← Back to home

Security reviews

Fixed scope, fixed price, remote. Each one ends in a written list of findings ranked by what an attacker reaches first — not a scanner dump, and not a slide deck.

I write here about supply-chain attacks, Kubernetes hardening, and the security of AI agents because that is the work. If something you read applies to your own stack and you want to know how badly, this is how to find out.

What you get

  • A written findings list, ordered by real reachability rather than CVSS.
  • The specific change for each finding — the manifest, the workflow, the flag.
  • A call to walk through it, and answers by email afterwards.

The packages

scope and quote on request · remote, 2 weeks

Supply-chain & CI review

Where your build can be turned against you, and what to change first.

  • npm/pnpm install-script surface and lockfile policy
  • GitHub Actions permissions, OIDC, and secret exposure
  • Image signing and verification (cosign), SBOM and VEX flow
  • A written finding list, ranked by what an attacker reaches first

scope and quote on request

Kubernetes hardening review

RBAC, Pod Security, and the unfixed CVEs you are actually exposed to.

  • RBAC blast radius: who can escalate to cluster-admin, and how
  • Pod Security Standards, user namespaces, and workload isolation
  • Runtime enforcement posture and what it would actually block
  • A written finding list with the manifest changes to make

scope and quote on request

AI agent security review

Agents hold credentials and take actions. This is where that goes wrong.

  • Agent identity and non-human credential governance
  • Prompt-injection and tool-call boundaries that hold under pressure
  • MCP/A2A trust: what your agent will believe and act on
  • A written finding list mapped to the actions an agent can take

scope and quote on request

How it starts

Email me at [email protected] with what you run and what worries you. If it is not something I can genuinely help with, I will say so and point you somewhere better. If it is, you get a scope and a price before any work begins.

Based in Indonesia? Temika Cyber — assessment, monitoring, and incident response, delivered locally