I build security tools, full-stack platforms, and AI systems from first principles.
Not wrappers. Not tutorials. Production code that solves real problems.
Currently shipping GhostLM — an 81M-parameter cybersecurity language model trained from scratch — and the ghostloop family: an embodied-AI agent runtime with a fail-closed safety pipeline (pip install ghostloop), its Next.js control plane, and a Tauri desktop app. Everything in one place at the live HuggingFace demo.
I'm a Computer Science student at Moi University (Nairobi, Kenya) and the founder of Complex Developers, a studio that ships web platforms, custom tooling, and AI adjacent products. The company site + CRM runs on Next.js 15, Prisma, and Postgres.
My work sits at the intersection of offensive security, full-stack engineering, applied AI, and systems programming. 34+ open source projects, 320+ commits, 165,000+ lines of code, and counting. The shortest way to prove what you can engineer is to show working code, so that's what this profile is.
|
Merged. Fixed agent name preservation in |
Open, under review. Replaces the naive |
|
An open source cybersecurity language model built from scratch in PyTorch. 81M parameter decoder-only transformer (RoPE, SwiGLU, RMSNorm) trained on a 422M token multi-domain corpus across 27 sources: cybersec writeups, NVD CVEs, MITRE / CWE / OWASP, NIST SP 800, FineWeb-Edu, open-web-math, and a 105 repo open source code pull spanning 15 languages. Ships GhostAgent (a tool-using runtime), a multi-vendor HTTP server speaking OpenAI / Anthropic / Gemini / Ollama wire formats, an MCP server, and GhostBench (a packaged eval suite with Wilson 95% CIs and McNemar paired comparisons across 14 differentiation bets). 312 tests green. AI agent safety stack: secure-mcp, ghostguard (4-tier policy proxy with audit dashboard), CyberBench Defensive security toolkit: ghostaudit (23 CIS Kubernetes checks), ghostforensics (memory forensics with YARA + Volatility + STIX 2.1 export), ghostsiem (Sigma-rule SIEM), securecommit (pre-commit secret scanner) Offensive tooling: concurrent TCP port scanner, packet-level traffic analyzer, vulnerability scanner, hash-cracking framework, MAC rotator, metadata scrubber Full-stack platforms: Complex Developers CRM (Next.js 15 + Prisma + Postgres), ChartSentinel (trading SaaS with Stripe + PostHog + Sentry), High-End CRM, ai-coding-assistant |
ghostloop v1.0.3 — the agent loop, embodied. ghostloop-ui — Next.js 15 + React 19 + Tailwind 4 control plane, live at ghostloop-ui.vercel.app. Fleet view, alarm tray, episode timeline, per-counter Prometheus metrics, and a profile-aware gamepad mapper (drone / mobile base / quadruped / arm / humanoid) built for non-coders. Demo-mode fallback keeps the deploy interactive with no backend configured. ghostloop-desktop v0.2 — Tauri 2 + Rust shell wrapping ghostloop-ui as a single-file native app for macOS / Windows / Linux. Voice control, gamepad rumble on safety events (geofence block, force-cap trip, e-stop), native OS notifications, 120 Hz gamepad polling via secure-mcp — MCP server exposing security tools to AI agents with policy gates, subprocess sandboxing, and audit trails. Fail-closed by default. CyberBench — Open, reproducible benchmark for evaluating LLMs on cybersecurity reasoning. YAML tasks, pluggable backends, ranked leaderboard. linkdrop v0.7.1 — Cross-platform Tauri + Rust desktop app bridging iPhone to Linux for photos, files, notifications, screen mirroring. Daemon-backed pymobiledevice3 bridge, CI-built .deb / .AppImage. |
Technical writing lives in joemunene-by/writing.
- AI Model Supply Chain Security — architectural guidance on serialization risks in model artifacts (pickle /
.ptcode execution, safetensors and ONNX alternatives), provenance verification, artifact scanning, and Model Bills of Materials. Originally proposed to the OWASP Cheat Sheet Series (PR #2111) and revised through maintainer review.
I'm always open to collaborating on security research, open source tooling, or interesting engineering problems.
If you're building something that matters, I'd like to hear about it.
Nairobi, Kenya · Founder, Complex Developers · Available for contract work — backend builds, security reviews, API hardening · joemunene984@gmail.com