Security engineer and vulnerability researcher. I find memory-safety and authorization-boundary defects in widely-deployed infrastructure — cluster control planes, network-facing daemons, and serialization libraries — and work with upstream maintainers and security response teams to get them fixed.
My work is evidence-first: every finding ships with a sanitizer transcript or a failing upstream test, a duplicate check, and a tested fix. Google has reviewed and publicly released one of my reports; another is in review with the Go project. 6 merged pull requests to independent open-source projects — Go, protobuf, SymPy, TheAlgorithms/Python, freeCodeCamp, free-programming-books — plus 57 merged across my own production and open-source organisations.
Alongside that I build and maintain the tooling — ~200 open-source offensive and defensive security tools, secure full-stack products, and hardware wireless kits — with a focus on systems that stay maintainable as they grow.
| Identity |
Nikhil Nagpure · 5h4d0wn1k🌍 Open to relocation & frequent travel · always exploring somewhere new |
| Education | B.Tech CSE — Cybersecurity & Digital Forensics, VIT Bhopal (2021–2025) · CGPA 8.33/10 |
| Now |
Technical Lead @ CuboidSoft ·
Founder @ Shadownik ·
Founding SWE @ Pawan Technologies Previously: Offensive Security Intern @ InLighnX · Ethical Hacking Intern @ Internship Studio |
| Focus | Vulnerability Research · Memory Safety · Fuzzing · Offensive Security · Red Teaming · API Security · AI/LLM Security · Hardware-Wireless Pentesting · Secure Full-Stack |
| Building | ApiSecPlatform (enterprise API security testing) · Portable Wireless Pentest Toolkit (ESP32-based) · SentinelWall AI threat detection |
I research memory-safety and authorization-boundary defects in widely-deployed infrastructure — cluster control planes, network-facing daemons, and serialization libraries. The bar I hold: a finding is real when it reproduces under a sanitizer or fails an upstream unit test, and it ships with a tested fix. A theoretical attack scenario is not a finding.
Method: source audit of bounds/length handling → minimal reproducer → ASan/UBSan confirmation → duplicate check → private disclosure → verified fix.
| protobuf-java Google · gRPC |
Integer-overflow and silent-truncation audit of Timestamps.parse in the Java ProtoJSON parser.
Oversized timezone offsets overflow and wrap; >9 fractional digits are silently truncated —
producing a different-but-valid Timestamp with no error, inconsistent with the C++ parser.
Issue #30276 · PR #30277 (+99/−10, awaiting review) Reported to Google VRP (ref 567495093); Google reviewed it and released it for public disclosure. |
| Go stdlib encoding/xml |
xml.Marshal and EncodeToken emit ill-formed element and attribute names
while returning a nil error — invalid XML leaves the encoder with no way for callers to detect it.
Standard library, affects every Go program using encoding/xml.
Issue #81881 · CL 841865 (under review) |
Additional findings in Kubernetes admission control and embedded/network daemon memory safety are in coordinated private disclosure with the respective security response teams. Details are available on request once each advisory is published.
Disclosure policy: no finding is made public before the affected project has had a fair opportunity to ship a fix. Undisclosed reports are never discussed publicly, including here.
| Project | Description | Stars |
|---|---|---|
| photo-organizer | Local-first, private-by-default photo & video library — Rust daemon + Flutter desktop, SQLCipher vault, ChaCha20-Poly1305 encryption, OCR & scene search, P2P LAN sync | |
| Decentralized Cloud Storage | Blockchain-backed decentralized storage — Solidity smart contracts sharing encrypted file references with on-chain access control | |
| ML Web-Attack Detection | ML-powered web-attack detection — phishing URL, DoS intrusion & XSS classification | |
| cybersecurity-framework | Interactive map of everything in cybersecurity — 27 domains, 776 categories, 1,067 curated offensive & defensive tools | |
| ApiSecPlatform | Enterprise API security platform for automated testing, threat insights, and OWASP-aligned checks | — |
| Portable Wireless Pentesting Toolkit | ESP32-based field pentesting device for wireless assessments and protocol testing | — |
The current effort — autonomous offensive/defensive security tooling for authorized labs. Every tool ships with docs, tests, and explicit legal-use boundaries.
| Tool | What it does |
|---|---|
| sentinelwall | Autonomous AI network threat detection & correlation — MITRE ATT&CK mapping, ML anomaly detection, rule DSL, STIX/Navigator/HTML exports |
| mythicforge | Adversarial LLM prompt-injection & jailbreak testing — 37 techniques, OWASP/NIST/MITRE ATLAS benchmarks, SARIF reports |
| shadowvault | Cryptographic secrets lifecycle manager — AES-256-GCM vault, OPSEC zeroize, team RBAC, migration tools |
| hermesc2 | C2 & post-exploitation research framework (lab) — listeners, stagers, beacons, encrypted transport, killswitch, offline loopback-only demo |
| viperstrike | MCP (Model Context Protocol) server vulnerability auditor — AST/whitebox SAST for agentic AI tool handlers, SARIF-capable |
| crownjewel | Cross-cloud identity federation auditor — Golden/Silver SAML, OAuth client-ID spoofing, OIDC validation, offline fixtures |
| aiarsenal | Adversarial AI/ML security studio — data poisoning, model backdoors, extraction, membership inference, prompt injection, agentic red-team planner |
| webbreach | OWASP Top-10 web exploitation framework — built-in localhost vulnerable targets, AI-guided scan queue |
| cloudpwn | Cloud & container penetration suite — AWS/GCP/Azure enumeration, docker leaks, k8s secrets, terraform audit, CSPM |
| supplysec | Supply-chain security gate — SBOM (CycloneDX/SPDX), offline advisory matching, policy gates, post-quantum scanning |
| toxindb | RAG retrieval-time poisoning detector — canary injection, provenance attestation, SARIF+MD reports |
| honeynet | Honeypot farm + deception grid — multi-protocol honeypots, attacker fingerprinting, dwell/risk scoring, quarantine |
198+ catalog security tools and counting — see the security tool catalog. For more flagships:
cryptocrack,grainrecon,exploitcraft,mobsek,endpointaegis,netpwn,wiair,socialforge,sprayshed,rogueai,postpwn, and thew/m/c/d/f/h/i/n/p/r/se/web/x/ai/clcoded series. All for authorized testing only.
Technical Lead — CuboidSoft (Jan 2025 - Present)
- Lead an IT software company delivering custom web applications, mobile apps, and digital solutions for SMEs and startups across multiple domains.
- Lead full-stack architecture and development for client projects using Next.js, Node.js, PostgreSQL, and modern frontend frameworks to build secure, scalable applications.
- Own development workflows end-to-end: Git version control, CI/CD pipelines, code reviews, and cloud/VPS deployment.
- Ship on company strategy, branding, and go-to-market — service packaging, proposal writing, and technical client presentations.
Founder — Shadownik · Freelance Venture (Jun 2024 - Present)
- Build and scale a multi-service freelance venture across cybersecurity, full-stack engineering, cloud deployment, and digital operations.
- Deliver secure production systems and offensive security assessments for real-world clients.
- Lead product development for ApiSecPlatform and multiple automation-focused services.
- Developed responsive production web apps and scalable backend APIs.
- Built integrations, database workflows, and cloud-ready deployment pipelines.
- Performed web application security assessments (OWASP Top 10, Burp Suite, Metasploit), threat modeling, and red-team simulations.
- Contributed to large-scale IT infrastructure defense: intrusion detection monitoring, vulnerability triage, and security reporting.
- Identified and mitigated XSS vulnerabilities in production web applications; authored remediation reports.
- Designed practical security lab environments simulating real-world attack scenarios.
| Contributions | 3,600+ in the last 12 months |
| Pull Requests | 237 authored · 177 merged · 6 merged to independent OSS · 57 merged to my own orgs |
| Repos on GitHub | 249 · 231 built from scratch · 1,025 stars |
| Organizations | 3 orgs · 20 repos (Shadownik · Cuboidsoft · CuboidPilot) |
Bugs found by reading the code, reproduced with a failing test, and fixed with a patch upstream maintainers can review and merge. These are the projects that accepted my work.
| golang/go Go standard library |
xml.Marshal and EncodeToken emit ill-formed element and
attribute names while returning nil error — callers get invalid XML with
no way to detect it. Reached from every Go program using encoding/xml.
Issue #81881 · CL 841865 🟡 open — 3 comments, maintainer cross-linked the related family |
| protocolbuffers/protobuf Google · gRPC |
Integer overflow and silent truncation in Java ProtoJSON Timestamps.parse:
oversized timezone offsets wrap, >9 fractional digits are dropped, and the
parser returns a different but valid-looking Timestamp with no error —
inconsistent with the C++ parser. Found via integer-overflow audit; fixed with tests.
Issue #30276 · PR #30277 (+99/−10) 🟡 open — mergeable, awaiting maintainer review. Google VRP released it for public disclosure. |
| SymPy |
solve returned solutions outside the domain of a denominator — e.g.
x/log(x) returned complex and non-positive values that cannot satisfy the
original equation, silently.
PR #30567 🟢 merged |
| TheAlgorithms/Python |
Made reversort and odd-even transposition sort generic over
comparable items, so both work for any ordered type rather than int only —
removing an artificial type restriction in two widely-copied algorithm implementations.
PR #15402 · PR #15405 🟢 both merged |
| freeCodeCamp |
Corrected a wrong truthy/falsy example and its wording in the JavaScript curriculum —
a concept error in material used by millions of learners.
PR #70289 🟢 merged |
| EbookFoundation/ free-programming-books |
Repaired dead turing.com.br links across the book lists by resolving them
through the Wayback Machine.
PR #13472 🟢 merged |
| Project | Finding |
|---|---|
| pandas | #69429 — GroupBy.agg with as_index=False and a MultiIndex column group produces a wrong result shape |
| scipy | #26242 — sparse.csgraph mishandles duplicate CSR entries in bipartite matching |
Beyond upstream contributions, 57 merged pull requests across organisations I build and maintain — CuboidSoft, CuboidPilot and TCM-ONE. This is production infrastructure work: removing leaked credentials from tracked git history, pinning third-party CI actions to immutable revisions, gating production deploys on domain test suites, reversible R2 shadow writes for account migration, and automated Android release delivery with a self-repairing rollback path. Listed separately because employer and owned repositories are not independent third-party review.
- CEH (EC-Council)
- CNSP (The SecOps Group)
- Practical Ethical Hacking (TCM Security)
- Patent filed: A Self-Cleaning Glasses Case System (Application No: 202421032123)



