Start Here

Most of the work is organized around a few connected projects. If you are visiting for the first time, this is the quickest way to find the right one:

If you need...Start with
Vulnerability intelligence, CVE workflows, and public product docsMyVuln live product and MyVuln public hub
Public releases, signed update manifests, and operator support evidenceVaultPilot release hub
Windows-first Codex setup with agents, skills, MCP connectors, and validation gatesCodex Chef
Reusable approval-gated prompts, workflows, and verification checklistsPrompt Architect
Documentation-first starter kits for AI-coded projectsAI Project Starter
Reusable AI agent and Codex skill creationAI Skill Create
Codex CLI operating guidance for prompts, skills, MCP, hooks, and WindowsCodex CLI Operator Handbook
Turkish cybersecurity writing and public research surfaceSiberDergi

What I Build

  • Security products and public hubs that make useful documentation, releases, and trust signals easy to find without exposing private source, customer data, or tenant context.
  • Windows-first release surfaces for self-hosted tools, with the manifests, support evidence, operator notes, and verification gates needed to keep shipping understandable.
  • Codex and AI-engineering tools that turn a vague idea into a clear plan, a reusable skill, a well-routed workflow, and a handoff another person can actually pick up.

The Work I Keep Closest

MyVuln repository card
MyVuln starsMyVuln last commitMyVuln docs online
VaultPilot repository card
VaultPilot starsVaultPilot releaseVaultPilot last commit
Codex Chef repository card
Codex Chef starsCodex Chef last commitWindows-first setup
Prompt Architect repository card
Prompt Architect starsPrompt Architect last commitPrompt patterns ready

AI Engineering Tooling

Alongside the products, I build the small systems that make AI-assisted engineering more deliberate: better project context, safer prompts, reusable skills, and workflows that leave evidence behind.

AI Project Starter repository card
AI Project Starter starsAI Project Starter last commitAI Project Starter license
AI Skill Create repository card
AI Skill Create starsAI Skill Create last commitAI Skill Create skill package
Codex CLI Operator Handbook repository card
Codex CLI Operator Handbook starsCodex CLI Operator Handbook last commitCodex CLI Operator Handbook docs
Live product surfaces
MyVuln liveMyVuln docsSiberDergi live

How I Work

LoopProof in the repo surface
ResearchI read the public docs, threat boundaries, release notes, and repo instructions before changing behavior.
PlanI keep the scope clear, define the checks up front, and leave room for a safe rollback.
ExecuteI make the focused change without weakening auth, validation, public-safety, or support boundaries.
VerifyI start with local checks, then widen the evidence when the change can affect more of the system.
ReleaseI keep the docs clean and make the public artifact easy for the next person to trust and use.

The Stack Behind It

AreaTools and platforms
Product UI and docsTypeScript, React, Next.js, Tailwind CSS, Markdown, SVG assets
Security productsCVE workflows, URL intelligence, release manifests, support evidence, public-safe docs
Data and backendNode.js, Supabase, PostgreSQL, SQLite, Prisma
Windows release workPowerShell, Windows Server, signed release flow, GitHub Actions
AI engineeringOpenAI Codex, skills, agents, MCP connectors, prompt architecture, verification checklists

A Little GitHub Signal

GitHub signal summary

Contribution Snake

The contribution snake is kept as a manual-only profile asset. There is no cron trigger and no push trigger quietly changing the profile in the background.

GitHub contribution snake

Public Boundary

This profile points to public-safe hubs on purpose. It is not the place for private source paths, customer data, tenant screenshots, incident details, tokens, credentials, local machine paths, or private operational context.


Build. Verify. Release.



GitHub followersProfile views

Pinned Loading

  1. prompt-architectprompt-architectPublic

    Prompt Architect: reusable prompt patterns, approval-gated workflows, and verification checklists for AI-assisted development.

    JavaScript 4

  2. myvulnmyvulnPublic

    Public-safe TR/EN product hub for MyVuln threat intelligence platform.

    JavaScript 9 1

  3. vaultpilotvaultpilotPublic

    Public release, documentation, signed update manifest, and operator support hub for VaultPilot.

    JavaScript 7