Skip to content
View adamsjack711-ux's full-sized avatar
😁
😁

Block or report adamsjack711-ux

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
adamsjack711-ux/README.md

Hi, I'm Jack Adams-Lovell

Cybersecurity student at Thompson Rivers University (Computer Network & Cybersecurity, graduating Apr 2027) in Kamloops, BC. I build security tools for software supply chains and networks, and I contribute fixes to open-source security tools.

Open to: co-op, internship, and junior security roles (SOC, AppSec, security engineering) · CompTIA Security+ (Dec 2026), then CEH jackadamslovell.com · adamsjack711@gmail.com

Featured security projects

Project What it does Stack
pkgxray Checks npm packages and MCP servers before install: static analysis with cited SAFE / REVIEW / BLOCK verdicts. Never runs package code. On npm · pkgxray.ca Node.js
s-ide Security-testing IDE: sealed labs, scope default-deny, hash-chained audit log, findings traced from symptom to fix Python · TypeScript
stik-cli Passive network watcher: plain-English LAN inventory, alerts when a new device joins Go · gopacket
Cernis Detects AI-driven attacks in security logs and maps activity to MITRE ATT&CK Python
slopgate Install hook that blocks slopsquatted or hallucinated npm packages before an AI agent installs them Go
HexPath (TRU group project, in planning) IPv6 discovery, CVE enrichment, and attack-path analysis —

Open-source security contributions

  • projectdiscovery/subfinder #1809: cap untrusted source response bodies (memory-exhaustion hardening). Merged.
  • projectdiscovery/naabu #1722: reject invalid port numbers. Merged.
  • derailed/k9s #4116: show authentication errors instead of a misleading message. Open.
  • spf13/cobra #2435: native fuzz targets for completion generation. Open.
  • CorridorSecurity/hookshot #17, #18: pkgxray supply-chain install gate. Open.

Skills

Security: supply-chain analysis, static analysis, network monitoring and packet analysis, web app testing (OWASP WSTG), MITRE ATT&CK, threat modelling Languages: Go · Python · JavaScript/TypeScript · Bash Tools: Wireshark · Nmap · Docker · Linux · GitHub Actions · Git

How I work

I write threat models and design docs first (see pkgxray's threat model and architecture), test against benign and adversarial cases, and use AI pair-programming as a tool. I own the design and verify the results.

Beyond code

7+ years in hospitality leadership (Assistant Store Manager at Starbucks, Logjam Coffee): hiring, training, scheduling, and staying calm under pressure, which carries over to incident response and team work.

Pinned Loading

  1. pkgxray pkgxray Public

    Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

    JavaScript 11 4

  2. Cernis Cernis Public

    Python 1

  3. stik-cli stik-cli Public

    Passive network watcher: tells you in plain English what's on your network, and alerts when something new joins. Go, gopacket, Bubble Tea.

    Go 1

  4. driftcheck driftcheck Public

    Semantic diffing of config files (.env, JSON, YAML, TOML) across environments — typed drift detection with a CI exit-code gate

    Go

  5. agentwatch agentwatch Public

    Unified live token-usage and cost dashboard for local AI coding agents — Claude Code, Codex CLI, aider. TUI + report mode, read-only, offline.

    Go

  6. slopgate slopgate Public

    Install-gate hook that blocks slopsquatted/hallucinated npm packages before an AI agent installs them (existence + freshness; wraps pkgxray via hookshot)

    Go