Skip to content
View abrahamhl's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report abrahamhl

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
abrahamhl/README.md

Abraham Haddioui Lastras

Creative Technologist · AI Product Engineer · Security-minded Builder Arnhem, Netherlands · English C1 · Spanish native · Dutch A2 · Available now — on-site Gelderland, remote EU or relocation

I build products where design, frontend engineering and AI meet — and I verify what I ship with tests, threat models and honest limits.


🔍 OSINT & Threat Intelligence

Project What it does Tests Stack
osint-evidence-ledger Tamper-evident evidence ledger for OSINT investigations: SHA-256 chain, NATO Admiral reliability grading, multilingual reporting 14 Python · stdlib only
eu-sanctions-screen Explainable name screening against the EU Consolidated Financial Sanctions List with Cyrillic transliteration and scoring transparency 15 Python · stdlib only
eu-cti-brief Prioritised vulnerability bulletin from NCSC-NL, CERT-EU, BSI, CISA KEV and EPSS — three priority tiers, watchlist support 8 Python · stdlib only
citation-audit Checks whether sources cited in AI-generated answers actually say what the answer claims — no AI inside 6 Python · stdlib only
chronolocate Sun position, shadow-based time solving, EXIF consistency, perceptual hashing, Content Credentials (C2PA) detection 10 Python · Pillow
threat-feed-correlator Cross-correlate multiple CERT/CISA feeds into one deduplicated, ATT&CK-mapped, EPSS-enriched threat report 7 Python · stdlib only
ioc-evidence-store Offline-first IOC database with STIX 2.1 export, SHA-256 integrity chain, CSV/JSON import 12 Python · stdlib only
web-exposure-scan Passive e-mail and web exposure check for SMBs — SPF, DKIM, DMARC, TLS, headers — with client-ready reports in NL/EN/ES 18 Node · zero deps

🛡️ Security & AI Evaluation

Project What it does Stack Live
mcp-osint-server MCP server exposing OSINT tools (sanctions screening, CTI briefs, IOC search, chronolocation) to AI agents TypeScript · MCP SDK -
civil-sentry Evidence-driven cyber situational awareness: authorization gate, SHA-256 evidence chain, AI findings grounded in proof TypeScript · zero runtime deps · Apache-2.0 site
Buyer Arena Evidence-first evaluation of web products and AI-agent changes: seeded synthetic buyers in a real browser, baseline vs candidate, release gates TypeScript · Node 22 · Playwright -
npm-supply-chain-auditor Read-only scanner for compromised npm packages, droppers and persistence hooks PowerShell · offline IOC dataset -
ARGUS Evidence and opportunity control plane: typed, hashed evidence from collectors, correlated into findings and retests. 195 tests TypeScript · pnpm monorepo -

🎨 Creative Technology & Product

Project What it does Stack Live
NEXUS Visual Engine 30 real-time audio-reactive visual engines for DJ sets, museums and installations WebGL · Three.js · GLSL · Web Audio demo
IAQUARIUS Gateway Local multi-provider AI gateway: one OpenAI-compatible endpoint with automatic failover, chat UI and observability LiteLLM · Open WebUI · Docker -
Gelderland Crane Simulator Deterministic overhead-crane training simulator with 35 automated physics checks Godot · GDScript -
loopsmith Exact-duration assembly of AI-generated video clips with seam analysis Bash · FFmpeg/ffprobe -
civic-relay Offline-first crisis messaging prototype: multi-transport routing, store-and-forward, deduplication TypeScript · React · pnpm monorepo demo

How I work with AI

I use AI agents (Claude, Codex, Gemini) as implementation partners, not as authors of record: I set scope and architecture, agents implement, and nothing is claimed as done unless a test or command proves it. Examples of that workflow are public — the crane simulator's .claude/ agent roles and rules, and civic-relay's RELEASE_TRUTH_V0_1.md verification record.

Looking for

CTI & Threat Intelligence · SOC Engineering · AI Product Engineering · Creative Technology · Design Engineering · Security Engineering (defensive) · Applied AI / Forward Deployed

Links

Portfolio · AUX Design · GitHub

Popular repositories Loading

  1. nexus-visual-engine nexus-visual-engine Public

    NEXUS Visual Engine - 30 audio-reactive WebGL simulators for DJ sets, museums & immersive installations

    HTML

  2. creative-tech-portfolio creative-tech-portfolio Public

    Creative technologist portfolio: WebGL, product interfaces, automation and a preserved Hacker Lab.

    HTML

  3. stack-hub-ias stack-hub-ias Public

    AI Forge - nodo central del stack de IAs

    JavaScript

  4. gelderland-crane-simulator gelderland-crane-simulator Public

    Deterministic Godot overhead-crane simulator with 35 automated checks and auditable human-in-the-loop AI decisions.

    GDScript

  5. crane-simulator-academy-NL crane-simulator-academy-NL Public

    Crane & lifting simulator (Godot 4.6): 7 machines, 5 sites, 8 weather conditions, 21 scenarios. Load charts, stability, rigging. Training aid only — not a certification.

    GDScript

  6. loopsmith loopsmith Public

    Assemble AI-generated video clips into loops of exactly the duration you asked for, cutting where it shows least.

    Shell