Skip to content
View dodge1218's full-sized avatar

Block or report dodge1218

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
dodge1218/README.md

Ryan Brubeck

AI infrastructure and application security researcher focused on MCP/server-side tooling, agentic control planes, SSRF, authentication and authorization boundaries, unsafe execution, and coordinated disclosure.

Download my cybersecurity resume

Security research

I count a result only after a maintainer, platform, published advisory, fix, or case trail validates it. Scanner output and unconfirmed submissions are not counted as wins.

Public GitHub advisory credit

GitHub's live credit:dodge1218 advisory index currently links these native public credits:

Additional published advisories from my research

Private or unpublished advisories are intentionally omitted until their maintainers publish them.

Research practice

My reports use pinned-source review, non-destructive proof-of-concept transcripts, negative controls, adversarial falsification, private-route-first disclosure, and patch verification. The goal is a report a maintainer can reproduce, fix, and safely publish—not a scanner-generated claim.

Current research areas include MCP and agent/tool trust boundaries, server-side authentication, SSRF and redirect controls, unsafe command execution, sandbox escapes, authorization failures, path traversal, and insecure deployment defaults.

Public projects

  • ContextClaw — deterministic context budgeting for long-running agent sessions
  • PromptLens — local-first AI usage analytics for exported conversations
  • task-rag-mcp — local MCP retrieval for task instructions and project memory
  • Breaking Apps Hackathon — AI-assisted Playwright regression checks

Popular repositories Loading

  1. contextclaw contextclaw Public

    Deterministic context budgeting for long-running OpenClaw agent sessions.

    JavaScript 3 1

  2. zen zen Public

    Calm CPU/RAM audit and cleanup for AI-agent workflows

    Python 1 1

  3. task-rag-mcp task-rag-mcp Public

    Local MCP server for just-in-time task instructions, skills, and project memory retrieval.

    JavaScript

  4. openclaw openclaw Public

    Forked from openclaw/openclaw

    Local-first personal AI assistant across chat, voice, mobile, desktop, and canvas interfaces

    TypeScript

  5. breaking-apps-hackathon breaking-apps-hackathon Public

    Hackathon portfolio QA suite: AI-assisted Playwright regression checks for small-business websites.

    TypeScript

  6. promptlens promptlens Public

    Local-first AI usage analytics for exported conversations: topics, prompt patterns, loops, and personal workflow insights.

    Python