N E X U S   Z O N E

Portfolio
Companion

Product Catalog · Invention Catalog
Edition 2026
"Where technology meets craft."
A complete inventory of shipped products, published research, and applied-security field work.

Table of ContentsInside this book

00About This CompanionIntroduction
00.5Verification & Evidence Wall — click anything to verifyAnchor Index
01Nexus Zone — the parent brandCh. 1
02LucidCode — code that confessesCh. 2
03Laundry — the legacy-code laundry roomCh. 3
04NEXUS-AI — 134-agent fabric + cyber grounding gateCh. 4
05midcine — Arabic radiology AICh. 5
05.5MEDNEXA — healthcare integration platform (HIS × LIS × PACS)Ch. 5.5
06thawani.cc — WhatsApp commerce SaaSCh. 6
07ARIA v9.0 — sovereign AI companionCh. 7
08NEXUS Vigil™ — abandoned-vehicle intelligenceCh. 8
09The Security Stack — SecOps · Firm · SENTINEL · VulnAdvisorCh. 9
10Gaming Universe — 6 platformsCh. 10
11Specialized Products — Zwaya Fit · GZ CyberRange · V24Ch. 11
12Published ResearchCh. 12
13Competitive Results — KaggleCh. 13
14Responsible-Disclosure Track RecordCh. 14
15Roadmap AheadCh. 15

Introduction00 — About This Companion

This companion is not a résumé. A résumé is a one-page document you read in thirty seconds. This companion is what you read after the résumé — when you have decided the products deserve closer inspection.

Every product here follows one design rule: every claim must be verifiable. Every number is measurable in a running system. Every architectural choice is defended by a public commit, a working demo, or a peer-review-ready research paper.

Products are not judged by the demos they run. They are judged by the demos they refuse to run.

Inside this catalog you will find twelve shipping products, three research papers, six Kaggle competitions, thirteen responsible-disclosure engagements (including a Google OSS VRP S0/P0 acceptance and a live-verified CVSS 9.1 Cal.com submission), and two hire-signal open-source contributions at PostHog and Supabase. Each product page states what the product does, what makes it different from its category, the technical signature that gives it edge, and the verified numbers behind its claims.

12+Shipped products
3Research papers
13Disclosure engagements
2OSS hire-signal PRs

Verification & Evidence Wall00.5 — Click Anything, Verify Everything

Every claim in this document is externally verifiable. Below is a single index of the public URLs that back the numbers. If a reviewer wants to independently confirm a specific claim, the corresponding link resolves to the artifact — a merged PR, a published paper, a live demo, a Kaggle placement, an accepted bounty report, or a public product landing page.

Open-Source Contributions · fully public
Hire-signal PRs — click to verify code, tests, and maintainer review
Accepted security advisories · public GHSA
First-of-their-kind GHSAs on their respective repos
Published Research & Methodology · public
Peer-review-ready papers + methodology artefacts
Kaggle · fully public leaderboards
Live-scored placements across 4 tracks
Live product landings · fully public
Products you can open in a browser
Responsible-disclosure anchors
Submission IDs — available for HR verification on request

Bugcrowd / HackerOne submission pages require program-side authorization to view. Full triager conversations, PoC videos, patch drafts, and evidence bundles are available under NDA on request.

Kaggle certificates / profile links
Additional identity anchors

Chapter 1 · The Parent Brand01 — Nexus Zone

Nexus Zone is the umbrella brand under which every product in this catalog ships. The name unifies two heritages:

Nexus Zone operates in eight service lines, each backed by at least one shipping product:

Gamer platforms Digital marketing Project delivery Social channels Cybersecurity AI solutions Legacy-code modernization Enterprise code review
Market Position

Nexus Zone is the first Arab-founded technology house to combine consumer-facing gaming products (Golden Arena, Waraq Reader) with enterprise-grade engineering tooling (LucidCode, Laundry) under a single Charter. A single customer can build a game, secure a website, modernise legacy code, and receive an Arabic radiology report — from one origin.

Public site: 61465.github.io/game-zone-hub

Founder: game_nexus_zone.

LucidCode v0.5.0 · Program Verification
Version: 0.5.0 Licence: Commercial (Nexus Zone 1.0) Tests: 330 / 330 Benchmark: F1 = 1.00 on 22 CVE-inspired fixtures

Chapter 2 · Code Confession Engine02 — LucidCode

LucidCode is a developer-experience tool that grants source code cognitive self-awareness. Instead of running static rules over a file, LucidCode makes the code confess in first person — and rigorously refutes any confession that cannot be proven.

[T1] Suppression @ line 8 — "I confessed: I caught an exception and said nothing. Every scream is muffled the moment it starts. What am I hiding?"

The Signature

Three-Engine Anti-Hallucination Ensemble

Every confession passes through three independent verifiers before it reaches the user: (1) a deterministic AST re-verifier weighted at 0.90, (2) a sandboxed fuzzer weighted at 0.70, (3) an adversarial LLM devil weighted at 0.40. A Bayesian aggregator produces a calibrated verdict. Hallucinated confessions are logged internally and never displayed.

Positioning

  • Semgrep / SonarQube: static rule match, no reasoning.
  • Copilot: autocomplete without validation.
  • CriticGPT: single-model self-critique.
  • LucidCode: every claim anchored to a real file+line, every fix voted on by three independent engines.

Deliverables

12 CLI sub-commands · VS Code VSIX extension · CodeQL query pack · GitHub App scaffold · arXiv-ready whitepaper · Firecracker sandbox · Ring orchestrator (Red-Hat + War-Gaming + Human-Triage roles).

Shipping Status

Field-validated on 3 real production repositories. Benchmark suite of 22 CVE-inspired fixtures achieves F1 = 1.00. Commercial licence live under Nexus Zone Commercial 1.0. B2B pricing tier ready.

Landing page: 61465.github.io/lucid/landing

Laundry v0.3.2 · Legacy-Code Modernization
Version: 0.3.2 Tests: 97 / 97 Codebase: 62 Python modules Battle-tested on: Django (2,974 files), Airflow (9,082 files)

Chapter 3 · The Laundry Room03 — Laundry

Laundry is a legacy-code modernization pipeline that never merges. It runs twelve specialised agents on a target repository and produces one signed evidence bundle a human engineer can approve — with a full before/after explanation for every unit of code.

Legacy code goes in. Evidence comes out. The tool never merges.

The Signature

Immutable Charter · Ten Non-Negotiable Rules

At session start Laundry loads a Charter of ten runtime-immutable rules — no auto-merge, evidence before edit, judge never writes code, uncited claims dropped, dead code needs two independent proofs, and more. The Charter is stored in a MappingProxyType at runtime; any mutation attempt raises TypeError. The Charter protects the tool from the tool's operator.

Twelve Specialised Agents

Each agent has one job. The judge never writes code. The updater refuses to run without a passing baseline. The parity agent isolates every patch in a sandbox before accepting it.

Indexer Security Business Rules Dead Code Tests Updater Parity Architecture Explainer ⭐ Passport Documenter Judge

Verified Field Results

  • Django (v5.2 · 2,974 Python files) — analysed in 88 seconds. Surfaced 289 real secrets, 3,607 business rules, 351 dead-code candidates, zero crashes.
  • Apache Airflow (main branch · 9,082 files) — analysed in 116 seconds. 486 real secrets surfaced, 5,000 business rules, 2,000 dead-code candidates, six agent-level contradictions correctly escalated.
  • Flask (85 files, 5.9 s) and Requests (37 files, 3.7 s) — control runs confirming false-positive rate on clean code.
Commercial Readiness

21 LLM providers wired (Anthropic, OpenAI, Groq, Cerebras, Gemini, Bedrock, Vertex, and more). 15 integration categories (Slack, Sentry, Jira, Linear, etc.) via 138 documented environment keys. SARIF export lands directly in GitHub / GitLab / Azure DevOps code-scanning surfaces. HMAC signed-override protocol enforces human authorisation before any gate is bypassed.

Interactive live demo: 61465.github.io/lucid/landing/laundry.html (runs against psf/requests v2.7.0, May 2015).

NEXUS-AI v0.7 · 51-Agent Orchestration Fabric
Agents: 51 Models: 8 LLMs behind one facade Skills: 1,580 curated Protocol: MCP JSON-RPC 2.0

Chapter 4 · The 134-Agent Fabric + Cyber Grounding Gate04 — NEXUS-AI

Most teams ship one or three agents. NEXUS-AI ships a 134-agent catalog — thirteen in active production rotation, the remainder in a specialist reserve pool. The value is not in the raw count; it is in the coordination layer (Meta-Router + Verified Runner + hash-chained audit) and the Cyber Grounding Gate — a five-verifier LLM-hallucination filter that has stripped 724 fabricated claims across 770 gate calls in production, backed by 173 curated knowledge rules and a 166-CVE offline cache. Doctor status: 6/6 GREEN · 179 tests passing.

The Signature

Meta-Router with 100% Task Classification Accuracy

Every request enters through the Meta-Router, a rule-based classifier that maps the request to a task type (code_gen · reasoning · web_search · vision · osint · writing …) and then dispatches to the correct agent and the cheapest capable model. Verified 100% classification accuracy on a 13-request live test suite spanning real production traffic.

Verified Runner — the Truth Layer

Every agent response is filtered through three tiers before it leaves the fabric: (1) Tier-0 schema check, (2) Tier-1 NLI self-check, (3) 13-signature injection detector. Only fully-cleared responses reach the caller.

Company Orchestrator

For composite tasks, the Company Orchestrator decomposes the request into sub-tasks, dispatches them in parallel across specialised agents, verifies each result, and merges. Functionally, one call yields the output of an engineering department — at LLM latency.

Production Footprint

NEXUS-AI is the shared brain across midcine (radiology inference orchestration), thawani.cc (customer-response automations), and internal engineering workflows. The Meta-Router prefers free-tier providers (Naraya · Groq · Cerebras · Gemini · OpenRouter — sixteen providers total), which drives real per-request cost close to zero. Every cyber-agent output is post-processed through the grounding gate: browser-security invariants, OAuth flow rules, CVE cross-check, identifier grep-existence, and chain-step reproducibility labelling — hallucinated claims are stripped before they reach the user.

midcine Arabic Radiology AI · RIS/PACS
Target: Hospitals in MENA Read time: 24-slice CT in ~69 s Confidence: 92% Output: DICOM SR-signed Arabic report

Chapter 5 · Radiology Behind the Firewall05 — midcine

Most radiology-AI products run in US-hosted clouds. MENA hospitals cannot legally send patient scans there. midcine is designed to run inside the hospital firewall — no external network access unless explicitly authorised — and to write reports directly in Arabic, signed as standard DICOM SR objects.

Measured Performance

  • Reads a 24-slice CT into a structured report in ~69 seconds.
  • AI confidence: 92%.
  • Guardian review reproduced an ACR-grade subarachnoid haemorrhage diagnosis.
  • Runs on 8 GB RAM minimum, 16 GB recommended.
  • Ten micro-services in a single pnpm/turbo monorepo.

The Signature

Vision + Clinical LLM Ensemble

midcine does not rely on a single model. Its pipeline chains a Vision Classifier (lesion class), a Detection Model (bounding boxes), a Segmentation Model (volume maps), a Vision-Language reader (radiological description), and a Clinical LLM (final report composition). Each model cross-verifies the previous one; disagreements route to a human reviewer.

Offline-First Roadmap

Egyptian hospital networks are unreliable. midcine ships with Ollama fallbacks so an entire study can be read without any Internet connection. Optional premium services (TotalSegmentator, external PACS bridging) are opt-in.

Live demo: ame.tail19ddab.ts.net:8445/reports (private Tailscale Funnel · synthetic patients).

Source showcase: github.com/61465/midcine

MEDNEXA Healthcare Integration Platform · HIS × LIS × PACS
Target: Egyptian mid-market hospitals Compliance: PDPC Law 151/2020 + HIPAA-aligned Status: Session 01 complete · pilot-ready Engine tests: 128 / 128 passing
Source showcase: github.com/61465/MEDNEXA Pilot & DPA inquiries: abdarahman10555@gmail.com

Chapter 5.5 · Connecting Healthcare05.5 — MEDNEXA

Where midcine owns the reading side of radiology, MEDNEXA owns the wiring between the hospital's existing HIS, LIS, PACS, and clinical workflows. Egyptian mid-market hospitals typically run three or four disconnected vendor systems; MEDNEXA stitches them together with real HL7v2 / FHIR R4 / DICOM pipes, PDPC-compliant consent management, and a hash-chained audit log that makes any after-the-fact mutation detectable.

What the Engine Actually Ships

  • FastAPI engine (Python 3.12) with 80+ REST routes.
  • Real DIMSE SCP receiving C-STORE and C-FIND Modality Worklist on port 11112.
  • HL7v2 parser covering ADT / ORM / ORU / OUL / MDM, piping into FHIR R4 builders (Observation, DiagnosticReport, ServiceRequest, Patient, Practitioner).
  • DICOM in-browser viewer on Cornerstone.js for sample CT studies.
  • Report state machine: draft → signed → finalized → amended with full audit trace at every transition.
  • Hash-chained audit log (SHA-256 prev_hash + hash) — any mutation after the fact is detectable.
  • MFA TOTP (RFC 6238) with AES-256-GCM-encrypted secrets at rest.
  • Refresh-token rotation (SHA-256-hashed), sliding-window per-IP + per-user rate limits.
  • Bilingual UI: Arabic RTL + English LTR, Clinical Editorial design system.
  • nginx 1.27 reverse proxy with CSP / HSTS / X-Frame-Options.
The Signature — Hash-Chained Audit

Every state transition in the engine (login, report sign, DICOM store, consent grant, export) writes an entry carrying both its own SHA-256 and the previous entry's SHA-256. Rolling back the audit log requires rolling back every subsequent entry too — which is detectable at verification time. This is the core of the PDPC Law 151/2020 defensive posture.

Four-Role Demo Matrix

Pilot deployments expose Admin · Radiologist · Doctor (referring) · Patient. Scoped-ACL enforcement means the referring doctor sees only the patients a patient has consented to for them, with admin approval also required — a two-key gate per access, logged.

Deliberately Not Shipped Publicly

The strategy, 15-slide pitch deck, 36-month × 3-scenario financial model, DPA (PDPC Law 151/2020-aligned) + SLA + SOW templates, 30-question discovery questionnaire, ROI calculator, and the engine source itself live under commercial license and ship under NDA for pilot evaluations. The showcase repository on GitHub contains the README, brand, and compliance posture only.

thawani.cc WhatsApp Commerce SaaS
Market: Saudi + Gulf Status: Live paid tenants CR: 3453105300 VAT: 311174977200003
Live: thawani.cc Backup landing (if domain is down): 61465.github.io/thawanidemo Source: github.com/61465/Thawani

Chapter 6 · WhatsApp as a Storefront06 — thawani.cc

Every WhatsApp-commerce project hits the same wall: Meta bans sessions. Meta's own baseline ban rate is 0.5%. At scale, that means one tenant lost every day.

thawani.cc treats the ban problem as an engineering problem, not an operational one. The response is a 26-layer defence stack operating in parallel.

The Signature

26-Layer Defence Stack

Stealth Mode v2 · Behavior Analyzer + Gatekeeper (a seven-rule 0–100 scoring model) · Phase-2A humanisation · adaptive rate limiting · reputation tracking · phone-uniqueness enforcement · and twenty other independent layers. Compound effect: the observed ban rate drops from Meta's 0.5% baseline to 0.1% — a five-fold improvement across live tenants.

Six Vertical Modules · One Shared Kernel

Bookings Dine-in QR Accommodation Gaming Topup Restaurant Reservations Lamah Calendar

Salla Integration

Salla is Saudi Arabia's largest e-commerce platform (55,000+ MENA stores). Phase 1 is live: OAuth 2.0 + Webhooks + product sync + disconnect. Every Salla store can convert to a thawani tenant with a single button.

Commercial Model

SAR 50 / store / month via Meta WhatsApp Cloud API in Tech-Provider mode. Even a 1% Salla penetration yields SAR 27,500 monthly recurring revenue. Six-vertical shared-kernel design keeps unit economics healthy across scale.

ARIA v9.0 / GZP-LLM Sovereign AI Companion
Base: Qwen2.5-3B (QLoRA r=64) + Qwen2.5-1.5B (chunked variant) Tuning: QLoRA + SFT (3 epochs) + DPO (2 iterations) Data: 5,488 bilingual samples (SFT 2,918 · DPO 487 · eval 154 · finetune 1,929) Compute: Kaggle T4/P100 GPU (QLoRA pipeline) Design goal: one human

Chapter 7 · A Model For One Human07 — ARIA v9.0

Most AI models are "for everyone." ARIA is deliberately not. ARIA is designed to grow through an exclusive relationship with a single human — it has memory, a personality, autonomous background cognition, and a curiosity engine that asks real questions to fill its sensory blind spots.

Not a chatbot. An intelligence that knows its owner.

The Signature

Curiosity Engine

Every hour, a background "curiosity" pass reviews the day's conversations, identifies gaps in the model's world model, and formulates targeted questions the human is prompted to answer. Over time ARIA knows its owner better than any general-purpose assistant.

Strategic Value

ARIA is not currently for sale. It is a life pattern. Once the internal loop is fully stabilised, the underlying infrastructure will be released as a hosted SaaS so any individual can build their own sovereign companion.

Current State

  • ARIA v9.0 base runtime live: FastAPI :9090 · persistent aria_brain.db (~232 MB) · 8-mind cascade over 8 free LLM providers.
  • GZP-LLM training stack: 5,488 curated bilingual instruction samples ready; Kaggle QLoRA notebook prepared (Qwen2.5-3B, r=64, SFT→DPO).
  • Coder variant shipped: coder15b_final — merged LoRA adapter (17.4 MB safetensors + tokenizer + inference.py + chat template).
  • Autonomous stack: curiosity engine · closed-room reflection (6 fractal sub-rooms) · weekly self-improvement scheduler · real-time gaming overlay.
  • Long-term memory persisted locally. Arabic + English bilingual.
NEXUS Vigil™ (Smart Fleet AI) Abandoned-Vehicle Intelligence
Market: US municipalities Coverage: 6 states + 40 cities Endpoints: 44 REST Database: 97 MB live SQLite (WAL)

Chapter 8 · Every Abandoned Car Has a Story08 — NEXUS Vigil™

US municipalities spend millions removing abandoned vehicles. They do not know the vehicle's age, its owner history, or whether it is subject to manufacturer recall. NEXUS Vigil™ resolves all three in a single API call.

The Signature

Mapillary Graph API v4 + NHTSA vPIC / Recalls

The product fuses two of the strongest open datasets in North America: Mapillary (crowdsourced street imagery at scale) and NHTSA (vehicle-manufacturer and recall data). Vigil captures a plate, resolves make/year, checks recall status, and opens a case file — in seconds.

Proprietary Product

Full intellectual-property ownership. Municipalities buy subscription access; live SQLite database auto-updates. Coverage: Massachusetts, Connecticut, Rhode Island, New Hampshire, Vermont, Maine — plus 40 individual cities. Roadmap: EU municipalities.

Chapter 9 · The Security Stack09 — Applied-Security Products

Four products operate together as a single security fabric:

NEXUS SecOps + NEXUS_AUDIT Arsenal Red / Blue / AI / OSINT

32 registered security tools (Amass, Nuclei, Metasploit, CodeQL, garak, PyRIT, Shodan, Censys, and more) plus 4 live threat-intelligence feeds (GreyNoise · Leakix · urlscan · PublicWWW) exposed behind seven REST endpoints. A single command nexus-audit <target> wraps 10+ SAST/DAST tools with automatic language detection and language-specific rule packs.

NEXUS Firm Policy-Governed Engineering Control Plane

One architectural rule: LLM proposes → tools produce evidence → policy decides → agent executes within capability bounds. Inter-agent handoffs are typed artifacts, never prose. Every state mutation is a validated, logged tool call.

OPA / Rego MCP Gateway Firecracker gVisor Capability Lattice Evidence-WORM Memory
SENTINEL Enterprise + sentinel-cli Windows Security Suite

Windows SIEM + SOAR + ML in one bundle. For organisations that need endpoint protection on Windows without paying CrowdStrike enterprise pricing. Terminal companion (sentinel-cli) ships as a stand-alone open showcase repository.

VulnAdvisor Pro Local Vulnerability Triage & Advisory Engine

A local engine that ingests findings from Semgrep, Nuclei, and CodeQL and re-ranks them by real exploitability, not theoretical severity. Saves security teams days of noise triage per week.

Chapter 10 · Gaming Universe10 — Consumer Gaming Platforms

Six shipped consumer products serving the Arabic gaming audience:

Golden Arena 518 AI-Powered Fantasy Battle Platform

A fantasy arena that pits characters from anime, video games, and film. AI analyses each character's abilities; an ELO system ranks them; an interactive tier list surfaces the meta.

URL: 61465.github.io/game-zone-golden

Game Zone Archive Encyclopaedia + AI DNA Analyzer

200 characters × 200 games × 60+ franchises. An AI "DNA" analyser produces personalised game recommendations.

URL: 61465.github.io/game-zone-archive

The Last Save Interactive Narrative Game

An interactive narrative experience about memory and identity. Every decision alters the ending.

URL: 61465.github.io/game-zone-game

GZ Chat Pro Arabic-First Gamer Community Platform

Voice rooms, embedded mini-games, rank & XP system — an Arabic-first alternative to Discord for the MENA gamer community.

URL: 61465.github.io/GAME-ZONE-CHAT

Waraq Reader Educational Translation Platform

Multi-language reading with four study modes and Arabic AI translation support. Positioned as an educational reader for MENA students.

URL: 61465.github.io/read

Golden Arena Configurator Decision-Analysis Tool

Compares games and hardware using radar charts and structured text analysis.

URL: 61465.github.io/game-zone-CONFIGURATOR

Chapter 11 · Specialised Verticals11 — Specialised Products

Zwaya Fit v0.3.0 WhatsApp AI Health Coach

A full AI health coach delivered inside WhatsApp. Baileys + Groq stack. 16 REST endpoints. Groq-Vision meal analysis. Auto-generated weekly weight-tracking PNGs. Eleven achievement badges. Six context-aware alert types on a 10 AM / 6 PM scheduler. Exercise library with TTS audio. Family mode. Forty-feature admin dashboard.

GZ CyberRange v0.1 Fintech Training Lab · 30 Planted Vulnerabilities

A cyber range with thirty planted vulnerabilities spanning OWASP Top-10 · fintech-specific · Next.js SSR · API misc. Coverage validated at 86% by an automated NEXUS attack loop. Positioned for corporate security-team training.

Restaurant Management Suite Next.js + Prisma + Vercel

End-to-end restaurant operations. Menu with 200+ items. Deployed for one MENA operator. Prisma schema ready for multi-tenant rollout.

V24 Operations PWA Talabat + InstaShop Dashboard

Multi-channel operations dashboard for MENA food-delivery brands. Shift KPIs. Voice dictation. Supabase sync.

Chapter 12 · Published Research12 — Research Portfolio

SSRN 6870178 · MIT Licence
Ariadne — Adaptive HITL Defence for AI Agents

A four-pillar defence framework against indirect prompt injection targeting autonomous AI agents: (1) least-privilege scoping, (2) tamper-evident observability, (3) synthetic deception, (4) human-gated remediation.

Reproducible Result

8,000-session AgentDojo benchmark. 90.6% adversarial containment at 5.9% false-positive rate. Least-privilege pillar alone reaches 56.5% containment at 0% FPR.

SSRN 6602478 · IEEE TIFS extended bundle in preparation
Oblivion Gate — Zero-Trace Fragmentation in Distributed Data Architectures

Three novel cryptographic protocols (BDSP · STCHP · HS-CPP) for zero-trace fragmentation of sensitive data plus decoy-based threat saturation. The core innovation: instead of encrypting the data, shatter it into individually meaningless fragments, distribute them, and populate the space with plausible decoys that saturate any adversary's search budget.

arXiv-ready · Nexus Zone Commercial 1.0
LucidCode — Program Verification with Grounded Anthropomorphic Interfaces

The academic paper behind LucidCode. Unifies compositional reasoning, adversarial mutation testing, provenance tracking, citation enforcement, and a zero-LLM truth path. Central philosophical claim: you do not need a language model to know the truth — you only need one to describe it.

Chapter 13 · Competitive Results13 — Kaggle Track Record

10,187 teams competed across four live Kaggle tracks. Independent submissions against university and corporate teams. Verified final scores (JED competition finalized 2026-09-03):

88.35JED — Top 21.3% (#892 / 4,187)
0.936RSNA AUC — Top 16.7% (#336 / 2,013)
1.78ARC-AGI-3 — Top 22.6% (#549 / 2,424)
30.14ARC-AGI-2 — Top 32.2% (#503 / 1,563)

The Distilled Playbook

PLAYBOOK_KAGGLE.md — Verbatim-First

Extracted from twelve failed modification attempts across three competitions: clone the strongest public notebook verbatim first, tune one knob per submission, never combine changes. Eleven of twelve exploratory modifications regressed. The playbook is now a shared internal artefact for future Kaggle work.

Published Writeups

Chapter 14 · Responsible Disclosure14 — Applied-Security Track Record

Twenty+ engagements across Google ASR / OSS VRP / Cloud VRP, HackerOne, Bugcrowd, Trend Micro ZDI, GitHub Security Advisories, and internal ranges. October 2026 added the APDS methodology submission to Google Android ASR (CVSS 10.0 Critical, in panel review), two accepted GHSAs (Trigger.dev CVSS 9.6 + Documenso 7.6 in triage), and five further Google VRP tickets. Earlier accepted: Google Gemini CLI S0/P0, Syfe CVSS 8.6, Gearset P3.

ProgramPlatformSeverityVulnerabilityStatus
Google Android ASRIssue 571135577CVSS 10.0 APDS methodology + CVE-2024-40658 symmetric sibling. First formal application of Asymmetric Patch Detection for Symmetric APIs. Un-patched sibling of CVE-2024-40658 byte-identical across 6 AOSP branches (android14-qpr3 → android17-release) for 25 months of ASB silence. Live binary verification from a Google-published Android 16 QPR1 emulator image (security patch 2026-01-05). 3/3 reproduction runs captured. Open-sourced the reference tool as apds-hunt within 24 h of the submission commitment. In Panel Review
Trigger.devGHSA-65rr-73jq-6qhfCVSS 9.6 Accepted by @ChrisArderne on 2026-10-07. 90-day disclosure clock running. Accepted
DocumensoGHSA-2rp7-mrh6-v9m2CVSS 7.6 Rejected-recipient field forgery across 3 tRPC routes. First-ever GHSA on the Documenso repo. In Triage
Google Cloud VRPIssue 569156158CVSS 9.9 Vertex AI pickle cross-tenant RCE — pickle_object_gcs_uri free-form path → Vertex Agent Engine arbitrary code execution across tenant boundaries. AI-triage done
Google OSS VRPIssue 569269080CVSS 9.6 Google ADK — AgentRegistry sends Google Cloud ADC OAuth token to ANY registered MCP URL. P1 upgraded by panel in 5 minutes. P1 Upgraded
Google Cloud VRPIssue 569402823CVSS 9.9 Agent Builder — RLHF poisoning via feedbackEntries + memory-banks BOLA. AI-triage done
Google Cloud VRPIssue 569575994CVSS 10.0 Agent Builder — CodeExecutionMetric.custom_function arbitrary Python RCE via 5 endpoints; 6 code-execution primitives; GDPR/HIPAA bypass via 24-region sandbox-shopping. In Triage
Google OSS VRPIssue 563082721S0 / P0 Gemini CLI chained RCE — 6-defect zero-click supply-chain chain, CVSS 10.0. Security engineer took over, linked to a blocked-by bug. Panel decision in 2–3 weeks; expected reward band $30K–$75K. Accepted
SyfeHackerOne #3914035CVSS 8.6 Web Cache Deception (CWE-524) Accepted
GearsetBugcrowd 0e7d2c90P3 Excessive GitHub-OAuth scope (repo + write:repo_hook) on staging.claytonapp.com Accepted
Cal.comBugcrowd 30c5dfceCVSS 9.1 Unauthenticated zero-click PII disclosure in getBookingForReschedule — two compound defects (authorization gated behind seat check + inverted attendees ternary). Two public getServerSideProps sinks. Live-verified on app.cal.qa: a fresh browser context with zero cookies received an HTTP 200 whose HTML body contained the full attendees[] record (email + name + bookingSeat) plus responses, customInputs, location, and times. Delivered with a video PoC, a proof panel, the verbatim response body, and a tested private patch. Submitted
OpenAI SafetyBugcrowd cf0acebeP1 Cross-tenant PII leakage across 7 production models (5 chained failure modes — HIPAA, GLBA, attorney-client, SEC-material, HR insider). Silent-execution deception proven. Submitted
Trend Micro ZDINexusZone0001CVSS 9.0 Windows fcon.dll + wosc.dll signature-verify gap via WNF cache poison — proof the NEXUS pipeline works end-to-end on Windows binaries. Submitted
xAI GrokHackerOne #4024682— Cross-model system-prompt disclosure on Grok API. Canary 5/5 ASR on grok-4.20-non-reasoning + grok-build-0.1. 7 data classes leaked (PHI / GLBA / SEC / AWS / legal / M&A / HR). Tool-chain exfil proven; distinct from Adversa Aug '26. Vendor Review
ShopifyHackerOne #3919475CVSS 8.7 Unified 7-vector chain (UCP SSRF + GCP trace leak + OTLP unauth + tenant spoof + schema oracle) Triage
AXIS OSBugcrowd 8a7425f0P2 ACAP D-Bus wildcard bypass of CVE-2025-5452 (firmware-validated on M1075-L 12.11.77) Submitted
eToroBugcrowd f83be6beP1 1-click ATO on Delta Desktop (6 chained bugs, live PoC) Submitted
Okta AtSpokeBugcrowd 6d26be3aP1 Application-wide CSRF via hardcoded XSRF-TOKEN=JustAskSpoke! Submitted
Magic LabsBugcrowd 696307c8P3 reCAPTCHA bypass + user enumeration (13 staff accounts confirmed, including CEO and CTO) Submitted
GZ CyberRange
(self-built lab)
Internal— 30-vulnerability fintech training lab; 86% hunter coverage validated Live

Hire-signal open-source contributions

Two contribution-first PRs opened at engineering companies with public "we hire from our contributor pool" culture. Each PR was designed to sit at the intersection of a real user-facing bug and a technical difficulty bar the maintainers care about, and each was accompanied by a 4-element response protocol (acknowledge / state change / evidence / offer flexibility) developed and locked over the last two sessions.

PostHog · posthog-js · PR #5083 · Sep 2026
Opt-in bot-detection heuristics (issue #2921)

Regex-based detector of impossible Chrome patch/build tuples embedded in user-agent strings — closes a long-standing PostHog issue about a Chrome-forged bot family that other detectors miss. Delivered with a 5.1×–10.9× perf leap over the naive baseline, 32 new unit tests pushing coverage on the new file to 98.32%, the full 2,095 / 2,095 core suite green, and a 5/5 Wiz-scan pass. Blocking review from @marandaneto surfaced a live-Chrome edge case (Chrome 154.0.8037.58 and 155.0.8059.12 already shipping); fixed surgically by removing the build-ceiling rule the same session and posting a 4-part reply within the 4-hour SLA.

Supabase · storage · PR #1439 · Sep 2026
Full UTF-8 object keys + invisible-glyph reject list

Revives the direction of PR #875 with a scope-controlled patch: expands the allowed object-key character set to full UTF-8, rejects 17 zero-width / bidi / C1-control codepoints to prevent homograph attacks, and fixes two latent bugs discovered in the process (backslash escape, path traversal). 76 / 76 tests pass, 10,000 Hypothesis-driven fuzz cases pass, plus a benchmark run. When Supabase's depthfirst-app bot flagged four additional Unicode codepoints, all four were added to the reject list with tests in the same session. Staff maintainer @ferhatelmas engaged twice; awaiting a decision on how to sequence the follow-up work.

Chapter 15 · Roadmap Ahead15 — Roadmap

Next 90 Days

Next 6 Months

Next 12 Months

A product is not judged by the demo. It is judged by the reproducible run.

Engage With Nexus Zone

Every product in this catalog is real, published, and independently verifiable. Requests for evaluation copies, pilot programmes, licensing conversations, or research collaboration are welcomed.

CONTACT

Response within one business day.

Nexus Zone — Where technology meets craft.
Founded by game_nexus_zone · Portfolio Companion Edition 2026