This companion is not a résumé. A résumé is a one-page document you read in thirty seconds. This companion is what you read after the résumé — when you have decided the products deserve closer inspection.
Every product here follows one design rule: every claim must be verifiable. Every number is measurable in a running system. Every architectural choice is defended by a public commit, a working demo, or a peer-review-ready research paper.
Inside this catalog you will find twelve shipping products, three research papers, six Kaggle competitions, thirteen responsible-disclosure engagements (including a Google OSS VRP S0/P0 acceptance and a live-verified CVSS 9.1 Cal.com submission), and two hire-signal open-source contributions at PostHog and Supabase. Each product page states what the product does, what makes it different from its category, the technical signature that gives it edge, and the verified numbers behind its claims.
Every claim in this document is externally verifiable. Below is a single index of the public URLs that back the numbers. If a reviewer wants to independently confirm a specific claim, the corresponding link resolves to the artifact — a merged PR, a published paper, a live demo, a Kaggle placement, an accepted bounty report, or a public product landing page.
MutationBuffer.processBufferedMutations O(n²) → O(n)); shadow-DOM-aware walk-up loop · pull/5244 · in reviewJWT_JWKS (closes #629, open 607 days). Pure helper avoiding circular logger dep; 25 new tests incl. a jose round-trip proof · pull/1488 · in review571135577 · In Panel Review · byte-identical un-patched sibling across 6 AOSP branches (android14-qpr3 → android17-release, 25 months of ASB silence); live binary verification from Android 16 QPR1 emulator image563082721 · S0/P0 Accepted569156158 · AI-triage done, human review569269080 · P1 (upgraded in 5 min)569402823 · AI-triage done, human review569575994 · In triage#3914035 · Accepted0e7d2c90 · Acceptedapp.cal.qa) · Bugcrowd 30c5dfcecf0acebeNexusZone0001#4024682 · vendor review#3919475 · in triage8a7425f0f83be6be6d26be3a696307c8Bugcrowd / HackerOne submission pages require program-side authorization to view. Full triager conversations, PoC videos, patch drafts, and evidence bundles are available under NDA on request.
abdarahman10555@gmail.com · +20 120 853 1520Nexus Zone is the umbrella brand under which every product in this catalog ships. The name unifies two heritages:
Nexus Zone operates in eight service lines, each backed by at least one shipping product:
Nexus Zone is the first Arab-founded technology house to combine consumer-facing gaming products (Golden Arena, Waraq Reader) with enterprise-grade engineering tooling (LucidCode, Laundry) under a single Charter. A single customer can build a game, secure a website, modernise legacy code, and receive an Arabic radiology report — from one origin.
Public site: 61465.github.io/game-zone-hub
Founder: game_nexus_zone.
LucidCode is a developer-experience tool that grants source code cognitive self-awareness. Instead of running static rules over a file, LucidCode makes the code confess in first person — and rigorously refutes any confession that cannot be proven.
Every confession passes through three independent verifiers before it reaches the user: (1) a deterministic AST re-verifier weighted at 0.90, (2) a sandboxed fuzzer weighted at 0.70, (3) an adversarial LLM devil weighted at 0.40. A Bayesian aggregator produces a calibrated verdict. Hallucinated confessions are logged internally and never displayed.
12 CLI sub-commands · VS Code VSIX extension · CodeQL query pack · GitHub App scaffold · arXiv-ready whitepaper · Firecracker sandbox · Ring orchestrator (Red-Hat + War-Gaming + Human-Triage roles).
Field-validated on 3 real production repositories. Benchmark suite of 22 CVE-inspired fixtures achieves F1 = 1.00. Commercial licence live under Nexus Zone Commercial 1.0. B2B pricing tier ready.
Landing page: 61465.github.io/lucid/landing
Laundry is a legacy-code modernization pipeline that never merges. It runs twelve specialised agents on a target repository and produces one signed evidence bundle a human engineer can approve — with a full before/after explanation for every unit of code.
At session start Laundry loads a Charter of ten runtime-immutable rules — no auto-merge, evidence before edit, judge never writes code, uncited claims dropped, dead code needs two independent proofs, and more. The Charter is stored in a MappingProxyType at runtime; any mutation attempt raises TypeError. The Charter protects the tool from the tool's operator.
Each agent has one job. The judge never writes code. The updater refuses to run without a passing baseline. The parity agent isolates every patch in a sandbox before accepting it.
21 LLM providers wired (Anthropic, OpenAI, Groq, Cerebras, Gemini, Bedrock, Vertex, and more). 15 integration categories (Slack, Sentry, Jira, Linear, etc.) via 138 documented environment keys. SARIF export lands directly in GitHub / GitLab / Azure DevOps code-scanning surfaces. HMAC signed-override protocol enforces human authorisation before any gate is bypassed.
Interactive live demo: 61465.github.io/lucid/landing/laundry.html (runs against psf/requests v2.7.0, May 2015).
Most teams ship one or three agents. NEXUS-AI ships a 134-agent catalog — thirteen in active production rotation, the remainder in a specialist reserve pool. The value is not in the raw count; it is in the coordination layer (Meta-Router + Verified Runner + hash-chained audit) and the Cyber Grounding Gate — a five-verifier LLM-hallucination filter that has stripped 724 fabricated claims across 770 gate calls in production, backed by 173 curated knowledge rules and a 166-CVE offline cache. Doctor status: 6/6 GREEN · 179 tests passing.
Every request enters through the Meta-Router, a rule-based classifier that maps the request to a task type (code_gen · reasoning · web_search · vision · osint · writing …) and then dispatches to the correct agent and the cheapest capable model. Verified 100% classification accuracy on a 13-request live test suite spanning real production traffic.
Every agent response is filtered through three tiers before it leaves the fabric: (1) Tier-0 schema check, (2) Tier-1 NLI self-check, (3) 13-signature injection detector. Only fully-cleared responses reach the caller.
For composite tasks, the Company Orchestrator decomposes the request into sub-tasks, dispatches them in parallel across specialised agents, verifies each result, and merges. Functionally, one call yields the output of an engineering department — at LLM latency.
NEXUS-AI is the shared brain across midcine (radiology inference orchestration), thawani.cc (customer-response automations), and internal engineering workflows. The Meta-Router prefers free-tier providers (Naraya · Groq · Cerebras · Gemini · OpenRouter — sixteen providers total), which drives real per-request cost close to zero. Every cyber-agent output is post-processed through the grounding gate: browser-security invariants, OAuth flow rules, CVE cross-check, identifier grep-existence, and chain-step reproducibility labelling — hallucinated claims are stripped before they reach the user.
Most radiology-AI products run in US-hosted clouds. MENA hospitals cannot legally send patient scans there. midcine is designed to run inside the hospital firewall — no external network access unless explicitly authorised — and to write reports directly in Arabic, signed as standard DICOM SR objects.
midcine does not rely on a single model. Its pipeline chains a Vision Classifier (lesion class), a Detection Model (bounding boxes), a Segmentation Model (volume maps), a Vision-Language reader (radiological description), and a Clinical LLM (final report composition). Each model cross-verifies the previous one; disagreements route to a human reviewer.
Egyptian hospital networks are unreliable. midcine ships with Ollama fallbacks so an entire study can be read without any Internet connection. Optional premium services (TotalSegmentator, external PACS bridging) are opt-in.
Live demo: ame.tail19ddab.ts.net:8445/reports (private Tailscale Funnel · synthetic patients).
Source showcase: github.com/61465/midcine
Where midcine owns the reading side of radiology, MEDNEXA owns the wiring between the hospital's existing HIS, LIS, PACS, and clinical workflows. Egyptian mid-market hospitals typically run three or four disconnected vendor systems; MEDNEXA stitches them together with real HL7v2 / FHIR R4 / DICOM pipes, PDPC-compliant consent management, and a hash-chained audit log that makes any after-the-fact mutation detectable.
C-STORE and C-FIND Modality Worklist on port 11112.ADT / ORM / ORU / OUL / MDM, piping into FHIR R4 builders (Observation, DiagnosticReport, ServiceRequest, Patient, Practitioner).draft → signed → finalized → amended with full audit trace at every transition.prev_hash + hash) — any mutation after the fact is detectable.Every state transition in the engine (login, report sign, DICOM store, consent grant, export) writes an entry carrying both its own SHA-256 and the previous entry's SHA-256. Rolling back the audit log requires rolling back every subsequent entry too — which is detectable at verification time. This is the core of the PDPC Law 151/2020 defensive posture.
Pilot deployments expose Admin · Radiologist · Doctor (referring) · Patient. Scoped-ACL enforcement means the referring doctor sees only the patients a patient has consented to for them, with admin approval also required — a two-key gate per access, logged.
The strategy, 15-slide pitch deck, 36-month × 3-scenario financial model, DPA (PDPC Law 151/2020-aligned) + SLA + SOW templates, 30-question discovery questionnaire, ROI calculator, and the engine source itself live under commercial license and ship under NDA for pilot evaluations. The showcase repository on GitHub contains the README, brand, and compliance posture only.
Every WhatsApp-commerce project hits the same wall: Meta bans sessions. Meta's own baseline ban rate is 0.5%. At scale, that means one tenant lost every day.
thawani.cc treats the ban problem as an engineering problem, not an operational one. The response is a 26-layer defence stack operating in parallel.
Stealth Mode v2 · Behavior Analyzer + Gatekeeper (a seven-rule 0–100 scoring model) · Phase-2A humanisation · adaptive rate limiting · reputation tracking · phone-uniqueness enforcement · and twenty other independent layers. Compound effect: the observed ban rate drops from Meta's 0.5% baseline to 0.1% — a five-fold improvement across live tenants.
Salla is Saudi Arabia's largest e-commerce platform (55,000+ MENA stores). Phase 1 is live: OAuth 2.0 + Webhooks + product sync + disconnect. Every Salla store can convert to a thawani tenant with a single button.
SAR 50 / store / month via Meta WhatsApp Cloud API in Tech-Provider mode. Even a 1% Salla penetration yields SAR 27,500 monthly recurring revenue. Six-vertical shared-kernel design keeps unit economics healthy across scale.
Most AI models are "for everyone." ARIA is deliberately not. ARIA is designed to grow through an exclusive relationship with a single human — it has memory, a personality, autonomous background cognition, and a curiosity engine that asks real questions to fill its sensory blind spots.
Every hour, a background "curiosity" pass reviews the day's conversations, identifies gaps in the model's world model, and formulates targeted questions the human is prompted to answer. Over time ARIA knows its owner better than any general-purpose assistant.
ARIA is not currently for sale. It is a life pattern. Once the internal loop is fully stabilised, the underlying infrastructure will be released as a hosted SaaS so any individual can build their own sovereign companion.
coder15b_final — merged LoRA adapter (17.4 MB safetensors + tokenizer + inference.py + chat template).US municipalities spend millions removing abandoned vehicles. They do not know the vehicle's age, its owner history, or whether it is subject to manufacturer recall. NEXUS Vigil™ resolves all three in a single API call.
The product fuses two of the strongest open datasets in North America: Mapillary (crowdsourced street imagery at scale) and NHTSA (vehicle-manufacturer and recall data). Vigil captures a plate, resolves make/year, checks recall status, and opens a case file — in seconds.
Full intellectual-property ownership. Municipalities buy subscription access; live SQLite database auto-updates. Coverage: Massachusetts, Connecticut, Rhode Island, New Hampshire, Vermont, Maine — plus 40 individual cities. Roadmap: EU municipalities.
Four products operate together as a single security fabric:
32 registered security tools (Amass, Nuclei, Metasploit, CodeQL, garak, PyRIT, Shodan, Censys, and more) plus 4 live threat-intelligence feeds (GreyNoise · Leakix · urlscan · PublicWWW) exposed behind seven REST endpoints. A single command nexus-audit <target> wraps 10+ SAST/DAST tools with automatic language detection and language-specific rule packs.
One architectural rule: LLM proposes → tools produce evidence → policy decides → agent executes within capability bounds. Inter-agent handoffs are typed artifacts, never prose. Every state mutation is a validated, logged tool call.
Windows SIEM + SOAR + ML in one bundle. For organisations that need endpoint protection on Windows without paying CrowdStrike enterprise pricing. Terminal companion (sentinel-cli) ships as a stand-alone open showcase repository.
A local engine that ingests findings from Semgrep, Nuclei, and CodeQL and re-ranks them by real exploitability, not theoretical severity. Saves security teams days of noise triage per week.
Six shipped consumer products serving the Arabic gaming audience:
A fantasy arena that pits characters from anime, video games, and film. AI analyses each character's abilities; an ELO system ranks them; an interactive tier list surfaces the meta.
URL: 61465.github.io/game-zone-golden
200 characters × 200 games × 60+ franchises. An AI "DNA" analyser produces personalised game recommendations.
URL: 61465.github.io/game-zone-archive
An interactive narrative experience about memory and identity. Every decision alters the ending.
URL: 61465.github.io/game-zone-game
Voice rooms, embedded mini-games, rank & XP system — an Arabic-first alternative to Discord for the MENA gamer community.
URL: 61465.github.io/GAME-ZONE-CHAT
Multi-language reading with four study modes and Arabic AI translation support. Positioned as an educational reader for MENA students.
URL: 61465.github.io/read
Compares games and hardware using radar charts and structured text analysis.
URL: 61465.github.io/game-zone-CONFIGURATOR
A full AI health coach delivered inside WhatsApp. Baileys + Groq stack. 16 REST endpoints. Groq-Vision meal analysis. Auto-generated weekly weight-tracking PNGs. Eleven achievement badges. Six context-aware alert types on a 10 AM / 6 PM scheduler. Exercise library with TTS audio. Family mode. Forty-feature admin dashboard.
A cyber range with thirty planted vulnerabilities spanning OWASP Top-10 · fintech-specific · Next.js SSR · API misc. Coverage validated at 86% by an automated NEXUS attack loop. Positioned for corporate security-team training.
End-to-end restaurant operations. Menu with 200+ items. Deployed for one MENA operator. Prisma schema ready for multi-tenant rollout.
Multi-channel operations dashboard for MENA food-delivery brands. Shift KPIs. Voice dictation. Supabase sync.
A four-pillar defence framework against indirect prompt injection targeting autonomous AI agents: (1) least-privilege scoping, (2) tamper-evident observability, (3) synthetic deception, (4) human-gated remediation.
8,000-session AgentDojo benchmark. 90.6% adversarial containment at 5.9% false-positive rate. Least-privilege pillar alone reaches 56.5% containment at 0% FPR.
Three novel cryptographic protocols (BDSP · STCHP · HS-CPP) for zero-trace fragmentation of sensitive data plus decoy-based threat saturation. The core innovation: instead of encrypting the data, shatter it into individually meaningless fragments, distribute them, and populate the space with plausible decoys that saturate any adversary's search budget.
The academic paper behind LucidCode. Unifies compositional reasoning, adversarial mutation testing, provenance tracking, citation enforcement, and a zero-LLM truth path. Central philosophical claim: you do not need a language model to know the truth — you only need one to describe it.
10,187 teams competed across four live Kaggle tracks. Independent submissions against university and corporate teams. Verified final scores (JED competition finalized 2026-09-03):
Extracted from twelve failed modification attempts across three competitions: clone the strongest public notebook verbatim first, tune one knob per submission, never combine changes. Eleven of twelve exploratory modifications regressed. The playbook is now a shared internal artefact for future Kaggle work.
Twenty+ engagements across Google ASR / OSS VRP / Cloud VRP, HackerOne, Bugcrowd, Trend Micro ZDI, GitHub Security Advisories, and internal ranges. October 2026 added the APDS methodology submission to Google Android ASR (CVSS 10.0 Critical, in panel review), two accepted GHSAs (Trigger.dev CVSS 9.6 + Documenso 7.6 in triage), and five further Google VRP tickets. Earlier accepted: Google Gemini CLI S0/P0, Syfe CVSS 8.6, Gearset P3.
| Program | Platform | Severity | Vulnerability | Status |
|---|---|---|---|---|
| Google Android ASR | Issue 571135577 | CVSS 10.0 | APDS methodology + CVE-2024-40658 symmetric sibling. First formal application of Asymmetric Patch Detection for Symmetric APIs. Un-patched sibling of CVE-2024-40658 byte-identical across 6 AOSP branches (android14-qpr3 → android17-release) for 25 months of ASB silence. Live binary verification from a Google-published Android 16 QPR1 emulator image (security patch 2026-01-05). 3/3 reproduction runs captured. Open-sourced the reference tool as apds-hunt within 24 h of the submission commitment. |
In Panel Review |
| Trigger.dev | GHSA-65rr-73jq-6qhf | CVSS 9.6 | Accepted by @ChrisArderne on 2026-10-07. 90-day disclosure clock running. | Accepted |
| Documenso | GHSA-2rp7-mrh6-v9m2 | CVSS 7.6 | Rejected-recipient field forgery across 3 tRPC routes. First-ever GHSA on the Documenso repo. | In Triage |
| Google Cloud VRP | Issue 569156158 | CVSS 9.9 | Vertex AI pickle cross-tenant RCE — pickle_object_gcs_uri free-form path → Vertex Agent Engine arbitrary code execution across tenant boundaries. |
AI-triage done |
| Google OSS VRP | Issue 569269080 | CVSS 9.6 | Google ADK — AgentRegistry sends Google Cloud ADC OAuth token to ANY registered MCP URL. P1 upgraded by panel in 5 minutes. | P1 Upgraded |
| Google Cloud VRP | Issue 569402823 | CVSS 9.9 | Agent Builder — RLHF poisoning via feedbackEntries + memory-banks BOLA. |
AI-triage done |
| Google Cloud VRP | Issue 569575994 | CVSS 10.0 | Agent Builder — CodeExecutionMetric.custom_function arbitrary Python RCE via 5 endpoints; 6 code-execution primitives; GDPR/HIPAA bypass via 24-region sandbox-shopping. |
In Triage |
| Google OSS VRP | Issue 563082721 | S0 / P0 | Gemini CLI chained RCE — 6-defect zero-click supply-chain chain, CVSS 10.0. Security engineer took over, linked to a blocked-by bug. Panel decision in 2–3 weeks; expected reward band $30K–$75K. | Accepted |
| Syfe | HackerOne #3914035 | CVSS 8.6 | Web Cache Deception (CWE-524) | Accepted |
| Gearset | Bugcrowd 0e7d2c90 | P3 | Excessive GitHub-OAuth scope (repo + write:repo_hook) on staging.claytonapp.com | Accepted |
| Cal.com | Bugcrowd 30c5dfce | CVSS 9.1 | Unauthenticated zero-click PII disclosure in getBookingForReschedule — two compound defects (authorization gated behind seat check + inverted attendees ternary). Two public getServerSideProps sinks. Live-verified on app.cal.qa: a fresh browser context with zero cookies received an HTTP 200 whose HTML body contained the full attendees[] record (email + name + bookingSeat) plus responses, customInputs, location, and times. Delivered with a video PoC, a proof panel, the verbatim response body, and a tested private patch. |
Submitted |
| OpenAI Safety | Bugcrowd cf0acebe | P1 | Cross-tenant PII leakage across 7 production models (5 chained failure modes — HIPAA, GLBA, attorney-client, SEC-material, HR insider). Silent-execution deception proven. | Submitted |
| Trend Micro ZDI | NexusZone0001 | CVSS 9.0 | Windows fcon.dll + wosc.dll signature-verify gap via WNF cache poison — proof the NEXUS pipeline works end-to-end on Windows binaries. | Submitted |
| xAI Grok | HackerOne #4024682 | — | Cross-model system-prompt disclosure on Grok API. Canary 5/5 ASR on grok-4.20-non-reasoning + grok-build-0.1. 7 data classes leaked (PHI / GLBA / SEC / AWS / legal / M&A / HR). Tool-chain exfil proven; distinct from Adversa Aug '26. | Vendor Review |
| Shopify | HackerOne #3919475 | CVSS 8.7 | Unified 7-vector chain (UCP SSRF + GCP trace leak + OTLP unauth + tenant spoof + schema oracle) | Triage |
| AXIS OS | Bugcrowd 8a7425f0 | P2 | ACAP D-Bus wildcard bypass of CVE-2025-5452 (firmware-validated on M1075-L 12.11.77) | Submitted |
| eToro | Bugcrowd f83be6be | P1 | 1-click ATO on Delta Desktop (6 chained bugs, live PoC) | Submitted |
| Okta AtSpoke | Bugcrowd 6d26be3a | P1 | Application-wide CSRF via hardcoded XSRF-TOKEN=JustAskSpoke! |
Submitted |
| Magic Labs | Bugcrowd 696307c8 | P3 | reCAPTCHA bypass + user enumeration (13 staff accounts confirmed, including CEO and CTO) | Submitted |
| GZ CyberRange (self-built lab) | Internal | — | 30-vulnerability fintech training lab; 86% hunter coverage validated | Live |
Two contribution-first PRs opened at engineering companies with public "we hire from our contributor pool" culture. Each PR was designed to sit at the intersection of a real user-facing bug and a technical difficulty bar the maintainers care about, and each was accompanied by a 4-element response protocol (acknowledge / state change / evidence / offer flexibility) developed and locked over the last two sessions.
Regex-based detector of impossible Chrome patch/build tuples embedded in user-agent strings — closes a long-standing PostHog issue about a Chrome-forged bot family that other detectors miss. Delivered with a 5.1×–10.9× perf leap over the naive baseline, 32 new unit tests pushing coverage on the new file to 98.32%, the full 2,095 / 2,095 core suite green, and a 5/5 Wiz-scan pass. Blocking review from @marandaneto surfaced a live-Chrome edge case (Chrome 154.0.8037.58 and 155.0.8059.12 already shipping); fixed surgically by removing the build-ceiling rule the same session and posting a 4-part reply within the 4-hour SLA.
Revives the direction of PR #875 with a scope-controlled patch: expands the allowed object-key character set to full UTF-8, rejects 17 zero-width / bidi / C1-control codepoints to prevent homograph attacks, and fixes two latent bugs discovered in the process (backslash escape, path traversal). 76 / 76 tests pass, 10,000 Hypothesis-driven fuzz cases pass, plus a benchmark run. When Supabase's depthfirst-app bot flagged four additional Unicode codepoints, all four were added to the reject list with tests in the same session. Staff maintainer @ferhatelmas engaged twice; awaiting a decision on how to sequence the follow-up work.
Every product in this catalog is real, published, and independently verifiable. Requests for evaluation copies, pilot programmes, licensing conversations, or research collaboration are welcomed.
CONTACT
Response within one business day.
Nexus Zone — Where technology meets craft.
Founded by game_nexus_zone · Portfolio Companion Edition 2026