Skip to content
View macaugh's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report macaugh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
macaugh/README.md

Matthew Caughman

typing header

Building AI-powered security systems. Shipping production infrastructure.


What I Do

Senior Software Engineer at HackerOne building AI infrastructure, payments systems, and security tooling at scale. I architect agentic AI systems that amplify engineering teams (3x delivery velocity), build production Ruby on Rails backends handling critical financial transactions, and develop offensive security tools for automated vulnerability research. 12+ years shipping distributed systems across security, cloud, and embedded domains.

Currently exploring: Advanced fuzzing techniques, autonomous security agents with Claude & Bedrock, and AI-powered bug bounty automation.

AI/ML Infrastructure

Agentic Systems at Scale
Claude Code skills marketplace · Multi-agent orchestration · AWS Bedrock · MCP servers · RAG systems

Backend Engineering

Production Systems
Ruby on Rails · Payments (Stripe/Coinbase) · PostgreSQL · Microservices · GraphQL/REST APIs

Offensive Security

Automated Vuln Research
Bug bounty · Recon automation · Auth bypasses · API security · Privilege escalation

Featured Projects

redamon: Agentic Red Team Framework

Python · AI Agents · Offensive Security

AI-powered agentic red team framework that automates offensive security operations from reconnaissance to exploitation to post-exploitation, with zero human intervention.

strix: Open-Source AI Pentest Agents

AI Agents · Penetration Testing · Automation

Open-source AI agents for penetration testing. Autonomous security assessment through intelligent agent coordination.

hexstrike-ai: MCP Security Agents

MCP Server · 150+ Tools · Claude/GPT/Copilot

Advanced MCP server enabling AI agents to autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, and bug bounty automation.

PeezyPGP: Privacy-First Encryption

Swift · Ed25519 · AES-256-GCM · Secure Enclave

Privacy-first OpenPGP for iOS and macOS. Ed25519, X25519, AES-256-GCM with Secure Enclave integration and zero third-party dependencies.


More Projects

skills: Trail of Bits Claude Code Skills

Claude Code · Security Research · Audit Workflows

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows.

hound: AI Code Auditor

AI · Knowledge Graphs · Iterative Reasoning

Language-agnostic AI auditor that autonomously builds and refines adaptive knowledge graphs for deep, iterative code reasoning.

semdex: Project File Indexer for Claude

Semantic Indexing · Context Retrieval

Project file indexer for Claude. Speeds up project context retrieval through semantic understanding.

picoclaw: Tiny Autonomous Agent

Lightweight · Deployable Anywhere

Tiny, fast, and deployable anywhere. Automate the mundane, unleash your creativity.


Stack

Languages Ruby, Python, Go, TypeScript/JavaScript, C, Swift
Backend Ruby on Rails, Node.js, PostgreSQL, Redis, GraphQL, REST APIs, Event-Driven Architecture
AI/ML Claude API, AWS Bedrock, MCP Servers, Multi-Agent Orchestration, RAG, LLM Integration
Security Burp Suite, ffuf, Nuclei, BBOT, nmap, subfinder, httpx, SBOM/SCA
Infrastructure AWS (Lambda, ECS, Bedrock), Docker/Kubernetes, Terraform, CI/CD
Tools Claude Code, Obsidian, Neovim, Git

Experience

Senior Software Engineer | HackerOne | 2022 - Present

  • Architected enterprise AI infrastructure achieving 3x engineering delivery velocity
  • Built payments systems (Stripe/Coinbase) reducing incidents 58% and enabling 50K new crypto payees
  • Created internal AI skills marketplace adopted by 100+ engineers
  • Delivered Source Code Analysis (SCA) system with SBOM generation for H1-Code

Software Engineer | IBM | 2012 - 2022

  • Built cloud-native distributed systems on AWS and IBM Cloud at enterprise scale
  • Developed firmware security analysis and embedded systems tooling
  • Pioneered early AI/ML integration for automated threat detection workflows

Education | BS Electrical & Computer Engineering | UT Austin | 2012


GitHub

Popular repositories Loading

  1. super-rouge-hunter-skills super-rouge-hunter-skills Public

    Community-editable skills for Claude Code's super-rouge-hunter plugin

    4 3

  2. hopgoblin hopgoblin Public

    Forked from assetnote/hopgoblin

    Adobe Experience Manager (AEM) hacking toolkit

    Python 1

  3. large-file-entropy large-file-entropy Public

    C++

  4. macaugh macaugh Public

    Config files for my GitHub profile.

  5. tensorflow tensorflow Public

    Forked from tensorflow/tensorflow

    An Open Source Machine Learning Framework for Everyone

    C++

  6. typescript-eslint typescript-eslint Public

    Forked from typescript-eslint/typescript-eslint

    ✨ Monorepo for all the tooling which enables ESLint to support TypeScript

    TypeScript