Skip to content
View ztothez's full-sized avatar

Highlights

  • Pro

Block or report ztothez

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ztothez/README.md

Hi, I'm Roosa

I build AI systems and software tools end-to-end: multi-agent pipelines, LLM integrations, Python backends, REST APIs, and automation workflows. I use AI coding tools by default and make their output prove itself with tests, evidence, and clear system boundaries. My background is in cybersecurity, which shapes how I think about reliability, failure modes, and systems that have to work unsupervised.

Finishing MSc in Information Technology at the University of Turku (Robotics and Autonomous Systems; multidisciplinary AI minor), expected 2027-2028. Master's thesis planned in robotics and AI. Based in Turku, Finland.

Featured Projects

Open-source MCP server and deterministic quality gate for AI-built UI. Turns product intent, interface truth, information hierarchy, accessibility, and browser evidence into enforceable, evidence-backed contracts. 20 scoped MCP tools, automated repository audits, browser verification, and 168 automated tests.

Browser-based demoscene builder for beginners, designed and built solo in 20 hours. Onboarding, 21 learning paths, real-time effects, empty and error states, and offline export. TanStack Start, React 19, TypeScript, and Canvas API, no backend. 2nd place at the Assembly Summer 2026 Fix It Competition. Source is not public; see the live app on my website.

Portfolio code quality and security auditor built on RAG, LLM agents, and vector search. FastAPI backend with async Python, pgvector semantic search over 20,875 embeddings from 8 security books, LangGraph ReAct agent with custom tools, Pydantic validation, prompt-injection checks, and CI/CD via GitHub Actions. Evaluation suite with 15 OWASP and clean-code test cases (7/15 passing with diagnosable failures in progress).

4-agent LangGraph pipeline built for the AMD Developer Hackathon 2026. Converts MITRE ATT&CK techniques into Sigma detection rules, SOC response guidance, and validation scores. Public Hugging Face Spaces deploy (Docker, nginx); demo mode for reliability with a vLLM/ROCm inference path on AMD Instinct MI300X.

Paying client delivery; client identity remains private, repo published with permission. FastAPI system linking work orders to pipe and material inventory. Tracks consumption, scrap, and reusable remnants with a full audit trail. Deployed on Linux with nginx and systemd. Includes authentication, CSRF protection, and a full handover package.

Multi-agent infrastructure audit system. A configuration agent inspects Terraform IaC for missing guardrails, a metrics agent analyzes operational data, and a supervision agent calls the Anthropic API to synthesize findings into an actionable audit report. Built with Python, Streamlit, and the Anthropic SDK.

FastAPI backend with SQLAlchemy, cursor-based sync, async httpx with retry/backoff, SSE live feed, input validation, and CI smoke tests on every push.

Other Work

Fully local voice assistant built from scratch. faster-Whisper for speech recognition, Ollama for LLM inference, Piper TTS for voice output, FastAPI web interface with browser microphone support. No cloud APIs. Supports custom fine-tuned models via Ollama Modelfiles.

Browser Extensions (live on Firefox & Chrome)

ShodanLookup · VirusTotal-Lookup · AbuseIPDBCheck · Windows-Security-Event-Log-lookup Lightweight extensions for IOC validation and infrastructure intelligence. Privacy-first, no data collection.

Security Research

Independent bug bounty researcher on HackerOne, Intigriti, and Bugcrowd (2018 to 2026). Bug-bounty-pocs contains sanitized PoCs from web security research: CORS misconfigurations, OS command injection, cryptographic weaknesses.

Focus Areas

  • Agentic AI systems and multi-agent orchestration
  • AI-assisted development with verification: MCP tooling, evidence-gated quality, automated tests
  • LLM integration and local inference pipelines
  • Python backend development and REST APIs
  • Security-aware software engineering

Links

Website: ztothez.com LinkedIn: linkedin.com/in/roosayoruusu


Open to AI and software engineering roles.

Pinned Loading

  1. ztothez-design-engineering ztothez-design-engineering Public

    ZtotheZ Design Engineering: An MCP-backed closed-loop architecture for product design, interface verification, automated repair, and strict UI quality gates.

    TypeScript

  2. AI-Insight-Engine AI-Insight-Engine Public

    AI analysis engine combining RAG, LLM agents, and real-world data integration to produce structured, grounded outputs. In progress.

    Python

  3. aegisops-ai aegisops-ai Public

    4-agent purple-team detection copilot — MITRE ATT&CK to Sigma rules, SOC response guidance, and validation scores via LangGraph + vLLM on AMD MI300X ROCm

    Python

  4. Inventory Inventory Public

    Production inventory system for tube/pipe cutting workshops. Work orders, stock reservation, job completion with scrap and remnant tracking, low-stock alerts, .lst import, CSV exports, and full aud…

    Python

  5. azure-optimizer azure-optimizer Public

    Multi-agent system: config agent + metrics agent + Claude supervision layer producing infrastructure audit reports from Terraform IaC and operational data.

    TypeScript

  6. rps-league-app-python-fullstack rps-league-app-python-fullstack Public

    FastAPI full-stack: async httpx with retry/backoff, cursor-based sync, SSE live feed, SQLAlchemy, input validation, CI smoke tests. Python implementation.

    Python