Basra, Iraq · Building useful, understandable, and safer technology
I am Ali Alkarar, known on GitHub as @9gkc. I design and build practical security tools, secure web applications, learning platforms, and open-source projects with a strong focus on clarity and responsible use.
My work sits at the intersection of application security, full-stack engineering, defensive tooling, and Arabic-first technical education. I care about software that solves a real problem, communicates its limitations honestly, and remains maintainable after the first release.
Responsible-use boundary: Security research and testing are performed only with explicit authorization, within an approved scope, and with safeguards that reduce unnecessary impact.
| Area | Direction |
|---|---|
| Application security | Defensive review workflows, authorization verification, secure defaults, and structured findings. |
| Security education | Arabic-first learning experiences, safe labs, progressive roadmaps, and accessible explanations. |
| Product engineering | Focused web, desktop, Android, and browser applications built around reliable state and clear user flows. |
| Open source | Small, documented, verifiable projects that are useful to learners, builders, and security practitioners. |
These projects represent the strongest themes across my current portfolio. Each link points to the project’s official repository or release surface.
| Project | Purpose | Explore |
|---|---|---|
| CyKun | Arabic right-to-left Android reader for university cybersecurity stages, semesters, subjects, lectures, approved PDF resources, announcements, and timetable notices. | Releases |
| FileGuard | Bilingual, offline-first Windows utility for inspecting selected local files without executing them or automatically uploading data. | Releases |
| AuthZGuard | Defensive authorization-verification tooling for explicitly approved API scopes, with CI-friendly reports and safety controls. | Documentation |
| IraqCode | Arabic-first bilingual programming platform with sequenced lessons, project missions, local progress, and a transparent skill passport. | Live platform |
| AegisScope | Allowlist-first AppSec workspace for authorized assets, low-impact reviews, findings, and structured reporting. | Platform |
Cyber 4 Ever provides a bilingual cybersecurity learning workspace with safe-lab guidance and role-based roadmaps. Al-Kunooze-Security focuses on defensive web-security workflows with server-side target validation. WiFiScan is a defensive Python utility for inspecting Wi-Fi security and encryption information without automatically enabling network interfaces. AtomicSite presents educational material on encryption, network security, and secure-system concepts.
ShopFlow, Bookmarker, NewsFeed, CurrConv, and Eventify explore validated data, safe rendering, predictable state handling, and accessible interfaces.
PassGen, QuoteGen, Roshambo, SlideShow, and TicTacToe demonstrate practical browser development, responsive interaction, and controlled client-side state.
| Capability | Tools and practices |
|---|---|
| Languages | JavaScript, TypeScript, Python, Dart, Java, HTML5, and CSS3. |
| Web and mobile | React, Node.js, Express, Firebase, Flutter, and Tailwind CSS. |
| Security | Burp Suite, Kali Linux, Wireshark, Metasploit, OWASP ZAP, and defensive validation. |
| Delivery | Git, GitHub Actions, Postman, Docker, VS Code, documentation, and incremental verification. |
I work from a few consistent principles: secure by default, explicit authorization, accessible interfaces, small verifiable changes, transparent limitations, and documentation that reflects the implementation. In security-focused projects, responsible-use boundaries are part of the product—not a disclaimer added at the end.
I welcome focused collaboration on open-source security tooling, Arabic-first technical education, secure web applications, and responsible disclosure. If you are reporting a security concern, please follow the private process described in SECURITY.md instead of posting sensitive details publicly.
For contribution standards, scope expectations, and pull-request guidance, see CONTRIBUTING.md.
The best way to reach me is through LinkedIn or email. You can also explore the complete project portfolio through my GitHub profile.
Build with clarity. Test with authorization. Ship useful software.