Skip to content
View Shad0w-Farm's full-sized avatar
πŸ’­
Take actions efficiently and work on continuous improvements.
πŸ’­
Take actions efficiently and work on continuous improvements.

Block or report Shad0w-Farm

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Shad0w-Farm/README.md
Fazil Khan β€” Product Security

AppSec Google Cloud Kubernetes TypeScript Python LangChain LinkedIn Medium

Live Demo Self-Healing CI/CD

Staff Product Security Leader in energy-tech. I secure the software factory - and, lately, the AI we're wiring into it.

About

I work on "security by design" in the literal sense: threat models that change the architecture before code exists, pipelines that catch what reviews miss, and findings triaged with evidence instead of severity labels. Based in Al Khobar, working across complex energy-tech and digital products.

These repositories are where I think in public. They follow one thread: end-to-end application security, extended to the newest part of the attack surface - the models, the context they consume, and the agents we're starting to trust with real work.

Currently working on

  • Securing AI systems. LLM security and context engineering - prompt injection, tool misuse, poisoned context. Securing the "brain" and the "senses" of an agent so it doesn't become a high-speed vulnerability generator.
  • Agentic DevSecOps. An SDLC where agents write, review, and ship code inside guardrails: sandboxed CI/CD, MCP servers, LangChain pipelines, autonomous agents with security consultants in the loop.
  • The architect's path. Moving from securing one product to designing systems where security is a property, not a phase - and writing down what I learn on the way.

Selected work

Application-Security End-to-end application security, from secure design by threat modeling to secure deployment. The reference I wish I'd had when I started: what to do at each SDLC stage, and why.

Securing-Context-Engineering Context is the new attack surface. Securing what an AI reads, retrieves, and remembers - because a model with poisoned senses makes confident, wrong, and fast decisions.

LLM-Security Notes and patterns for securing large language models in production: injection, jailbreaks, data leakage, and the controls that actually hold up.

secchallenge An agentic SDLC built end to end: DevSecOps pipeline, LangChain framework, MCP server integration, autonomous agent engineering, CI/CD sandboxing, Spring Boot microservices. The lab where the other repos get tested against reality.

AI-Projects Building AI projects hands-on - you can't secure what you've never built.

Solution-Architect The working notebook of becoming a solution architect: patterns, trade-offs, and decisions with reasons attached.

What I reach for

Layer Usually
Design Threat modeling (STRIDE), abuse cases before user stories
Code & dependencies SAST, SCA, and secrets scanning wired into CI - not bolted on
Running applications DAST and IAST in staging; WAF transparency checked before scans
Cloud GCP - GKE, shared-VPC firewalling, Cloud Armor, IAM discipline
AI stack LangChain, MCP, OpenAI-compatible gateways, OpenClaw, OpenBot, Purple Llama, Hugging Face, LiteLLM, vLLM
Evidence Raw requests, log lines, probes - findings ship with proof

None of this is a religious position. It's the set of controls I've watched fail often enough to know how they fail.

How I work

  • A finding without evidence is an opinion. Mine ship with the request, the log line, or the probe output attached.
  • Shift left, but verify right. Design reviews kill classes of bugs; scanners catch instances; production tells the truth.
  • A fix isn't done when the patch lands. It's done when the rescan is green and the runbook exists.

Activity

Contribution streak

Live projects

Live Demo Self-Healing CI/CD

Languages & tools across my repos

Python TypeScript JavaScript HTML Bash YAML

GitHub Actions Docker FastAPI Hugging Face Google Cloud Kubernetes

Writing

I write on Medium. Recurring subjects:

  • Application security that survives contact with real delivery timelines
  • Securing AI systems before they're trusted with production access
  • What "security by design" looks like when it's a practice, not a slide

Contact

  • LinkedIn β€” in/fazil-khan-cyber
  • Medium β€” @nahklizaf
  • Happy to talk about: threat modeling workshops, DevSecOps pipelines, and securing agentic systems

Take actions efficiently and work on continuous improvements.

Popular repositories Loading

  1. Application-Security Application-Security Public

    We will talk about End-to-End Application Security. From Secure Design by Threat Modeling to Secure Deployment

    1

  2. Securing-Context-Engineering Securing-Context-Engineering Public

    This involves securing the "brain" and the "senses" of the AI to ensure it doesn't become a high-speed vulnerability generator.

  3. LLM-Security LLM-Security Public

  4. AI-Projects AI-Projects Public

    Build AI Projects

  5. Solution-Architect Solution-Architect Public

    Becoming a Solution Architect.

  6. secchallenge secchallenge Public

    Agentic SDLC and Security Consultant Challenge. Implementing DevSecOps Pipeline. Integrate LangChain framework. Leveraging MCP server. Autonomous Agent Engineering. CI/CD Sandboxing. Spring Boot Mi…

    TypeScript