01 · Roasts
Security lab, no safety net
PortSwigger-Academy-Exploits chains password resets to admin deletion, then skips tests and CI entirely.
Documentation outruns adoption
Several lab READMEs explain the exploits; 0 stars, 0 forks, and 0 watchers say nobody has signed the guestbook yet.
Python monoculture
100% of language bytes are Python, and the visible portfolio is one exploit-collection archetype.
Built using
Zoral
Shadows one worker for a week, then takes over their job with zero extra setup. Behaves exactly like the original.
zoral.ai
02 · Category breakdown
- Impact25% weight20F
- Consistency20% weight30F
- Quality20% weight40D
- Depth15% weight35F
- Breadth10% weight25F
- Community10% weight5F
03 · Stats
365-day commit heatmap
32 active days
Language distribution
- Python100%
04 · Numbers
Owned repos
non-fork
1
Commits
last 12 months
10
Followers
0
Joined GitHub
Oct 2025
05 · Top repos
06 · Timeline
- Oct 6, 2025Joined GitHub
- Jul 28, 2026Created PortSwigger-Academy-Exploits — Automated exploit scripts for PortSwigger Web Security Academy labs in Python & C.
- Aug 4, 2026Most recent push to PortSwigger-Academy-Exploits
07 · Compare
08 · Rubric
How this score was produced
Overall = Σ (category × weight) + gentle top-end curve
Tier thresholds
▸ How the pipeline works
- 01Scrape.Pull every non-fork repo pushed in the last 90 days, plus your contribution calendar, followers, and language byte counts — straight from GitHub's REST & GraphQL APIs.
- 02Triage.A small model reads every repo's file tree + README and picks the 20 files per repo that actually reveal how you code.
- 03Grade each repo. All repos run in parallel through a fast scoring model that reads the picked files and rates each one independently on Impact, Quality, and Depth — with evidence citations.
- 04Aggregate. A larger reasoning model combines the per-repo scores with server-computed stats (heatmap, commit cadence, language entropy, follower count) to produce the 6-dimension profile score + roasts.
- 05Correct.Deterministic server-side checks enforce anchor-scale floors (e.g. a profile with 2,000+ public commits can't score 30 Consistency) and recompute the final verdict.
~90 seconds per profile, ~$0.25 in compute. Total of ~240 files read across your top-12 repos. One rating per GitHub account per day.
▸ Data sources & caveats
- Heatmap & commit totals: GitHub GraphQL
contributionsCollection— covers the last 365 days, includes private repos when the user has opted in (default). - Language %: byte totals across the top 30 owned non-fork repos.
- Curve: a small upward nudge centered on raw score ≈ 70, capping at 100. Prevents specialists from being unfairly penalised for narrow breadth.
- Anchor corrections: when server-measured signals (e.g. privateWorkLikely, multiRepoVolume, follower count) mandate a minimum category score, the aggregation step enforces it. These are signal-conditional, not identity-based floors.