Skip to content
View AshtonVaughan's full-sized avatar

Highlights

  • Pro

Block or report AshtonVaughan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AshtonVaughan/README.md
Ashton Vaughan




> ./about

It started at 9, guessing the passwords on my parents' devices so I could play games. Still at it: 18 now, studying IT at QUT and hunting on HackerOne. Most of what I ship is security and AI tooling - an autonomous bug-bounty agent, an authorization-first LLM red-team framework, a Burp-to-MCP bridge, a hardware-agnostic LLM inference engine, and a browser runtime built for AI agents.

a decade of side projects, with the most recent years highlighted

offensive security  ·  applied ml  ·  agent systems  ·  systems programming


> ./shipping

python   agents   offsec   hackerone

Autonomous bug bounty hunting agent. 71K lines of Python. Hypothesis-driven pentesting with 19 reasoning modules, 51+ tools, and HackerOne integration.

python   llm   red-team   bug-bounty

Authorization-first LLM red-team framework. Local 70B abliterated attacker LM, 6 novel transformer-architecture attacks, statistically-validated universal jailbreak claims.

kotlin   burp   mcp   agents

Burp Suite extension that exposes the Montoya API as an MCP server. 152 typed tools + cross-extension reflection bridge into Logger++, Hackvertor, Param Miner. Drives Burp from any AI agent.

typescript   browser   agents   mcp

Browser runtime built for AI agents. Semantic tools, site memory, MCP server.

rust   inference   llm   pypi

Hardware-agnostic LLM inference engine. Runs anything from a Raspberry Pi to a B200 cluster. Written in Rust, shipped on PyPI.

python   re   binary-analysis   agents

Local-first reverse engineering orchestrator. Drives Ghidra, angr, Frida, rizin, QEMU, AFL++ and pwntools through a small-model LLM to triage binaries and find bugs. No API keys, no network calls.


> ./stack

offense              

ai / ml              

systems              

ops            


> ./signal


> ./recent

- `push`     [AshtonVaughan/React-Components](https://github.com/AshtonVaughan/React-Components) - Empty repo
- `push`     [AshtonVaughan/DiaxiInject](https://github.com/AshtonVaughan/DiaxiInject) - Add baseline reproduction scripts, docs polish, paper restructure
- `push`     [AshtonVaughan/DiaxiInject](https://github.com/AshtonVaughan/DiaxiInject) - Add multi-modal orchestrators, integration tests, baseline reproductions, docs site
- `push`     [AshtonVaughan/DiaxiInject](https://github.com/AshtonVaughan/DiaxiInject) - Add defense layer, agentic feedback loops, marketplace, tracking, novel-method tuning
- `push`     [AshtonVaughan/Nerve](https://github.com/AshtonVaughan/Nerve) - Anthropic adapter tool_result loop, clean nerve stop, honest README
- `push`     [AshtonVaughan/Nerve](https://github.com/AshtonVaughan/Nerve) - Merge pull request #3 from AshtonVaughan/claude/nerve-automation-mvp-0j5iJ

responsible disclosure only / AEST / always learning

Pinned Loading

  1. agentbrowser agentbrowser Public

    Browser runtime purpose-built for AI agents. Semantic tools, site memory, self-healing execution, MCP server.

    TypeScript 1

  2. ProjectTriage ProjectTriage Public

    Autonomous hypothesis-driven pentesting agent powered by LLMs. 71K+ lines of Python. 19 reasoning modules, 51+ tools, HackerOne integration.

    Python 1

  3. DiaxiInject DiaxiInject Public

    LLM security testing tool - uses local uncensored LLMs to test cloud LLMs for bug bounties

    Python 2

  4. prismllm prismllm Public

    Any model. Any hardware. Any size. Hardware-agnostic LLM inference engine with the Sparse Oracle Architecture.

    Rust

  5. somnus somnus Public

    Local-first reverse engineering orchestrator. Drives Ghidra, angr, Frida, rizin, QEMU, AFL++, and pwntools through a small-model LLM to triage binaries and find bugs.

    Python

  6. burp-mcp-ultimate burp-mcp-ultimate Public

    Burp Suite Pro extension that exposes the Montoya API as an MCP server. 152 tools, 10 resources, 9 prompts, drives Burp from any MCP-aware AI agent.

    Kotlin 1