Skip to content
View danielcadev's full-sized avatar

Highlights

  • Pro

Block or report danielcadev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
danielcadev/README.md

Daniel Castrillon

AI & Security Engineer focused on agentic systems, Rust tooling, and Linux

Portfolio · Email · UseSecure · Madrid, Colombia

I build developer tools and production systems where reliability and security matter. My work spans agentic AI systems, Rust and TypeScript, Linux applications, static analysis, authentication and authorization, data platforms, and cloud delivery.

I use coding agents within a disciplined engineering workflow: scoped tasks, deterministic controls, automated checks, security review, reproducible evals, and human validation.

Highlights

  • Built SecureFlow, a local-first evidence platform that connects deterministic analysis, contextual security review, reproducible benchmarks, a versioned knowledge base, and offline API-inventory research. Human validation remains authoritative; the project does not claim autonomous vulnerability validation or human replacement.
  • Built and published Secure Engine, a local-first Rust security analyzer for JavaScript and TypeScript that follows untrusted data across files and helpers, then emits reproducible source-to-sink evidence through CLI, desktop UI, JSON, and SARIF.
  • Modernized a production travel platform while preserving indexed routes, content, metadata, and search visibility, then automated quotation and customer follow-up workflows that were previously manual.
  • Discovered and responsibly disclosed GHSA-hc5h-gqhc-4h79, a Moderate integration CSRF vulnerability in Trigger.dev's Slack OAuth flow; credited as the reporter and fixed in version 4.5.12.
  • Reported a security issue to RustDesk through coordinated private disclosure; the maintainers acknowledged the report and merged the related fix.
  • Delivered an invited technical talk at the Max Planck Institute for Security and Privacy on structural security risks in AI-assisted software systems.

Selected Work

Project Work and outcome Evidence
SecureFlow Local-first Rust platform combining deterministic scanning, human-reviewed evidence, advisory provenance, benchmark contracts, and offline Next.js/API inventory. v0.2.0 adds sealed Web scopes and synthetic API-risk corpus generation without network scanning. Repository · v0.2.0
UseSecure Local-first Rust analysis, signed releases, performance engineering, and reproducible benchmark infrastructure Engine v0.1.10-rc2 · Bench
Production platforms Modernized customer-facing and operational systems across discovery, quotations, booking, publishing, authentication, PostgreSQL, and AWS-backed media Mitiquete · Conociendo Colombia · TripEuropa
Open source Small, reviewable fixes across Rust and Linux tooling, CLI behavior, desktop integration, CI, dependencies, and regression coverage Contribution activity
CMS Nova Reusable headless CMS foundation with schema-driven content, hybrid persistence, template tooling, and role-based administration Repository

Engineering Focus

  • AI systems: agent orchestration, task scoping, evals, guardrails, human-in-the-loop validation, AI-assisted delivery
  • Languages: Rust, TypeScript, JavaScript, Python, SQL, shell
  • Platforms: Linux, Next.js, React, Node.js, PostgreSQL, Prisma, Docker, GitHub Actions, Nix, AWS, Vercel, Hetzner
  • Security: authentication, authorization, tenant isolation, secrets, storage, webhooks, static analysis, and coordinated disclosure

Background

I lead software architecture and AI-assisted engineering at Mitiquete SAS while contributing to open-source tooling and developing public security tooling and evaluation infrastructure.

Spanish is my native language, and I work professionally in English.

Contact

Popular repositories Loading

  1. danielcadev danielcadev Public

    Shell

  2. cms-nova cms-nova Public

    JavaScript

  3. codex-desktop-linux codex-desktop-linux Public

    Forked from ilysenko/codex-desktop-linux

    Unofficial ChatGPT desktop app for Linux (formerly the Codex app), built locally from OpenAI’s official macOS app. Includes Chat, Work, and Codex. Packages for Debian/Ubuntu (.deb), Fedora/openSUSE…

    JavaScript

  4. openpad-hub openpad-hub Public

    Experimental open-source Linux controller hub with verified GameSir Cyclone 2 support

    Python

  5. danielcadev.github.io danielcadev.github.io Public

    Daniel Castrillon software engineering portfolio

    Astro

  6. starship starship Public

    Forked from starship/starship

    ☄🌌️ The minimal, blazing-fast, and infinitely customizable prompt for any shell!

    Rust