MCP / AI-agent security review
Static review of a small MCP server or agent integration: permissions, secrets, trust boundaries, sensitive operations, logging, input handling, and remediation.
from $75
/ Independent security & software lab
Open-source tools, independent security research, and small fixed-scope engineering work.
01 / Services
Clear scope, practical deliverables, and no inflated consulting promises.
Static review of a small MCP server or agent integration: permissions, secrets, trust boundaries, sensitive operations, logging, input handling, and remediation.
from $75
Small utilities, API integrations, parsers, reporting workflows, logging/audit tools, Dockerization, test automation, and focused Go, Python, or Rust work.
from $100
Concise inspection of small open-source projects and developer tools for obvious security, privacy, configuration, and supply-chain risks.
from $75
02 / Featured work
Selected practical projects across security engineering, systems, and developer tooling.
01
Local-first MCP auditing with tamper-evident logs and automatic secret redaction.
02
Security engineering R&D exploring credential isolation and phone-approved, second-device authorization.
03
Threat-intelligence enrichment for IPs, domains, URLs, and file hashes across multiple security data sources.
03 / Security research
Static analysis and manual review of publicly available code, with disclosure status retained alongside each report.
A malicious installer analysis covering SSH key deployment, undisclosed hardware fingerprinting, and persistent service behavior.
Read writeupA review of anonymization bypasses and transmission of account usernames and hostnames contrary to a published privacy policy.
Read writeup04 / Lab
Earlier tools and active research experiments that complement the featured work.
Experimental / R&D
A safety-enforcing DSL for ICS/OT systems that compiles to C.
View projectLive utility
Local network packet capture with real-time browser analysis.
Open toolLive utility
TCP scanning with OT/ICS protocol awareness.
Open toolLive utility
Backend host telemetry for CPU, memory, disk, and network.
Open tool05 / About
Ahlyx Labs focuses on security tooling, agent security, systems programming, automation, and independent research.
06 / Contact
Send what you are trying to build or review, the relevant repository or documentation, and your expected timeframe.