I build security tools, full-stack platforms, and AI systems from first principles.
Not wrappers. Not tutorials. Production code that solves real problems.
Currently shipping GhostLM (an 81M parameter cybersecurity language model trained from scratch) and the ghostloop family: ghostloop v1.0.3 (the embodied-AI agent runtime + fail-closed safety pipeline + sim-first execution + statistically-rigorous bench harness + post-hoc analysis layer for robotics, pip install ghostloop), ghostloop-ui (Next.js 15 control plane with profile-aware gamepad mapping for non-coders, deployed at ghostloop-ui.vercel.app), and ghostloop-desktop v0.2 (Tauri 2 native app with voice control, gamepad rumble on safety events, native OS notifications, single-file builds for macOS / Windows / Linux). Live HuggingFace demo for everything in one place.
I'm a Computer Science student at Moi University (Nairobi, Kenya) and the founder of Complex Developers, a studio that ships web platforms, custom tooling, and AI adjacent products. The company site + CRM runs on Next.js 15, Prisma, and Postgres.
My work sits at the intersection of offensive security, full-stack engineering, applied AI, and systems programming. 34+ open source projects, 320+ commits, 165,000+ lines of code, and counting. The shortest way to prove what you can engineer is to show working code, so that's what this profile is.
|
An open source cybersecurity language model built from scratch in PyTorch. 81M parameter decoder-only transformer (RoPE, SwiGLU, RMSNorm) trained on a 422M token multi-domain corpus across 27 sources: cybersec writeups, NVD CVEs, MITRE / CWE / OWASP, NIST SP 800, FineWeb-Edu, open-web-math, and a 105 repo open source code pull spanning 15 languages. Ships GhostAgent (a tool-using runtime), a multi-vendor HTTP server speaking OpenAI / Anthropic / Gemini / Ollama wire formats, an MCP server, and GhostBench (a packaged eval suite with Wilson 95% CIs and McNemar paired comparisons across 14 differentiation bets). 312 tests green. |
ghostloop v1.0.3: the agent loop, embodied. Production-stable in 14 releases, ghostloop-ui: Next.js 15 + React 19 + Tailwind 4 control plane for the ghostloop production backend. Live at ghostloop-ui.vercel.app with the FastAPI backend hosted free on Render. Fleet view, alarm tray with one-click ack, episode timeline, Prometheus metrics broken out per-counter, profile-aware gamepad mapper (drone / mobile base / quadruped / arm / humanoid), three-path ghostloop-desktop v0.2: Tauri 2 + Rust shell wrapping ghostloop-ui as a single-file desktop app. Voice control via the embedded WebView's Web Speech API on Windows + Linux ("ghostloop, stop / land / takeoff / pause"), gamepad rumble triggered on safety events (geofence block, force-cap trip, HITL escalation, e-stop), native OS notifications for alarms (toast / banner / libnotify), native gamepad input through secure-mcp: MCP server exposing security tools to AI agents with policy gates, subprocess sandboxing, and audit trails. Fail-closed by default. CyberBench — Open, reproducible benchmark for evaluating LLMs on cybersecurity reasoning. YAML tasks, pluggable backends, ranked leaderboard. linkdrop v0.7.1 — Cross-platform Tauri + Rust desktop app bridging iPhone to Linux for photos, files, notifications, screen mirroring. Daemon-backed pymobiledevice3 bridge, CI-built .deb / .AppImage. AI agent safety stack: secure-mcp, ghostguard (4-tier policy proxy with audit dashboard), CyberBench Defensive security toolkit: ghostaudit (23 CIS Kubernetes checks), ghostforensics (memory forensics with YARA + Volatility + STIX 2.1 export), ghostsiem (Sigma-rule SIEM), securecommit (pre-commit secret scanner) Offensive tooling: concurrent TCP port scanner, packet-level traffic analyzer, vulnerability scanner, hash-cracking framework, MAC rotator, metadata scrubber Full-stack platforms: Complex Developers CRM (Next.js 15 + Prisma + Postgres), ChartSentinel (trading SaaS with Stripe + PostHog + Sentry), High-End CRM, ai-coding-assistant |
|
Replaced the naive |
Merged. Fixed agent name preservation in |
Authored the AI Model Supply Chain Security cheat sheet (now part of the OWASP corpus, 92 sheets). Covers unsafe deserialization (pickle / |
I'm always open to collaborating on security research, open source tooling, or interesting engineering problems.
If you're building something that matters, I'd like to hear about it.
Nairobi, Kenya · Founder, Complex Developers · Open to opportunities · joemunene984@gmail.com


