| Project | Area | Date | Findings | Report |
|---|---|---|---|---|
| PasswordStore | Access control · Storage | 2025-11-26 | 2H · 1I | PDF · MD |
| RaiseBox Faucet | Token distribution | 2025-12-27 | 2H · 1M | PDF · MD |
| Mystic Finance | Liquid staking · Plume | 2026-05-11 | 1M · 2L · 2I | PDF · MD |
| Castr.fun | Token launchpad · Base | 2026-08-13 | 3C · 16H · 28M · 37L/I | PDF · MD |
Severity: C Critical · H High · M Medium · L Low · I Informational
Counts represent findings documented in each report. For team engagements, they are engagement totals and do not imply individual authorship of every finding.
These reports are independent portfolio assessments unless explicitly stated otherwise. Each review is limited to the scope and code version described in the report and does not guarantee the absence of vulnerabilities.
Reports are licensed under CC BY-NC-ND 4.0; embedded proof-of-concept code is MIT. See LICENSE for details.
Protocol security reviews are defined by a fixed revision, written scope, exclusions, delivery window, and agreed reporting format. Typical outputs include architecture and trust-boundary mapping, a review ledger, reproducible findings, remediation guidance, and remediation verification.
For scope and intake requirements, see Working With Me. Do not send private source, credentials, or sensitive architecture through a public GitHub issue.
