Skip to content
View danielcadev's full-sized avatar

Highlights

  • Pro

Block or report danielcadev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
danielcadev/README.md

Daniel Castrillon

Software Engineer | Rust Security Tooling | Linux & Open Source | Application Security

Portfolio · Email · UseSecure · Madrid, Colombia

I build security tooling, Linux infrastructure, and production web systems. My work combines upstream open-source contributions, local-first static analysis, reproducible engineering, and hands-on ownership of authentication, authorization, data, and deployment boundaries.

I use coding agents as engineering tools: scoped tasks, typed contracts, automated verification, security review, and human validation. The objective is reliable software with evidence behind it—not code generation for its own sake.

Selected Work

Project What I work on Evidence
Open-source contributions Focused fixes across Linux tooling, Rust applications, developer tooling, CI, dependencies, and regression coverage Contribution activity
UseSecure A local-first Rust analyzer, independently frozen security benchmarks, and a reusable workflow for evidence-backed review Engine v0.1.8 · Bench
CMS Nova A reusable headless CMS foundation with schema-driven content, hybrid persistence, template tooling, and role-based administration Repository
Production platforms Architecture and delivery across booking, B2B operations, publishing, localization, authentication, PostgreSQL, and AWS-backed media Mitiquete · Conociendo Colombia · TripEuropa

Open Source

I contribute small, reviewable fixes across several actively maintained open-source projects, primarily in Rust, TypeScript, JavaScript, shell tooling, Nix, and GitHub Actions.

  • Recent upstream work spans parser and type-checking consistency, CLI tool detection, Linux desktop integration, CI hardening, dependency maintenance, and targeted state-management bugs.
  • I match repository-local conventions, reproduce issues before changing code, and validate fixes with focused regression tests and project-required checks.
  • I perform evidence-backed security reviews and use private disclosure channels when a finding could affect users.

I prioritize projects with real contributor activity, responsive maintainers, reproducible issues, and changes small enough to review confidently.

Security Engineering

  • Built and published Secure Engine v0.1.8 with deterministic analysis, reproducible Fedora packaging, signed provenance, and local-first execution.
  • Built Secure Bench around blinded holdouts, one-shot scanner campaigns, immutable evidence, independent verification, and corrected scoring contracts.
  • Led authorization, tenant-isolation, secret-handling, and exposed-route hardening across production systems.
  • Developed a capability- and invariant-centered review method for AI-assisted changes.
  • Delivered an invited talk at the Max Planck Institute for Security and Privacy on structural security risks in AI-assisted software systems.

Benchmark results retain their lane boundaries and documented limitations. They support engineering decisions; they are not broad superiority claims.

Core Stack

  • Languages: Rust, TypeScript, JavaScript, Python, SQL, shell
  • Web and data: Next.js, React, Node.js, PostgreSQL, Prisma
  • Systems and delivery: Linux, Fedora, Docker, Git, GitHub Actions, Nix, Vercel, Hetzner
  • Security: authentication and authorization boundaries, tenant isolation, secrets, storage, webhooks, static analysis, evidence contracts
  • Agent engineering: context construction, task decomposition, evaluation, failure-mode analysis, and verification-driven workflows

Background

I lead software architecture and AI-assisted engineering at Mitiquete SAS while contributing to open-source Linux tooling and developing public security-review infrastructure.

Spanish is my native language, and I work professionally in English.

Contact

Popular repositories Loading

  1. cms-nova-template cms-nova-template Public

    TypeScript 1

  2. danielcadev danielcadev Public

    Shell

  3. cms-nova cms-nova Public

    JavaScript

  4. codex-desktop-linux codex-desktop-linux Public

    Forked from ilysenko/codex-desktop-linux

    Unofficial ChatGPT desktop app for Linux (formerly the Codex app), built locally from OpenAI’s official macOS app. Includes Chat, Work, and Codex. Packages for Debian/Ubuntu (.deb), Fedora/openSUSE…

    JavaScript

  5. openpad-hub openpad-hub Public

    Experimental open-source Linux controller hub with verified GameSir Cyclone 2 support

    Python

  6. danielcadev.github.io danielcadev.github.io Public

    Daniel Castrillon software engineering portfolio

    Astro