Skip to content
View r0075h3ll's full-sized avatar
🙀
on my puter
🙀
on my puter

Block or report r0075h3ll

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
r0075h3ll/README.md
$ whoami
Hardik Nanda — product security engineer

$ ps aux | grep root
hardik   red-teaming RAG apps and AI agents before they ship
hardik   chasing compromised packages through the supply chain
hardik   oralyzer.py        open redirect/XSS/CRLF scanner, since 2020, ~800★
hardik   chainwatch.py      flags compromised packages across a GitHub org
hardik   fireeye.py         watches an AWS account for changes worth a look
hardik   hermes-leash.sh    keeps a self-hosted bot's AWS bill in check
hardik   endomorph.c        flips byte order, little-endian to big and back
hardik   toleman-platform   new build, not shipped yet

$ cat contact.txt
r0075h3ll.github.io · r0075h3ll.hashnode.dev · linkedin.com/in/r0075h3ll · hnanda21@gmail.com

Pinned Loading

  1. hermes-leash hermes-leash Public

    Budget guardrails for a self-hosted Hermes Agent Telegram bot on EC2, with idle auto-shutdown, nightly Lambda shutdown, billing alarms, and a hard budget stop. No open ports, everything runs over SSM.

    Shell 1

  2. ChainWatch ChainWatch Public

    Supply chain security CLI that scans every repo in a GitHub org for compromised, malicious, or vulnerable package versions via the Dependency Graph SBOM API, with ecosystem-aware matching and JSON/…

    Python

  3. Oralyzer Oralyzer Public

    Python tool that probes websites for open redirection via headers, JavaScript, and meta-tag refresh, pulls candidate URLs from the Wayback Machine, and checks CRLF injection and DOM XSS.

    Python 826 116