I build security-aware web systems and local-first browser tools. Same sequence every time: understand the mechanism → locate the trust boundary → state the limits.
- 2fa — browser-local TOTP
- MCC2T — Microsoft cookie → Minecraft token chain
- Image-Obfuscation — reversible pixel permutation
- VibeChat — local
llama.cppor remote OpenAI-compatible chat - tinylink-nextjs — short links + analytics
- AboutHali — WebGL homepage for userhali.com

