Skip to content
View MohibShaikh's full-sized avatar

Block or report MohibShaikh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
MohibShaikh/README.md

Hey, I'm Mohib

Software engineer in Karachi. I build AI agent security tools, backend systems, and firmware for nRF hardware.

These days most of my time goes into agent security and evaluation: scanning agent skills before they run, and measuring how well other scanners and models catch malicious ones.

What I work with

Agent security and evaluation: agent-skill scanning, static analysis, LLM adjudication, benchmark harnesses, SARIF AI/ML: PyTorch, computer vision (YOLO, RF-DETR, ByteTrack) Backend: Python, Django REST, FastAPI, PostgreSQL, Redis, Docker Web: TypeScript, React, Next.js, Tailwind Embedded: C++, nRF54L15, BLE, Zigbee, FPGA edge inference (Vitis AI) Systems: Rust

Projects

clawvet (PyPI, npm) Security scanner for AI agent skills. Static triage first, LLM adjudication second. Two independent research papers used it as their baseline.

jev-skillbench Benchmark harness for TypeSafe's Jev model as a malicious-skill detector. Ran all 7,944 skills in MalSkillBench across three inference backends.

unix-ancillary (Rust) Safe file descriptor passing over Unix sockets (SCM_RIGHTS). Used by the systemd-nspawn plugin for Forgejo's CI runner.

overruled (PyPI, GitHub Action) Verdict auditor for AI SOC agents. Replays ground-truth cases and grades the rulings, with no LLM in the grading path.

hwcontract (PyPI) Temporal assertions over hardware traces. Runs as a pytest plugin, a GitHub Action, and an MCP server.

Open source contributions

  • Zed editor: merged PR #48870, credited in v0.224.0-pre
  • Roboflow: merged an RF-DETR and ByteTrack sports tracking pipeline

Research

  • "Comparative Assessment of YOLO Nano Architectures for High-Speed Steel Detection"
  • "Secure Edge Deployment of Machine Vision System on FPGA Platform", IEEE CW 2026, accepted

Contact

Email Portfolio

Pinned Loading

  1. clawvet clawvet Public

    Skill vetting & supply chain security for the OpenClaw ecosystem. Scans SKILL.md files for prompt injection, credential theft, remote code execution, typosquatting, and social engineering — catchin…

    TypeScript 11 3

  2. mcp-uplift mcp-uplift Public

    Run legacy MCP stdio servers behind the 2026-07-28 protocol. Translates the removed initialize handshake, sessions, and server-initiated requests.

    JavaScript 2

  3. YOLOv8_DANN_CBAM YOLOv8_DANN_CBAM Public

    Implements a domain-adaptive object detector based on YOLOv8n, enhanced with CBAM (Convolutional Block Attention Module) and DANN (Domain-Adversarial Neural Network) for improved cross-domain detec…

    Python 11

  4. unix-ancillary unix-ancillary Public

    Rust 6