Skip to content
View TerminalsandCoffee's full-sized avatar

Block or report TerminalsandCoffee

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
TerminalsandCoffee/README.md

Rafael Martinez

I build and break web applications, APIs, and AI systems.

My work focuses on practical application security: building security controls, testing the assumptions behind them, reproducing failures, and turning the results into open-source tools, labs, and research.

Currently building Secure Cloud Academy.

AI Security

Project What it is
llm-security-gateway Security gateway for LLM applications supporting prompt-injection detection, PII scanning/redaction, streaming, and AWS deployment with Terraform.
AI-Security-Architecture Practical AI security architecture covering threat modeling, OWASP LLM risks, jailbreaks, RAG, agents, and security program development.
openclaw-deploy-zero-trust Zero-trust AWS deployment for self-hosted AI agents using Tailscale, private access, managed secrets, and hardened EC2 configuration.

Web & API Security

Project What it is
salvo-cli Go-based offensive web security CLI combining reconnaissance, request replay, and automated fuzzing workflows.
webapp-security-portfolio Application security lab covering AWS WAF, OWASP attack scenarios, logging, analysis, and infrastructure as code.
detection-engineering-lab Detection-as-code lab with Wazuh, MITRE ATT&CK-mapped detections, Terraform infrastructure, and CI validation.

Current Research

I'm increasingly focused on AI-native application security — especially the places where model behavior, application logic, untrusted context, APIs, and security controls intersect.

Areas I'm exploring include:

  • Prompt injection and instruction-boundary failures
  • Indirect prompt injection
  • LLM security control bypasses
  • Agent and tool-use security
  • API attack-surface discovery
  • Automated security testing for AI applications

The goal is simple:

Build the control. Break the control. Understand why it broke. Make the test repeatable.

How I Build

Python · Go · Terraform · FastAPI · AWS · GitHub Actions

Cloud infrastructure is the delivery system.

The work is web, API, and AI security.

Connect

LinkedIn · Medium · Secure Cloud Academy · rafael@terminalsandcoffee.com

Pinned Loading

  1. aws-devops-portfolio aws-devops-portfolio Public

    A collection of AWS DevOps projects built with Terraform, AWS, and GitHub Actions. Each project follows the AWS Well-Architected Framework and demonstrates scalable Infrastructure as Code.

    HCL 2

  2. webapp-security-portfolio webapp-security-portfolio Public

    A repo containing webapp security projects

    HCL

  3. security-architecture-fundamentals security-architecture-fundamentals Public

    A Cyber Security Architecture study and reference repo focused on fundamentals, cloud design, threat modeling, risk assessment, and framework-driven decision making.

    2 3

  4. salvo-cli salvo-cli Public

    Bug bounty CLI — recon, repeater, and fuzzer in one tool.

    Go

  5. detection-engineering-lab detection-engineering-lab Public

    Detection engineering lab — Wazuh-based detection rules, CI/CD pipeline, and theory documentation mapped to MITRE ATT&CK.

    Python 2

  6. CloudAutomationProjects CloudAutomationProjects Public

    A collection of multi-cloud automation scripts in Python, PowerShell, and Bash for AWS and Azure.

    Python 5 2