skeletonsec
vulnerability research · exploit development · reverse engineering
skeletonsec is Ahmed Ibrahim’s vulnerability-research lab, working in public: 0/1/N-day analyses, CTF writeups, and the open tools built for that work — across web, native, and supply chain.
Everything here ships with evidence or it doesn’t ship. A bug without a reproducer is a rumor; a benchmark without a method section is marketing. Expect every post to end with something you can run.
now
- skelet0n phase 0 — engine and evidence ledger, in progress
- authprobe design notes — in draft, ships when the benchmarks are real
- first original-research disclosures — in the pipe
latest
- dissecting a git-exposure finding: anatomy of an information leak research
- skeletonsec is online research
- demo ctf 2026 — baby steps writeups