Skip to content
Lab

Where ideas get a weekend. Some grow into tools. Some stay delightfully weird.

Side projects, tools and experiments. Most are public on GitHub; the private ones are marked.

TypeScript · 2026

Moat

Threat models usually live in a diagram nobody updates. Moat keeps one in a moat.yaml next to the code, turns it into a STRIDE threat register, and fails CI when a new risk shows up unhandled.

moat
$ moat init # scaffold a commented moat.yaml
$ moat validate # schema + referential integrity
$ moat generate # write the threat register into the file
$ moat report # markdown, with a mermaid DFD at the end
$ moat check # CI gate: exit 1 on open high-or-above

Try it. Flip properties on an element and watch which threats Moat raises.

Sbaseline

Spoofing

Tbaseline

Tampering

Rbaseline

Repudiation

Ibaseline

Information disclosure

Dbaseline

Denial of service

Ebaseline

Elevation of privilege

no context rules fired

Uses the baseline and context rules from Moat's README. The real tool reads a whole moat.yaml.

stellar-dvn
$ cargo test # 85 tests across contracts and verifier
$ stellar contract build
$ ./scripts/e2e-security-stack.sh # the full receive flow, 2-of-3 quorum
$ ./scripts/e2e-real-layerzero.sh # fee + attestation against real contracts

stellar-dvn

Rust · 2026

An independent LayerZero V2 verifier for Stellar, built for the fun of it and working end to end against LayerZero's real testnet contracts.

nivoui
nivoui/
├── apps/
│ ├── docs/ # Documentation site
│ ├── studio/ # Visual builder
│ └── sandbox/ # Component testing
├── packages/
│ ├── ui/ # Component registry
│ ├── react/ # React hooks & providers
│ ├── cli/ # CLI tool
│ └── utils/ # Shared utilities
└── tooling/ # Build scripts & codegen

nivoui

TypeScript · 2025

shadcn, but for Stellar apps. A component registry, React hooks and providers, a CLI that copies components into your project, plus a visual studio and docs.

README.md
# QueryMaster
- Create and manage projects
- Upload files to projects
- Generate vector embeddings using OpenAI
- Store the embeddings in Pinecone
- Query files through a chatbot interface

QueryMaster

JavaScript · 2024

Drop files into a project, then ask them questions. QueryMaster embeds everything with OpenAI, keeps the vectors in Pinecone and answers through a chat window, with the backend running on Zoho Catalyst functions.

Private repo
Just an idea so far

StellarMind

Early idea · 2025

An AI chatbot and code helper for Soroban smart contract developers. Still a sketch on paper.

Everything else100+ public repositories, from first commits to last week.