/ Independent security & software lab

Security engineering, agent security & developer tooling.

Open-source tools, independent security research, and small fixed-scope engineering work.

Open source · independent · security / systems / tooling

Ahlyx Labs circular satellite badge

01 / Services

Focused help for small, well-defined projects.

Clear scope, practical deliverables, and no inflated consulting promises.

A

MCP / AI-agent security review

Static review of a small MCP server or agent integration: permissions, secrets, trust boundaries, sensitive operations, logging, input handling, and remediation.

from $75

B

Developer tooling & automation

Small utilities, API integrations, parsers, reporting workflows, logging/audit tools, Dockerization, test automation, and focused Go, Python, or Rust work.

from $100

C

Static security code review

Concise inspection of small open-source projects and developer tools for obvious security, privacy, configuration, and supply-chain risks.

from $75

Discuss a project

02 / Featured work

Tools and systems work.

Selected practical projects across security engineering, systems, and developer tooling.

01

AuditMCP

Local-first MCP auditing with tamper-evident logs and automatic secret redaction.

Rust / MCP / SQLite / Security

View project

02

Conveyance

Security engineering R&D exploring credential isolation and phone-approved, second-device authorization.

Android / Security / Systems R&D

View project

03

Security Enrichment

Threat-intelligence enrichment for IPs, domains, URLs, and file hashes across multiple security data sources.

Go / Threat intelligence / Web API

03 / Security research

Public findings, responsibly reported.

Static analysis and manual review of publicly available code, with disclosure status retained alongside each report.

2026-03-18 · Supply chain · Reported

RustChain — Malicious Installer

A malicious installer analysis covering SSH key deployment, undisclosed hardware fingerprinting, and persistent service behavior.

Read writeup

2026-03-18 · Privacy · Disclosed

OneDragon — Telemetry Policy Violation

A review of anonymization bypasses and transmission of account usernames and hostnames contrary to a published privacy policy.

Read writeup
View all research

04 / Lab

Experiments and live utilities.

Earlier tools and active research experiments that complement the featured work.

Experimental / R&D

Baptisia

A safety-enforcing DSL for ICS/OT systems that compiles to C.

View project

Live utility

PCAP Agent

Local network packet capture with real-time browser analysis.

Open tool

Live utility

Network Scanner

TCP scanning with OT/ICS protocol awareness.

Open tool

Live utility

Hardware Dashboard

Backend host telemetry for CPU, memory, disk, and network.

Open tool

05 / About

An independent lab run by Alex.

Ahlyx Labs focuses on security tooling, agent security, systems programming, automation, and independent research.

06 / Contact

Have a small project?

Send what you are trying to build or review, the relevant repository or documentation, and your expected timeframe.

Discuss a project