Skip to content

Navigation Menu

Sign in
Sign up
@skuzu7
skuzu7
Follow

Antonio Caetano skuzu7

Software engineer | AppSec & secure code review | Threat modeling, authentication & regression tests | TypeScript, Next.js, Python

Block or report skuzu7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
skuzu7 /README.md

Antonio Caetano

Software engineer focused on application security, secure code review and testable remediation.

I build web applications and automation tools with TypeScript, Next.js and Python. My security work focuses on authentication, session handling, server-side trust boundaries and regression tests. This portfolio links the code, threat models and validation evidence behind that work.

LinkedIn · Public repositories

Security work with public evidence

1. Authentication and session security · freeband-nextjs

A Next.js and TypeScript application with a maintainer security review covering administrative authentication and session management.

The August 29 review documents a separate baseline with 33 passing tests. It identifies limitations in per-instance rate limiting, forwarded-address trust, legacy tokens in URLs and session revocation. Use the current source and CI history to assess later changes; the test totals do not establish that every finding has been resolved.

2. Payment boundaries · Shopping-Cart-Project

A Next.js shopping cart integrating Stripe checkout. The payment security architecture documents the browser/server boundary, backend secret handling and checkout validation.

Repository · Security policy · CI history

3. Browser automation and MCP · CSA-Obsidian

A Python project combining Camoufox, persistent browser sessions, a CLI and a 17-tool Model Context Protocol server. Documented use cases include authorized QA, accessibility, browser compatibility and agent evaluation. Browser profiles, cookies and saved sessions are sensitive data and require explicit scope and careful handling.

Project and test instructions · Architecture · Security design · Security policy · CI history

AI-assisted defensive engineering

My focus is using AI assistance for code understanding, threat modeling, test design and remediation review, with human review of findings and changes. The intended outcome is a reproducible finding, a reviewable fix and a regression test.

  1. Define scope: work on my own projects or systems explicitly authorized for testing, in controlled test environments.
  2. Trace the risk: connect authentication, authorization, input validation and secret-handling concerns to specific code paths and trust boundaries.
  3. Validate the finding: check assumptions against source and reproducible tests before treating an AI-generated finding as confirmed.
  4. Review and retest: evaluate the proposed change, run the relevant checks and document remaining limitations.
  5. Protect sensitive data: keep credentials, session exports and confidential information out of public issues and shared examples; follow the affected project's security reporting policy.

The linked assessments are maintainer reviews and project documentation. CI results are evidence of the configured checks at the referenced commit.

Technical toolkit

Development: TypeScript, JavaScript, Python, SQL, HTML/CSS, Next.js, React, Node.js, Express.
Automation: Playwright, Camoufox, FastMCP.
Testing and security: Vitest, pytest, Ruff, ESLint, Gitleaks, GitHub Actions, STRIDE threat modeling.

Background and credentials

My background includes Civil Engineering and full-stack software development.

Contact

For professional contact, use LinkedIn. For security findings, follow the affected repository's security policy.

Pinned Loading

  1. freeband-nextjs freeband-nextjs Public

    Next.js and TypeScript web application with administrative sessions, a documented security review, STRIDE threat model, regression tests and GitHub Actions CI.

    TypeScript

  2. Shopping-Cart-Project Shopping-Cart-Project Public

    Next.js shopping cart with Stripe checkout, server-side payment integration, documented security boundaries and a security reporting policy.

    TypeScript 1

  3. CSA-Obsidian CSA-Obsidian Public

    Python browser automation with Camoufox, session persistence and a 17-tool MCP server. CLI and Python API for authorized QA, accessibility and agent evaluation.

    Python 1

AltStyle によって変換されたページ (->オリジナル) /