Software Engineering student @ University of Southern Denmark · I build LLM-native security tooling and full-stack systems.
LinkedIn · Argo findings · agerculture.com · Email
I run Argo, my own LLM-native vulnerability scanner, as the front of a coordinated responsible-disclosure program across open-source projects. Real, verifiable outcomes:
- CVE-2026-85724 — Critical (CVSS 9.6): pattern-ACL wildcard injection in the moquette MQTT broker.
- CVE-2026-73213 — coturn TURN/STUN relay (IPv6 range-comparison SSRF).
- CVE-2026-82410 — PocketBase (High, CVSS 8.7): unhandled panics in worker goroutines.
- LiveKit Security Hall of Fame — credited researcher.
Every finding is human-triaged, cross-validated, and PoC-verified where feasible, then disclosed through each project's security policy. The full record of published advisories and merged upstream fixes is on the → live findings site: gigioneggiando.github.io/argo
- Argo — LLM-native static vulnerability detection. An LLM reads your source like a human auditor; guardrails enforced in code, detection-only, multi-backend (Claude / Codex / local OSS). Python · Apache-2.0.
- Ager — a non-profit, link-first quality-news aggregator I co-founded and engineer end-to-end (live beta). .NET 9 · Next.js 16 · PostgreSQL/pgvector, self-hosted.
- Student teaching assistant for the Operating Systems course @ SDU (helping students with labs and exercises).
- Exploring research in LLMs & AI agents for software security.
Python · C# / .NET 9 · TypeScript / Next.js · FastAPI · PostgreSQL / pgvector ·
MySQL · Docker · LLM pipelines & agents · application-security & responsible disclosure


