- 01Static analysisRazinDeterministic security analysis for LLM agent skills.
- 02Supply chainSlopLockA CI guardrail for nonexistent and suspiciously new packages.
- 03Secret validationArcherFind exposed secrets, then verify whether they are usable.
- 04Application securityQuickXSSA focused Bash workflow for automated XSS discovery.
Keshav Malik / Product security engineer
Somewhere between a commit and an incident
Professionally curious about unintended behavior.
I work across software supply chains, CI/CD systems, application security, and static analysis. Then I build tools that turn recurring risk into engineering controls.
01 / Selected work
Things built to answer a specific question.
Tools for examining trust, evidence, and failure across code and delivery systems.
02 / Expertise
Security as an engineering problem.
Four connected areas, approached through design, automation, and precise evidence.
03 / Open source
Changes sent upstream.
05 / About
Engineering over theatre.
Question. Build. Break. Repair.
I’m Keshav, a senior product security engineer at LinkedIn. My work centers on software supply chain security, design review, and security automation.
I like problems that sit between security and engineering: understanding how a system fails, finding the smallest useful control, and making that control work at scale.
Sometimes I contribute to open source.