镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content
View Zeerg's full-sized avatar
🤖
⃐ ⃑ ⃒ ⃓ ⃔ ⃕ ⃖ ⃗ ⃘ ⃙ ⃚ ⃛ ⃜ ⃡ ⃥ ⃦ ⃧ ⃨ ⃩ ⃪ ͣ ͨ ͩ ͤ ͪ ͥ ͫ ͦ ͬ ͭ ͧ ͮ ͯ
🤖
⃐ ⃑ ⃒ ⃓ ⃔ ⃕ ⃖ ⃗ ⃘ ⃙ ⃚ ⃛ ⃜ ⃡ ⃥ ⃦ ⃧ ⃨ ⃩ ⃪ ͣ ͨ ͩ ͤ ͪ ͥ ͫ ͦ ͬ ͭ ͧ ͮ ͯ

Sponsoring

@python

Highlights

  • Pro

Organizations

@K8sSMM

Block or report Zeerg

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Zeerg/README.md

Tom Bowyer

I'm a security leader who has spent the past four years helping security teams succeed through servant leadership.

I focus on removing blockers, supporting people, and helping teams do their best work. I bring deep technical experience to my leadership and keep building security tools.

I'm looking for a security leadership role where I can support a team, develop its people, and improve how it protects the organisation.

GitHub Activity

Tom's GitHub activity

Selected Work

An AI pull-request reviewer built around narrow, structured questions rather than free-form review explanations.

Lisa reads PR changes through GitHub's API without running PR code. It loads configuration from the base commit and fails checks when required review coverage is incomplete.

Dependency tooling for npm and Python, focused on install-time security.

OMC checks package capabilities against explicit policies, skips install scripts, and compares dependency versions for changes in behavior. Its checks are not a runtime sandbox.

A security engineering workbench built from OpenCode.

The project brings together a desktop client, an agent backend, security tools, and cross-platform packaging. It also documents execution policies and trust boundaries.

Writing

I write about security engineering, AI agents, and the decisions behind the tools I build.

Read my technical posts

Pinned Loading

  1. turenlabs/batou turenlabs/batou Public

    Batou catches risky code while Claude Code is writing files, before bad code lands in your repo.

    Go 5

  2. turenlabs/spice turenlabs/spice Public

    OSS exposure checker for developers

    Go 1

  3. turenlabs/omc turenlabs/omc Public

    A drop-in npm/pip that never runs install scripts. Deny-by-default supply-chain security for npm & PyPI.

    Rust 2 1

  4. turenlabs/turenos turenlabs/turenos Public

    TurenOS local-first AI security agent harness. Works with most models and providers

    TypeScript 8

  5. turenlabs/jast turenlabs/jast Public

    JAST is an experimental SAST (static application security testing) desktop app that uses TypeSafe AI's Jev System One model.

    Rust 1

  6. helix-honeypot helix-honeypot Public

    K8s API Honeypot with Active Defense Capabilities

    Go 44 7