Skip to content
View gigioneggiando's full-sized avatar
🕯️
🕯️

Block or report gigioneggiando

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
gigioneggiando/README.md

Luigi Colluto

Software Engineering student @ University of Southern Denmark · I build LLM-native security tooling and full-stack systems.

LinkedIn · Argo findings · agerculture.com · Email

CVE-2026-85724 CVE-2026-73213 CVE-2026-82410 LiveKit Hall of Fame


🔎 Security research

I run Argo, my own LLM-native vulnerability scanner, as the front of a coordinated responsible-disclosure program across open-source projects. Real, verifiable outcomes:

  • CVE-2026-85724 — Critical (CVSS 9.6): pattern-ACL wildcard injection in the moquette MQTT broker.
  • CVE-2026-73213coturn TURN/STUN relay (IPv6 range-comparison SSRF).
  • CVE-2026-82410PocketBase (High, CVSS 8.7): unhandled panics in worker goroutines.
  • LiveKit Security Hall of Fame — credited researcher.

Every finding is human-triaged, cross-validated, and PoC-verified where feasible, then disclosed through each project's security policy. The full record of published advisories and merged upstream fixes is on the → live findings site: gigioneggiando.github.io/argo

🛠️ Projects

  • Argo — LLM-native static vulnerability detection. An LLM reads your source like a human auditor; guardrails enforced in code, detection-only, multi-backend (Claude / Codex / local OSS). Python · Apache-2.0.
  • Ager — a non-profit, link-first quality-news aggregator I co-founded and engineer end-to-end (live beta). .NET 9 · Next.js 16 · PostgreSQL/pgvector, self-hosted.

🌱 Currently

  • Student teaching assistant for the Operating Systems course @ SDU (helping students with labs and exercises).
  • Exploring research in LLMs & AI agents for software security.

🧰 Stack

Python · C# / .NET 9 · TypeScript / Next.js · FastAPI · PostgreSQL / pgvector · MySQL · Docker · LLM pipelines & agents · application-security & responsible disclosure

📫 Connect

LinkedIn · luigicolluto2006@gmail.com

Pinned Loading

  1. argo argo Public

    LLM-native static vulnerability detection: point it at a repo and get a reviewable vuln report, the way a human auditor would.

    Python 59 10

  2. ager-app ager-app Public

    AGER — link-first Italian civic news aggregator (web + mobile frontend)

    TypeScript 2