S1000D MCP Server
Agentic Review Workflow for Technical Publications · Independent Project, 2026
Shipped
An MCP server and agentic review workflow for S1000D technical publications — the structured-authoring standard used across aerospace and defense. Exposes schema validation, cross-reference integrity checking, applicability checking, and LLM-assisted fix suggestions as tools an agent can call directly, chained into one review skill via a Claude SKILL.md. Built on a hand-built subset schema and a fully fictional sample corpus — no proprietary content. Then I red-teamed it — path traversal, XXE, oversized-input DoS, prompt injection — fixed what broke, and put the fixes behind a CI security gate.
Python
lxml
MCP SDK
Anthropic API
pytest
GitHub Actions
OWASP LLM Top 10
MCP Security Suite
CI-Gated Security Testing for MCP Servers · Independent Project, 2026
Active
A reusable security suite any MCP server plugs into, and a CI gate that keeps them honest. Layer 1 runs repo scanners (bandit, pip-audit, gitleaks); layer 2 speaks MCP directly and black-box fuzzes every tool for path traversal, oversized input, output injection, and error leakage — including a differential probe that catches a tool reaching outside its directory even when nothing leaks (the exact bug an off-the-shelf scanner missed). I built it by red-teaming my own S1000D server — it surfaced arbitrary file read/write, a file-existence oracle, and an exfiltration chain, all now fixed — then used it to gate two servers in CI with branch protection and a weekly scan, which caught a transitive-dependency CVE on its own. Mapped to the OWASP LLM Top 10 and MCP Security Cheat Sheet.
Python
MCP SDK
GitHub Actions
bandit
pip-audit
gitleaks
OWASP LLM Top 10
DevTrack MCP
AI Access to Issue Tracking · Independent Project, 2026
Shipped
An MCP server that lets Claude (or any MCP client) file, search, update, and report on tasks in TechExcel DevTrack — the issue tracker behind a lot of real documentation workflows. Eight tools over DevTrack’s REST API. Ships pointed at TechExcel’s public sandbox so anyone can demo it; two environment variables point it at a real instance. Where the vendor docs wouldn’t load, I left endpoints in the backlog instead of guessing.
Python
MCP SDK
httpx
Pydantic
pytest
REST API
Café Fausse
Full-Stack Restaurant Reservation Platform · Independent Project, 2025
Shipped
A full-stack reservation platform designed and built end-to-end — React front end, Flask REST API back end, and a PostgreSQL relational database — with real-time availability checks, automated table assignment across a 30-table inventory, and booking confirmation/error handling. Includes a responsive, cross-browser interface with a validated email-newsletter signup flow. Designed, built, tested, and documented using agentic, AI-assisted development practices with Claude Code, including a full Software Requirements Specification and deployment README.
React
Flask
PostgreSQL
REST API
Claude Code