Security research, shipped
Volunteer, Technical Department
Building tech for global Muslim community
Security researcher and open-source contributor from Karachi, Pakistan. I build security tooling and full-stack applications with AI-assisted engineering workflows and evidence-led validation.
Recognized in the EC-Council Hall of Fame for responsible vulnerability disclosure. Contributor to GitLab (gitlab-shell) and Inkscape. Currently building shadowaudit — an open-source CLI that detects unauthenticated and undocumented API routes through static analysis.
I approach security research through passive analysis, source code review, and AI-assisted attack-surface mapping, keeping every finding evidence-driven and reproducible.
Volunteer in the Technical Department at 360 Muslim Experts — a global network of Muslim experts committed to positive change through Islam, education, and research. Building Pak Books(free digital library for Pakistani students) and contributing to the organization’s technical infrastructure.
Passive Analysis
Non-intrusive observation of application behavior and data flows
JS Bundle Review
Source code analysis of client-side JavaScript for leaked secrets and logic flaws
Responsible Disclosure
Evidence-driven reports with verified, reproducible findings
360 Muslim Experts
Volunteer, Technical Department — building tech for a global Muslim community (Pak Books, infrastructure)
Résumé
A single-page PDF generated from the same data as this site, so it never drifts from what is published here.
3 work relationships · 5 upstream contributions · 3 disclosed engagements
Skills & Tools
Every line has a receipt.
Security
- Vulnerability Research20 disclosed vulnerabilities · Hall of Fame 2026
- Web Pentesting9 vulnerabilities, 3 critical
- Static Analysisshadowaudit — SARIF, GitHub Action
- API SecurityOWASP API Top 10 mapping
- Burp Suite · NmapRecon and validation on real targets
- F-Droid Audits13 submissions, 11 merged upstream
Development
- KotlinNoor Connect, Hidayah OS
- TypeScriptKarobarX — React + Supabase
- Pythonnafs-ai agent, automation
- RustNeuron-Encrypt — AES-256-GCM-SIV
- Node.jsshadowaudit CLI
- React · Next.jsThis site, shadowaudit dashboard
Tools & Infra
- Cloudflare WorkersZero-cost hosting across 3 live projects
- SupabaseRow-level security on every table
- Linux · KaliHidayah OS, live ISO builds
- Git · GitHub ActionsCI for Hidayah OS ISO builds
- CapacitorKarobarX Android client
- AI-Assisted EngineeringClaude and Gemini on public repos
Journey So Far
PriceOye
First bug bounty report submitted; 5 vulnerabilities identified, including critical PII leaks.
EC-Council initial report
Initial responsible disclosure submitted to EC-Council.
HaramVeil + NoFap Hydra + Waqar Electronics
Built privacy-focused projects and disclosed Waqar Electronics ATO chain.
FOSS contributions
Continued open-source development on privacy/security-oriented repositories.
F-Droid Snowflake verification
Forward-compatibility verification for Snowflake Volunteer on Android 16 approved by F-Droid maintainer.
ShadowAudit v0.6.1 shipped
Released static API security scanner with 4 framework scanners, SARIF output, and GitHub Marketplace action integration.
EC-Council Hall of Fame
Hall of Fame 2026 listing with Certificate of Appreciation for 9 vulnerabilities (3 Critical).
Hidayah OS v1.0.0 “Nur” released
Shipped a privacy-hardened Debian 13 Linux distribution for Muslim families — KDE + XFCE live ISOs, Sovereign Shield DNS (326,632 rules), doctor self-test 31/0, GPG-signed release artifacts.
Common questions
Everything you need to know before reaching out.
Still have questions? Send a message