Automation & AI agent tooling
I build working automation with Claude Code and AI coding agents.
Not consulting, not slides — a real working CLI tool, automation pipeline, or AI-agent setup by
the time we're done. Everything below is live and public; open it and check it yourself before you get in
touch.
Real proof of work
agent-audit — CLI that scans AI
coding agent session logs for leaked credentials and risky commands.
Zero dependencies, 23 passing tests, CI on 3 Node versions, ships as both a CLI and a
GitHub Action. Read the actual source, not a summary of it.
QuickInvoice — a free, no-backend
invoice generator, live and working right now.
Built, tested, and shipped end-to-end in one sitting. Try it — nothing to sign up for.
n8n Engagement Monitor —
a scheduled automation template that tracks GitHub/dev.to engagement.
Verified by actually importing and running it, not just writing it and hoping.
What I can build for you
ONE AUTOMATION
$75
- One well-defined automated task (e.g. pull data from an API into a spreadsheet on a schedule)
- Delivered as a working script or n8n workflow
- 1 revision round, 2-day delivery
SMALL TOOL
$200
- A small CLI tool or multi-step automation pipeline
- Basic tests so it doesn't silently break
- Short README so your team can run it without me
- 2 revisions, 4-day delivery
WORKING MVP
$450
- A small tool/service with a simple interface, tests, and CI
- Written explanation of how it works and how to extend it
- 3 revisions, 7-day delivery
AI Agent Security Audit — $300
Your team is using Claude Code, Codex, or Cursor. Every session those tools run gets written to disk
verbatim — every .env cat, every API response, every command executed. Nobody's looking at
those files. I will.
- Run against your team's actual local session logs (or CI-collected transcripts) — not a generic
scan, tuned to your stack (cloud provider, RPC endpoints if you're on-chain, CI secrets conventions)
- Written report: what leaked, exact severity, which file/line, and concrete remediation steps —
redacted findings only, the report itself never contains a usable secret
- Delivered in 3 business days
- Add-on: wire it into your CI as a merge gate so it doesn't happen again — +$150
This isn't hypothetical: I ran this on my own development
machine before ever pitching it and found 71 real, previously-unnoticed leaked database credentials and
JWTs in one project's logs, plus live AWS keys in another. Full writeup here — or read
the open-source scanner itself.
Building on Ethereum/EVM chains?
I built agent-audit specifically to
catch what general-purpose scanners miss for Web3 projects: wallet seed phrases and private keys that
passed through an AI coding agent's session (a `.env` cat, a debug print) without ever touching a
committed file. If you want that run against your team's actual setup — not just the open-source CLI,
but wired into your CI, tuned for your specific RPC providers and key-management conventions — that's a
project I'll take on directly. Paid in USDC/ETH by default, which I'm guessing is not a novel request
for you.
Get in touch
Bring the problem, not the spec — most of this starts as "I do X manually every week and it's annoying."
Email with what you're trying to solve and I'll turn it into a concrete plan before anything starts.
Email gmslight@gmail.com
Payment
USDC/ETH accepted directly (Base network preferred — near-zero fees), same address across Ethereum,
Base, Polygon, Arbitrum, and Optimism:
0x36CCCB5854e1d513A2Af94CeaFC0f886102634e2
Other payment methods available on request — ask when you reach out.