Skip to content
View hiratinspace's full-sized avatar
♾️
Offensive Security
♾️
Offensive Security

Highlights

  • Pro

Block or report hiratinspace

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
hiratinspace/README.md

Hirat Rahman Rahi

Security engineer. I build tooling that maps attack surface, and the software and AI systems behind it.

Building REDHEXX · Built TuitionCreep · CS & Neuroscience @ Illinois Wesleyan

Portfolio LinkedIn REDHEXX Email


whoami

focus      →  offensive security · attack surface · AI agent security
building   →  REDHEXX — security review for MCP & agent attack surface
shipped    →  TuitionCreep — 3,525 US schools, federal IPEDS data
also       →  software & AI engineering: Python, TypeScript, Swift, on-device LLMs
based      →  Illinois, United States

Currently

REDHEXX — AI-native security review mapping the MCP and agent attack surface: unauthenticated tools, over-broad scopes, and injection-to-action paths. Pre-launch. Research published here; OSS scanner on the roadmap.

specter-ai — Attack surface recon that runs DNS, port scanning, HTTP and TLS analysis in parallel, then generates a risk-assessed pentest report. CLI and live web dashboard. → demo

Learning — Identity and Authorization, AI Agent & MCP Security


Security

Project What it does
specter-ai Parallel recon engine — DNS, ports, HTTP, TLS — with Claude-generated risk assessment. Flask dashboard + CLI.
portfolio Personal site with a live threat-intel feed pulling NVD CVEs and the CISA KEV catalog.

Software & AI

Project What it does
tuitioncreep-showcase IPEDS tuition projections and an aid-erosion engine. Next.js front end, Python ETL, Playwright + Vitest. Public 13-school sample of tuitioncreep.org.
Glovebox Offline-first roadside assistance for iOS. On-device LLM diagnosis via RAG + llama.cpp. UC Berkeley AI Hackathon 2026. → Devpost
HackTitan_Web Official site for Illinois Wesleyan's flagship hackathon. [add your organizer role]
Appeally 24-hour hackathon build at HackAugie with a two other teammates. A tool that helps people get their mental health insurance claim from insurance company by creating and sending a strong appeal letter.

Stack

Security Burp Suite Nmap Wireshark GDB Linux

Languages Python TypeScript Swift Bash

AI & Data MCP Claude API llama.cpp RAG

Web & Infra Next.js React Flask Tailwind Cloudflare


Open to security engineering internships and design-partner conversations for REDHEXX.

hiratrahi.com · LinkedIn · REDHEXX

Pinned Loading

  1. specter-ai specter-ai Public

    Attack surface recon tool that runs DNS, port scanning, HTTP, and TLS analysis in parallel, then uses Claude to generate a risk-assessed pentest report via CLI or a live web dashboard.

    Python

  2. tuitioncreep-showcase tuitioncreep-showcase Public

    Know your senior-year college bill before you enroll: IPEDS tuition projections and an aid-erosion engine (Next.js + Python ETL). Showcase of the live app at tuitioncreep.org (13-school sample).

    TypeScript

  3. Glovebox Glovebox Public

    Offline-first roadside assistance for iOS: on-device LLM diagnosis (RAG + llama.cpp) and cached emergency help. Built at UC Berkeley AI Hackathon 2026.

    Swift

  4. ethan-godsey/Appeally ethan-godsey/Appeally Public

    Our 24-hour hackathon project

    JavaScript

  5. portfolio portfolio Public

    Personal portfolio for Hirat Rahman Rahi: a React and Cloudflare Pages site featuring a live security intel feed (NVD CVEs plus CISA KEV) and case studies for shipped projects.

    JavaScript