Skip to content
View Tito0015's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Tito0015

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Tito0015/README.md

Hi, I'm Tarek πŸ‘‹

Founder & Lead Architect @ Veraptos β€” building the universal rule compiler for AppSec ("Terraform for Threat Detection"). Write abstract vulnerability logic once (CPG/AST) $\rightarrow$ compile & lower directly into native CodeQL | Semgrep | Opengrep | Nuclei | YARA | Sigma | Hexens Glider rules across Web2 & Web3.

⚑ The upstream contributions below were compiled, lowered, and verified using the Veraptos engine.

πŸ”„ The Meta-Compiler Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚        Abstract Threat Invariant        β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                     β”‚ (Write once: CPG/AST)
                     β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚        Veraptos Lowering Engine         β”‚
β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”˜
     β”‚          β”‚          β”‚          β”‚
β”Œβ”€β”€β”€β”€β–Όβ”€β”€β”€β” β”Œβ”€β”€β”€β”€β–Όβ”€β”€β”€β” β”Œβ”€β”€β”€β”€β–Όβ”€β”€β”€β” β”Œβ”€β”€β”€β”€β–Όβ”€β”€β”€β”
β”‚CodeQL  β”‚ β”‚Semgrep β”‚ β”‚ Nuclei β”‚ β”‚ Glider β”‚ + YARA/Sigma
β””β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ›‘οΈ Upstream Proof-of-Work & Merged Contributions

  • CodeQL ( github/codeql ): #22438 β€” C++ MMIO un-sanitized memcpy query [Merged Sep 21, 2026]
  • Semgrep ( semgrep/semgrep-rules ): #4052 β€” TypeScript MCP command injection & SSRF [Merged Sep 21, 2026]
  • Nuclei ( projectdiscovery/nuclei-templates ): #17171 β€” Ray RCE (CVE-2025-62593) [Merged Sep 24, 2026]
  • Joern CPG Engine ( joernio/joern ): #6298 β€” C2CPG double-pointer dataflow reachability fixes [Merged Sep 24, 2026]

⛓️ Web3 & Glider (Hexens) Query Suite (Tito099 β€” Pending Update)

Author of 7 automated Solidity AST invariant detection queries on Glider IDE:

  • πŸ”΅ Decimal Precision Loss via Scale-to-Single/Dual-Vault (Pending merge β€” 30 Aug 2026)
  • πŸ”΅ Native Asset Double-Spend via settle/sweep logic (Pending update β€” 6 Aug 2026)
  • πŸ”΅ Duplicate Signature Quota Bypass via reuse (Pending update β€” 5 Aug 2026)
  • πŸ”΅ Risc0 ZK Unbound Journal Digest (Pending update β€” 4 Aug 2026)
  • πŸ”΅ Merkle Shift-Compose Overflow via verifier logic (Pending update β€” 4 Aug 2026)
  • πŸ”΅ Governance Check-Effects-Interactions (CEI) (Pending merge β€” 3 Aug 2026)
  • πŸ”΅ ABI Smuggling β€” Fixed-Offset Calldata (Pending merge β€” 22 Jun 2026)

πŸ”¬ Featured Projects & Technical Analysis


πŸ“« Connect


Self-funding the Veraptos R&D floor one pizza πŸ• at a time while lowering CPG ASTs into multi-format threat rules.

Pinned Loading

  1. cpg-nuclei-compiler cpg-nuclei-compiler Public

    Deterministic Joern CPG-to-Nuclei YAML compiler & Docker verification harness

    Rust 2

  2. joern joern Public

    Forked from joernio/joern

    Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc

    Scala

  3. nuclei-templates nuclei-templates Public

    Forked from projectdiscovery/nuclei-templates

    Community curated list of templates for the nuclei engine to find security vulnerabilities.

    JavaScript

  4. semgrep-rules semgrep-rules Public

    Forked from semgrep/semgrep-rules

    Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.

    HCL

  5. AikidoSec/opengrep-rules AikidoSec/opengrep-rules Public

    42 8