Fixed scope, fixed price, remote. Each one ends in a written list of findings ranked by what an attacker reaches first — not a scanner dump, and not a slide deck.
I write here about supply-chain attacks, Kubernetes hardening, and the security of AI agents because that is the work. If something you read applies to your own stack and you want to know how badly, this is how to find out.
What you get
- A written findings list, ordered by real reachability rather than CVSS.
- The specific change for each finding — the manifest, the workflow, the flag.
- A call to walk through it, and answers by email afterwards.
The packages
scope and quote on request · remote, 2 weeks
Supply-chain & CI review
Where your build can be turned against you, and what to change first.
- npm/pnpm install-script surface and lockfile policy
- GitHub Actions permissions, OIDC, and secret exposure
- Image signing and verification (cosign), SBOM and VEX flow
- A written finding list, ranked by what an attacker reaches first
scope and quote on request
Kubernetes hardening review
RBAC, Pod Security, and the unfixed CVEs you are actually exposed to.
- RBAC blast radius: who can escalate to cluster-admin, and how
- Pod Security Standards, user namespaces, and workload isolation
- Runtime enforcement posture and what it would actually block
- A written finding list with the manifest changes to make
scope and quote on request
AI agent security review
Agents hold credentials and take actions. This is where that goes wrong.
- Agent identity and non-human credential governance
- Prompt-injection and tool-call boundaries that hold under pressure
- MCP/A2A trust: what your agent will believe and act on
- A written finding list mapped to the actions an agent can take
scope and quote on request
How it starts
Email me at [email protected] with what you run and what worries you. If it is not something I can genuinely help with, I will say so and point you somewhere better. If it is, you get a scope and a price before any work begins.
Based in Indonesia? Temika Cyber — assessment, monitoring, and incident response, delivered locally