API Bridge
OpenAI-compatible API bridge for DeepSeek, GLM & other LLM providers with SSE streaming.
Security researcher & full-stack developer from Bangladesh.
I find vulnerabilities before the bad guys do.
I'm a self-taught security researcher and developer who believes the best way to secure something is to break it first.
My journey started with web development, but I quickly realized I was more interested in finding the cracks than building the walls. Now I spend my days hunting bugs on HackerOne, building security tools, and helping startups lock down their platforms.
When I'm not breaking things, I'm building them — from SaaS platforms to AI-powered automation agents. I believe in open source, responsible disclosure, and making the internet a safer place.
Building web apps with modern stacks — React, Laravel, Node.js
Finding vulnerabilities through bug bounty & responsible disclosure
Building LLM agents and automation workflows with OpenClaw
OpenAI-compatible API bridge for DeepSeek, GLM & other LLM providers with SSE streaming.
Automated recon & vuln scanning toolkit for bug bounty — subdomain enum, tech detection, passive analysis.
Custom OpenClaw skills for security research, email triage & multi-step task orchestration.
Android APK reverse engineering tool — OTP keyboard fixes, input restrictions, SMS paste support.
AuroraStore-style APK downloader via Google Play internal API with protobuf support.
Full-stack web applications — SaaS platforms, e-commerce, admin dashboards with modern UI.
Independent · Bug Bounty
Hunting bugs on HackerOne. Responsible disclosure to startups. Specializing in IDOR, auth bypass, and API security.
Freelance
Building web apps with Laravel, React & Node.js. SaaS platforms, e-commerce, and automation tools on Linux servers.
OpenClaw & Community
Building custom skills and plugins for AI agent frameworks. Contributing to security tooling and automation.
Got a security concern, a project idea, or just want to chat?
I'm always open to new opportunities.