Cybersecurity & LLM-Powered Tooling

We build open-source CLI tools and libraries for incident response, threat intelligence, and LLM-powered automation. Everything is designed to be pipe-friendly, composable, and lightweight — small tools that do one thing well.

Cybersecurity Workflow Tools

AI-augmented tools for threat intelligence, product risk assessment, and incident response analysis.

Email Analysis

Suspicious email analysis with rule-based indicators and LLM content analysis.

LLM Tools & Libraries

Small, local-first CLI tools for LLM interaction, retrieval, classification, and governance.

llm-cli

Go

CLI client for local LLMs (LM Studio, Ollama) — streaming, batch, multi-image VLM, structured output

lite-llm Archived

Go

Superseded by llm-cli — CLI client for OpenAI-compatible LLM APIs

lite-rag

Go

RAG CLI for Markdown docs using DuckDB — index and query local knowledge bases

lite-switch

Go

Natural language classifier for shell pipelines — routes stdin text to a matching tag via LLM

gem-cli

Go

Gemini CLI client — multimodal prompts, streaming, grounding, structured output via Vertex AI

gem-rag

Python

Gemini-powered RAG CLI for Markdown documents — Vertex AI embeddings and DuckDB

mcp-guardian

Go

MCP governance proxy — transparent auditing, OAuth2 auto-discovery, and tool masking

cclaude

Bash

Containerized Claude Code — run Claude Code in an isolated container with project isolation

nlk

Go

LLM utility toolkit — guard, jsonfix, strip, backoff, validate. Zero external dependencies

nlk-py

Python

Python edition of nlk — same 5 modules, same API design. Zero external dependencies

gem-search

Go

Agentic web search via Vertex AI Gemini — Google Search Grounding, Markdown/JSON output, pipe-friendly

gem-image

Go

Image generation and editing CLI — Vertex AI Gemini 2.5 Flash, pipe-friendly

gem-query

Go

Natural language data analysis CLI — interactive SQL generation for DuckDB/SQLite via Vertex AI Gemini

data-analyzer

Go

Large-scale JSON/JSONL data analysis — sliding window + progressive summarization with local LLMs

quick-translate

Swift

macOS menu-bar translation tool — powered by local LLM, always-on-top overlay

ChatOps & Slack

Pipe-friendly Slack tools for ChatOps automation and monitoring.

Service CLI Clients

Pipe-friendly, Unix-composable CLI clients for external services.

Data Processing Utilities

Pipe-friendly tools for data transformation, parsing, and visualization.

IoT & Embedded

Sensor data collection and monitoring on M5Stack hardware.

Claude Code Skills

Claude Code Skills for development process automation.

Experimental

Works in progress. APIs and interfaces may change without notice.