Skip to content
View glatinone's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report glatinone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
glatinone/README.md

Kiell Tampubolon. Applied AI and Cybersecurity. Animated agent request, policy check, and audit receipt.

Portfolio   /   DEV.to   /   LinkedIn   /   Medium

Agents that remember. Actions with boundaries. Systems you can inspect.

I build at the intersection of applied AI, cybersecurity, and developer tools. My projects explore what agents should remember, what they should be allowed to do, and what evidence they leave behind.

860 DEV.to followers

Featured / Agentic Security Lab

What should an agent be allowed to do, and how do you prove it respected the boundary?

Agentic Security Lab explores that question with a deny-by-default policy boundary for tool calls, runtime enforcement, adversarial cases, and audit receipts.

Explore the lab →

Selected Work

Project What it does Area
mcpscan Scans MCP servers and agent projects for risky tools, permissions, commands, and secrets before install. Agent security
agent-memory-protocol An open protocol and reference implementation for durable, inspectable agent memory. Agent infrastructure
ai-safety-compass A local-first workspace that turns AI workflow facts into safeguards, hard stops, and review records. Applied AI
secops-toolkit-mcp Defensive utilities for IOC handling, hashing, CIDR checks, repository checks, and command assessment. Security tooling
More from the workbench
  • autoreview: AI-powered pull request review in the terminal, with support for multiple model providers.
  • dev-to-mcp: Browse DEV.to articles and challenges, and publish authenticated posts through MCP.
  • human-approval-gate: An Agent Zero plugin that pauses high-risk actions for human approval.
  • payment-webhook-repair-lab: A local lab for retries, idempotency, state protection, and webhook failure recovery.

Merged Upstream

Fixes I found while using these tools, merged by their maintainers.

Project Contribution
ahujasid/mcp-for-blender Handle multi-byte UTF-8 sequences split across socket reads.
NVIDIA/SkillSpector Stop the code-example heuristic from silently dropping SKILL.md findings.
teamhanko/hanko Propagate context and fix a duplicate defer in the OAuth providers.
Tencent/AI-Infra-Guard Surface the underlying error when an MCP scan can't connect.
gpustack/gpustack Propagate asyncio cancellation and remove mutable default arguments.
zalando/skipper Isolate the upgrade proxy dialer and give it a 30s timeout.
agent0ai/a0-plugins Three Agent Zero plugins: human approval gate, chat jumper, chat status lights.

Stack & Principles

Python TypeScript JavaScript Shell

Concrete workflow first. A small runnable implementation next. Then normal paths, adversarial inputs, and documented limits. I care about useful demos and evidence that someone else can reproduce.

Writing & Collaboration

I write about AI engineering, security, and what I learn while building. Find my articles on DEV.to and Medium.

For collaborations around agent security, developer tools, technical documentation, or code-backed demos, connect on LinkedIn.


Implementation first. Evidence over hype.

Pinned Loading

  1. BraveMCP BraveMCP Public

    Local-first MCP server that gives Claude Desktop searchable memory of your browsing history — pages, bookmarks, highlights, notes.

    TypeScript 1 1

  2. agent-memory-protocol agent-memory-protocol Public

    An open protocol and reference implementation for durable, inspectable memory in AI agent systems.

    Python

  3. secops-toolkit-mcp secops-toolkit-mcp Public

    Defensive security utilities for analysts and agents: IOC handling, hashing, CIDR checks, repository checks, and safe command assessment.

    Python

  4. mcpscan mcpscan Public

    Supply-chain security scanner for MCP servers and agent projects. Finds risky tools, permissions, commands, and secrets before install.

    Python

  5. vulnscan vulnscan Public

    AI-powered vulnerability scanner — OSV.dev lookups across 7 ecosystems plus LLM-generated exploitability analysis and fixes.

    Python

  6. soc-copilotstudio soc-copilotstudio Public

    AI-powered SOC built on Microsoft Copilot Studio, Power Automate & Graph API — no Sentinel, no third-party SIEM.