I'm Eko. I reverse-engineer undocumented APIs, automate things that shouldn't be manual, and find security holes before someone else does — for developers, founders, and small teams who need things connected, automated, or made more secure.
- 5+ yrs
- Security & automation
- 30+
- APIs integrated without docs
- 50+
- Dev tools shipped
- 🛡️
- Google Bug Hunter
- Verified security researcher
JSON Formatter & Validator
Format, validate, fix, and explore JSON — with tree view and auto-repair.
JWT Decoder
Decode, verify, and generate JWT tokens — all client-side.
Base64 Encoder/Decoder
Encode/decode Base64 and Base64URL — with file support and auto-detection.
SecurityAug 19, 20269 minThe Certificate Row Is Not the Certificate: A Revocation Bypass in Lemur
A newly disclosed Lemur flaw lets a low-privileged user create a duplicate certificate record and use it to revoke the real certificate at its issuing CA. The problem is a subtle but serious authorization mistake: trusting local row ownership instead of the CA-side certificate identity.
IndustryAug 17, 202611 minThe API Contract Your AI Users Already Believe Exists
An AI generated a polished demo for an API endpoint that did not exist, then its creators shipped compatibility routes instead of arguing with the model. The lesson is bigger than one text-erasure API: generated code is now a form of product telemetry.
SecurityAug 15, 20269 minOne SSRF Control Is Not Enough: The Budibase Automation Bypass
A newly disclosed Budibase SSRF issue shows why outbound HTTP protection cannot live in one integration while automation steps call fetch directly. The real failure is architectural: security controls that are opt-in, inconsistent, and easy for new features to bypass.
SecurityAug 14, 202610 minA Leaked Cookie Signing Key Is an Auth Failure, Not a Configuration Bug
CVE-2026-72793 exposes sensitive SiYuan configuration data through an API endpoint available to anonymous or publish-reader users. If you run SiYuan before v3.7.4, treat this as a potential authentication compromise and patch accordingly.
Field NotesAug 9, 20268 minBringing the Open Web Back: The Robot.villas RSS-to-Mastodon Bridge
robot.villas is a collection of bot accounts that mirror public RSS and Atom feeds into Mastodon. Here's why this simple bridge matters more than ever for the open web.
What I do
Automation engineer with a security background. I build automation, integrations, and internal tools — for businesses, founders, and small teams who need things connected, automated, or made more secure.
- Automation & scheduled workflows
- Custom integrations (no-SDK platforms)
- Internal tools & dashboards
- Security review (web & API)
01 lang: node, python, typescript, +adapt 02 web: next.js, react, tailwind 03 tools: burp, mitmproxy, curl, +oss 04 security: web, api, infra 05 approach: direct API, no low-code 06 mode: remote · UTC+7
Got a project in mind?
Tell me what you're trying to do.
No need to know exactly what you need — just describe the problem. I read everything & reply within 1–3 days.