SHIPPED
verified 2026-10-01
A complete agent runtime for Android: on-device model routing, tool execution, a Linux sandbox for untrusted code, plugins with declared permissions and a network allowlist, scheduled tasks, an encrypted vault, and run telemetry. Ships through CI as a signed build and is verified on-device after every release — because a green build is a claim, not a test.
AGENTS
ANDROID
SANDBOX
PLUGIN PERMISSIONS
SIGNED CI
architecture diagram — add later
ARGUS
SHIPPED
verified 2026-09-28
Entity intelligence that runs entirely from a phone. Content-addressed evidence in SQLite, a resolver that returns SAME / DIFFERENT / UNKNOWN with the evidence attached, per-source coverage states so "not checked" can never be mistaken for "nothing found", and report generation behind a citation validator that fails closed.
OSINT
RESOLUTION
PROVENANCE
CITATION VALIDATION
entity graph — add later
SHIPPED
verified 2026-09-29
Reverse engineering of a commodity Android RAT's Telegram exfiltration channel: payload extraction, protocol reconstruction from recovered code, derived indicators of compromise. Samples handled in isolation; no live infrastructure contacted.
RE
THREAT ANALYSIS
IOC DERIVATION
protocol reconstruction — add later
PANOPTES
ACTIVE
updated 2026-09-28
A cron-snapshot geospatial feed on edge workers — earthquakes, military and civil flights, satellites, fires, hazards, news — collected on schedule into a historical store. Deliberately inverted from per-request fan-out: the observation is the record, not a query. A national Algerian-scoped variant runs alongside it.
EDGE WORKERS
SCHEDULED COLLECTION
HISTORICAL STORE
CyberRAG
ACTIVE
updated 2026-09-29
A retrieval arsenal over WSTG, ATT&CK, exploitation references and my own field notes, rebuilt around one rule: abstention is a valid output. Keyed lookup data and conceptual corpora live in separate indexes so a 1,900-record CVE catalogue cannot poison concept queries, and a query term absent from the corpus is treated as evidence the corpus lacks the topic.
RAG
IDF WEIGHTING
CALIBRATION
EVAL HARNESS
Wormlab
RESEARCH
started 2026-09-28
An unanswered question: what is the real capability floor of small open-weight models used as autonomous cyber tooling? Existing public claims test one deliberately undisclosed model size and call it a result. I'm building the sweep — size against task fitness, below single-GPU scale, micro-policies versus language models, payload execution versus rhetoric.
RESEARCH
LITERATURE REVIEW
EXPERIMENTAL DESIGN
SHIPPED
verified 2026-09-28
All 69 wilayas and their communes, updated for the 2026 administrative reform, bilingual naming, with a documented generation procedure — a reproducible build rather than a one-off export.
DATASET
REPRODUCIBLE BUILD
PUBLIC