Skip to content
View Addy-shetty's full-sized avatar
๐Ÿ’ญ
I may be slow to respond.
๐Ÿ’ญ
I may be slow to respond.

Highlights

  • Pro

Block or report Addy-shetty

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
Addy-shetty/README.md

Hey ๐Ÿ‘‹ I'm Harshith M S

I break things on purpose โ€” then build tools so others can do it faster.

Bengaluru, India ยท 100+ Labs ยท Active VDP ยท Web + AI Sec


About

  • Application Security Engineer & Project Lead at GND Solutions, with a strong foundation in offensive security, VAPT, and cyber intelligence.
  • Previously worked with the Karnataka State Police (State Intelligence), uncovering 45+ web vulnerabilities contributing to real-world investigations.
  • Currently focused on AI-accelerated DevSecOps, AWS IAM hardening, and web/API security testing, while building open-source offensive tooling.
  • Profile Snapshot

    Role: Application Security Engineer & Project Lead
    Location: Bengaluru, India
    Former: Ethical Hacker & OSINT Analyst @ Karnataka State Police
    Arsenal: Penetration Testing ยท Bug Bounty / VDP ยท Web Exploitation ยท OSINT & Recon ยท AI Security ยท Python Tooling ยท Burp Suite ยท Linux / Kali ยท Nmap ยท JavaScript ยท LLMs ยท Docker ยท Git ยท OpenClaw

    Active Operations

    PITT โ€” tooling Lightweight offensive utility focused on practical security testing workflows.
    Python Security ยท Repository โ†—

    Vibe Prompting โ€” open source Experimentation with prompt engineering techniques for smarter AI interactions.
    LLMs Prompt Engineering ยท Repository โ†—

    Auto_XSS โ€” automation Automated XSS detection tool for faster web vulnerability discovery.
    Python Web Security ยท Repository โ†—

    Mission Timeline

    [07/2022 - 12/2022]  Cybersecurity Intern
                        Built foundations in networking, Linux administration,
                        and core security principles.
     
    [09/2022 - 03/2025]  Ethical Hacker & Social Media Analyst โ€” Karnataka State Police
                        VAPT, cyber intelligence, and dark-web OSINT monitoring.
                        Identified 25+ web vulnerabilities supporting investigations.
     
    [03/2025 - Present]  Application Security Engineer & Project Lead โ€” GND Solutions
                        STATUS: ACTIVE
                        Leading end-to-end technical projects with accelerated AI workflows.
                        Architecting DevSecOps pipelines (Jenkins, Snyk, Semgrep, SonarQube).
                        Hardening AWS IAM and performing web/API security testing.
    

    Community

    Bug Bounty Tips โ€” 5.8k+ members A growing cybersecurity community focused on vulnerability research, writeups, and practical insights.

    • โšก Articles & curated security tips Blog
    • ๐ŸŽ™๏ธ Talks, workshops, and knowledge sessions
    • ๐Ÿค– AI-powered meme agent for the community

    ๐Ÿ‘‰ Join here: Telegram

    Tool chains

    DevSecOps & Automation: Jenkins, GitHub Actions, Docker.

    • SAST/Code Quality: SonarQube, Semgrep, CodeQL.
    • SCA & Container Security: Trivy, Snyk, Dependabot.
    • IaC Security: Terraform, Checkov (Infrastructure as Code scanning).

    VAPT & Bug Bounty Tools: Burp Suite Professional, OWASP ZAP, Nmap, SQLmap, Metasploit, Wireshark, Postman (API).

    OSINT & Recon: Shodan, Maltego, SpiderFoot, Recon-ng, Google Dorks.

    AI Security & Development: Languages: Python, Bash (Scripting & Automation). AI Projects: Prompt Injection Testing Tool (PITT), Vibe Prompting, Adversarial LLM Testing.

    Outside the Terminal

    When not testing systems (with permission):

  • ๐Ÿค– Running an AI agent for cybersec Name Vulnops
  • ๐ŸŽ™๏ธ Preparing For AWS SSA and Security Specialist/li>
  • ๐Ÿ”Ž Hunting for one more valid finding
  • ๐Ÿง  Debating edge cases with LLMs

  • Thanks for stopping by โญ My Loving Projects

    Pinned Loading

    1. Pitt Pitt Public

      PITT is an openโ€‘source, OWASPโ€‘aligned LLM security scanner that detects prompt injection, data leakage, plugin abuse, and other AIโ€‘specific vulnerabilities. Supports 90+ attack techniques, multipleโ€ฆ

      Python 4 3

    2. Vibe-Prompting Vibe-Prompting Public

      ๐ŸŽจ AI-Powered Prompt Generator | Transform ideas into powerful AI prompts instantly with smart credit system, real-time streaming, and 14 specialized categories. Built with React, TypeScript, Supabaโ€ฆ

      TypeScript 125 30

    3. Auto_xss Auto_xss Public

      auto_xss is a Bash script designed to automate the process of discovering XSS vulnerabilities in web applications. It integrates various tools to streamline the workflow from subdomain discovery toโ€ฆ

      Shell 6

    4. Cold_chain_intelligence Cold_chain_intelligence Public

      The Cold Room Operational Intelligence (COI) module continuously analyzes multiple sensor inputs---including temperature, humidity, door status, COโ‚‚ concentration, configured temperature/humidity sโ€ฆ

      TypeScript