Skip to content
View lspassos1's full-sized avatar

Block or report lspassos1

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
lspassos1/README.md

Lucas Passos

Full-stack — application security · OSINT & intelligence dashboards · geospatial data viz

Mapa da Violência Brasil · GitHub


👋 Overview

I build data-heavy products end to end — from typed RPC backends and statistical scoring to map-based frontends — with a strong focus on application security and on turning messy public data into trustworthy intelligence.

Most of my recent work lives at the intersection of OSINT, geospatial visualization, and security hardening: near-real-time dashboards that aggregate noisy sources (news, official datasets, third-party APIs) and present them honestly — always separating verified signal from unverified indication.


🧭 Specialties

  • Application security & hardening — SSRF/XSS mitigation, CSP / COOP-COEP, request-spoofing defenses, sandbox isolation by nonce, dependency & CVE patching.
  • Full-stack feature delivery — Protocol Buffers + typed RPC services, statistical scoring, reusable widgets, maps, and the test suites around them.
  • Geospatial & data viz — MapLibre GL / deck.gl, choropleth layers, near-real-time georeferenced data.
  • OSINT & intelligence pipelines — multi-source ingestion, keyword-first + LLM classification, deterministic deduplication, source-credibility framing.

🌐 Open source

Core contributor to koala73/worldmonitor — the open-source real-time global intelligence dashboard (AGPL-3.0). I shipped the "Resilience" intelligence dimension end to end: proto service + stub handlers, country dimension scorers and shared statistical utilities, score/ranking RPC handlers with premium gating, a reusable deep-dive widget with a choropleth map layer, and dedicated scorer/ranking test suites. I also contributed extensive security hardening across the gateway, sidecar and widget layers (private-target fetch blocking, header-spoofing fixes, sandbox nonce gating, CSP headers, base-image CVE patches).


📌 Featured project

Mapa da Violência Brasil — a near-real-time gun-violence radar for Brazil: live georeferenced shootings (Fogo Cruzado) + a national OSINT news layer (keyword-first + dictionary geocoding, no LLM where avoidable) + an anomaly radar that flags where official statistics may be unreliable. Built with Next.js · TypeScript · MapLibre · Supabase. AGPL-3.0.


🛠 Stack

TypeScript, Next.js, React, Node.js, Protocol Buffers / typed RPC, PostgreSQL / Supabase, MapLibre GL · deck.gl, Tailwind CSS, Python (data/ETL), Docker, Vercel.


GitHub stats Top languages

Popular repositories Loading

  1. egos-lab egos-lab Public

    Forked from jorgyvanlima/egos-lab

    TypeScript 1

  2. WD WD Public

    Forked from koala73/worldmonitor

    Real-time global intelligence dashboard — AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface

    TypeScript

  3. brazil-visible-sdk brazil-visible-sdk Public

    Forked from nferdica/brazil-visible-sdk

    📦TypeScript SDK for 93+ Brazilian public data sources — unified access to IBGE, BCB, CGU, TSE, Receita Federal & more. 22 modules, 97 typed methods, zero config.

    TypeScript

  4. EGOS-Inteligencia EGOS-Inteligencia Public

    Forked from enioxt/br-acc

    Python

  5. aframe-kingspan-local aframe-kingspan-local Public

    TypeScript

  6. mapa-da-violencia-brasil mapa-da-violencia-brasil Public

    Radar de tiroteios em tempo quase real + mapa oficial + radar de anomalia do dado de violência no Brasil. Indício ≠ estatística oficial.

    TypeScript