AI Platform Engineer at rubica — LLM & MCP infrastructure and application & supply-chain security for a regulated Australian financial-advice platform. I built the platform's core end-to-end: multi-provider chat (AWS Bedrock, native Anthropic, Google, OpenAI), a Model Context Protocol (MCP) connector fleet, and the security posture that runs them.
Background in Cyber Security and Computer Engineering. Mostly TypeScript on Node.js and Next.js, with the Anthropic SDK on the platform side.
→ yusufhan.dev · /now · linkedin · x
- vercel-seo-audit — CLI auditing Next.js / Vercel deploys for SEO and indexing failures. Published on npm.
- webhook-hmac-kit — Stripe-style webhook signing without the Stripe lock-in.
- clean-repo-standard — Production-safe GitHub repo template: branch protection, CI, PR templates, verified commits.
modelcontextprotocol/registry#1436— fix(api): allow PATCH in CORS so browsers can call the status endpointsmodelcontextprotocol/registry#1149— fix(publisher): omit repository when URL cannot be detectedmodelcontextprotocol/registry#1145— feat(publisher): copy version from package.json and prefer mcpName in initmodelcontextprotocol/typescript-sdk#1875— feat(client): support custom claims in PrivateKeyJwtProvidermodelcontextprotocol/servers#3893— fix(memory): resolve Vitest false positive for expected rejectioncloudflare/workerd#6040— Add TextDecoder support for x-user-defined encoding (fixes #6039)aws/aws-sdk-js-v3#8281— fix(credential-provider-node): handle passive credential refresh rejectionrjsf-team/react-jsonschema-form#5044— fix(@rjsf/core): prevent extraErrors duplication on array field mutation (#5041)cased/kit#189— fix: don't post non-actionable errors as GitHub review comments
- CVE-2026-44429 — Stored XSS in the official Model Context Protocol Registry catalogue UI. Disclosed and patched, May 2026. Assigned by GitHub-as-CNA.
The Lessons series — long-form essays on production AI systems, MCP, LLM infrastructure, and security engineering.




