> abdulsalam@lagos:~$ whoami

Abdulsalam
Abdulsalam

Security researcher and fullstack developer. I break web apps, build them, and teach LLMs how to use tools. Remote from Lagos, Nigeria.

available for freelance & remote work

abdulsalam ~ zsh

$ whoami

security_researcher / fullstack_dev

$ findings --accepted

[ok] HackerOne: stored_xss, business_logic

[ok] Bugcrowd: response_manipulation

[ok] Intigriti: response_manipulation

$ building --now

AI function calling agents

$ status

// about

Developer with a security brain

I build web apps with PHP/Laravel, Node.js and JavaScript, and I test them for a living too. As an independent security researcher I have reported validated vulnerabilities on HackerOne, Bugcrowd and Intigriti, including stored XSS, business logic and response manipulation flaws.

Before that I interned at Huawei Technologies and MTN Nigeria, working on network monitoring, incident response and operational documentation for enterprise telecom systems. I hold the Microsoft Azure AI Fundamentals (AI-900) certification.

Recently I have been building AI function calling agents: an LLM driven scanner that finds client-side tags with a headless browser, a network ops assistant, and an OSINT recon agent. I also develop augmented reality experiences with Unity, C# and Vuforia.

4+

years experience

20

projects delivered

3

bounty platforms, accepted findings

5

happy clients
Code editor with a security scanner Monitoring dashboard with charts

// skills

What I work with

languages

PythonJavaScriptPHPC#SQLHTML/CSS

frameworks & tools

LaravelNode.jsUnityVuforiaBootstrapGit

security

Burp SuiteWeb App TestingBusiness Logic TestingVulnerability AssessmentResponsible Disclosure

ai & cloud

LLM Function CallingTyped-Decision LLMs (Jev)REST API IntegrationMicrosoft AzureAzure AI (AI-900)Playwright

other

LinuxWindows ServerBlender

// projects

Things I have built

$ jev · POST /v1/systemone STAGE 1 · TRIAGE route billing 1.00 urgency 2.28 / 3 route = billing ↓ code routes STAGE 2 · BILLING DESK double_charge churn 0.98 needs_human ✓

AI · DECISION ENGINE

Jev Pipeline

A multi-stage decision pipeline on TypeSafe's Jev, a fast "System 1" decision model in the Thinking, Fast and Slow sense. One call triages a support ticket into typed decisions (route, urgency, needs-human), then the app routes in code to a team-specific second stage. Real, live API calls through a zero-dependency local backend that keeps the key server-side.

Python · Jev (System One) · REST · no dependencies
view on github

WEBXR · CREATIVE

Aurora Drift

An immersive WebXR quiet: drifting stardust, flowing aurora and a reflective sea, in a headset or a browser tab. Live experience.

Three.js · WebXR · GLSL shaders
view on github
$ scan.py · every 6h [new]h1:klarna · 12 assets [scope+]*.api.target.com added [deploy]new bundle main.8f3a.js [resumed]back after 5 days · paused 3x

SECURITY · AUTOMATION

Bounty Watch

Monitors HackerOne, Bugcrowd, YesWeHack and Intigriti every 6 hours for new programs, scope changes and new deploys on a watchlist, with email alerts and a live dashboard.

Python · GitHub Actions · GitHub Pages
view on github
▶ Enter VR

WEBXR · 3D

Constellation XR

WebXR graph explorer that runs a Barnes–Hut force layout in a Web Worker and renders the whole graph in two draw calls, in a headset or a browser tab. Live demo.

TypeScript · Three.js · WebXR · Vite
view on github
$ scan_single_page account.tier = "free" account.is_admin = false debug = false [flagged] 18 tags [pages] 1 scanned [target] burp suite

AI · SECURITY

AI Client Tag Recon

Headless browser scanner that extracts client-side tags and feature flags, driven by LLM function calling.

Python · Playwright · Groq
view on github
$ check_server_status web-01online · 45% cpu web-02offline db-01online · 88% cpu

AI · OPS

Sysadmin Agent

Network operations assistant that checks and restarts servers through tool calls.

Python · Groq · Qwen
view on github
$ osint_recon ip → 140.82.121.4 http → server: github.com port → 22 closed [done] 3 tools, 1 target

AI · OSINT

OSINT Recon Agent

Recon assistant that resolves domains, fetches HTTP headers and checks ports on request.

Python · Groq · Qwen
view on github
item item item ₦price ₦price ₦price checkout → secure

LARAVEL

Ecommerce Platform

Marketplace platform built for students within ABUAD.

Laravel · MySQL
client project · offline
admin_dash

WEB

Carter's Portfolio Website

Portfolio site with custom admin dashboard, built for Carternimations.

Laravel · JavaScript
client project · offline

WEB

Blog Website

Personal blog platform built for an entrepreneur.

Laravel · Bootstrap
client project · offline

// writeups

Writing

I write up the engineering behind my projects: the tradeoffs, the parts the docs skip, and what actually worked.

# burp: match & replace false -> true [dev console] Service Overrides ad-delivery add override ····/http app-config add override ····/https + 12 internal services exposed

WRITEUP · SECURITY

Break It, Then Ask Why

A production site shipped a hidden internal dev console gated only by a client-side flag. Flipping every false to true in Burp revealed it, exposing internal service names, ports and host-override hooks. On finding bugs by breaking assumptions and chasing why they broke.

dev.to · 6 min read
read on dev.to
# decision-only LLM route = billing ↓ 7 min read

WRITEUP · AI

Stop Parsing LLM Output

Building a routing pipeline on a decision-only model: why typed decisions beat prose you have to parse, and the CORS and key gotcha that forces a backend.

dev.to · 7 min read
read on dev.to

// research

Validated findings

Reported through responsible disclosure. I hunt business logic, authorization and data integrity bugs.

$ grep -r "accepted" ~/disclosures

[ok] HackerOne    stored XSS, business logic → fixed by vendor

[ok] Bugcrowd     response manipulation → unauthorized developer tool access

[ok] Intigriti    response manipulation → subscription plan extension

$ _

// certifications

  • [2024] Microsoft Certified: Azure AI Fundamentals (AI-900)
  • [2026] B.Sc. Computer Science, Afe Babalola University · CGPA 4.15/5.0
  • [2023] Complete Ethical Hacking Bootcamp · Udemy
  • [2023] Build Complete Inventory Management System A-Z · Udemy
  • [2021] Legacy JavaScript Algorithms and Data Structures
  • [cisc] Introduction to Cybersecurity · Cisco Networking Academy

// services

How I can help

Frontend Development

Responsive sites and admin dashboards with Bootstrap, JavaScript and Laravel Blade. Clean layouts that work on phones and desktops.

Penetration Testing

Web application testing with Burp Suite, business logic testing and responsible disclosure. Validated findings on HackerOne, Bugcrowd and Intigriti.

Backend Development

APIs and server-side logic with Laravel, Node.js and Python, plus database design in MySQL. Security code reviews included.

AR Development

Augmented reality experiences with Unity, C# and Vuforia, plus WebXR prototypes and custom 3D assets in Blender.

// testimonials

What clients say

"I hired Abdulsalam to make a website for me. Despite some delays it was completed expertly without any hiccups on the operational aspect. The site was well put together despite the budget given to him and also him having to juggle classes and personal life."

Ebi Buseri student

"I hired him to build a portfolio site for me, and he delivered. I like his approach to the site design and the admin functionality."

Carternimations 3d artist

"His creativity with AR technology is immensely good. Granted it could use some improvements in certain areas."

Adam Salami product manager

// contact

Let's work together

The fastest way to reach me is email. I usually reply within a day.