Skip to content

Who I am

Nadir Abdurakhmanov

Nadir Abdurakhmanov

Software engineer

I design and build software that does repetitive work instead of people. AI agents and bots, websites and web apps, backend and integrations, mobile apps, trading infrastructure. From the first call to production, one person owns the result — me.

No office, no managers, no sales department. Which means none of their salaries sit in your quote, and you talk directly to the person who will write the code. The honest downside: I take two or three projects at a time, and the queue is sometimes a month deep.

Start a project

How it works

I work alone
For design and mobile I bring in people I have worked with for years
2–3 projects at a time
So nothing stretches past its deadline
You talk to me
No manager relaying messages in between
Two markets
Europe, Russia and the CIS. Contract in euros or roubles

The proof

My own trading system in production

For several years I have been building and running my own trading system: eleven services, round-the-clock market data collection, order execution, position accounting, a risk layer with a kill switch. Hot-path computation lives in a Rust module, the rest is Python, PostgreSQL, Redis, Docker.

It is not a showcase, it is a bench. Every decision I offer clients was first paid for with my own mistakes: queues that accumulated tens of seconds of lag, position closing that silently never fired, a cleanup routine that deleted live data. So when I take on someone else’s system, I bring a concrete list of where these projects break rather than general reasoning.

Read the write-up

What I decline

A short list of noes saves time on both sides. If your task falls into it, better to know now than after three meetings.

  • —I decline work that is solved by configuring something you already pay for
  • —I do not sell trading signals or manage other people’s money
  • —I do not promise revenue growth — I answer for the system doing what the contract says
  • —I never keep a project on my own servers: access is yours from day one

Open source

All of this is open to read

A portfolio is easy to draw. A repository is not: you can see how the code is written, how many tests it has and how long it has lived. 32 open projects — see for yourself.

Live demos

6Open right in the browser — nothing to install
  • shadowmapJavaScriptReal-time global cyberattack map: live SSH/RDP/web threats with animated arcslive demoGitHub
  • crackvisJavaScriptInteractive password-cracking visualizer — watch a password get attacked livelive demoGitHub
  • sora-sushiJavaScriptSushi café landing: 3D hero, menu and delivery on three.js + GSAPlive demoGitHub
  • svetopisJavaScriptPhotographer site: WebGL shader, inertial scroll, booking — zero librarieslive demoGitHub
  • stroyflexJavaScriptWholesale construction-chemistry catalog: 617 items, instant filtering from an Excel price listlive demoGitHub
  • toolsJavaScriptLive security-tooling hub — a showcase with embedded demoslive demoGitHub

AI security

8Agents and tooling built on Claude and MCP
  • agentstrikePythonA "Metasploit for AI agents" — prompt-injection red-team framework with a genetic mutator and canary-proven breachesGitHub
  • poisondocPythonIndirect injection, both ends — crafts poisoned documents and detects hidden injections before an LLM reads themGitHub
  • vigilPythonAI security review for every pull request, powered by Claude — injection, secrets, authz bugsGitHub
  • specterPythonAutonomous AI recon agent — Claude plans and runs recon, then writes a severity-graded reportGitHub
  • offsec-mcpPythonMCP server giving AI agents authorized-only offensive-security toolsGitHub
  • mcpscanPythonSecurity scanner for MCP servers — tool poisoning, over-privileged tools, hidden instructionsGitHub
  • state-of-mcp-securityPythonReproducible MCP-server audit — 75% had a medium+ hardening issueGitHub
  • phantasmPythonAI phishing & social-engineering analyzer — detects manipulation tactics in real timeGitHub

Security tooling

18Scanners and utilities in pure Python
  • pathfinderPythonAttack-path planner — chains recon facts into end-to-end paths and ranks them, labelled with MITRE ATT&CKGitHub
  • exploit-synthPythonCVE → safe PoC — classifies the bug and generates a non-destructive presence check (detection, not weaponization)GitHub
  • sentinelPythonUnified security suite — recon, DAST, git-leak hunting and static analysis in one command, zero depsGitHub
  • argusPythonStatic security scanner with AST taint analysis — proves dataflow, zero deps, HTML/SARIFGitHub
  • web-vuln-scannerPythonWeb vulnerability scanner: SQLi, XSS, SSRF, open redirect, security headers — OWASP Top 10GitHub
  • reconwavePythonAsync attack-surface recon: continuous subdomain monitoring, asset graph, diffingGitHub
  • ssh-honeypotPythonSSH honeypot: logs credentials, geolocates attackers, Telegram alerts, fake shellGitHub
  • jwt-security-analyzerPythonJWT analyzer: alg:none, weak secrets, claim validation, signature forgingGitHub
  • password-auditorPythonHash cracker (MD5/SHA1/bcrypt), password-policy audit and a mutation engineGitHub
  • cve-forgePythonCVE-to-exploit automation: monitors fresh CVEs, matches your assets, auto-generates Nuclei templatesGitHub
  • phishing-url-detectorPythonML-based phishing-URL classifier: feature engineering + Random ForestGitHub
  • osint-aggregatorPythonOSINT automation: Shodan, VirusTotal, WHOIS, DNS, subdomain enum → HTML reportGitHub
  • jsintelPythonJavaScript intelligence — extracts secrets, endpoints, params and API maps from JS bundlesGitHub
  • log-analyzer-siemPythonMini-SIEM: SSH/nginx/Apache log analysis, brute-force detection, anomaly alertsGitHub
  • dossierPythonOne-command OSINT report: domain/IP/email → a clean HTML reportGitHub
  • network-anomaly-detectorPythonReal-time traffic analysis: port scans, ARP spoofing, DNS tunneling (Scapy)GitHub
  • custom-port-scannerPythonMultithreaded TCP/UDP port scanner with service fingerprinting and JSON outputGitHub
  • ctf-writeupsPythonCTF writeups (HTB/TryHackMe) and PoC tools — documented penetration-testing methodologyGitHub
Full GitHub profile