Skip to content
CLCarter LaSalle
AboutExperienceProjectsResearchBlogFilmsFingerprintContact

Opening record…

End of file / keep in touch

Carter LaSalle
GitHubLinkedInBlogFilmsFingerprintDevelopers

© 2026 Carter LaSalle. All rights reserved.

01Start02About03Experience04Projects05Research06Education07Contact

Security researcher / builder

CarterLaSalle

Security research, applied AI, and tools people actually use.

Inspect the work↓Open a channel
Case fileCL / 2026
Current
Engineering at Lila Sciences
Published
2 CVE disclosures
Open source
44K+ package downloads
Education
Notre Dame CS '29

Los Angeles ↔ Notre Dame

CVE-2025-45156 · CVE-2025-45157 · 44K+ DOWNLOADS · LILA SCIENCES · NOTRE DAME CS · CVE-2025-45156 · CVE-2025-45157 · 44K+ DOWNLOADS · LILA SCIENCES · NOTRE DAME CS ·

Profile / operating range

Security judgment. Product instinct. Builder speed.

The through-line is practical: understand the system deeply enough to expose what is fragile, then make something stronger.

I'm a Computer Science student at the University of Notre Dame and a published security researcher. My work spans vulnerability disclosure, network security, developer tools, applied AI, and systems that meet the physical world.

Right now, I'm contributing to engineering at Lila Sciences. I also co-founded Phoenix Fire Labs to develop autonomous wildfire monitoring with computer vision and drone integration.

Outside software, I volunteer on Skid Row, play club volleyball, and make 3D animated films. Those are not side notes: they are where technical work becomes human, visual, and accountable.

2Published vulnerability disclosures
44K+Open-source package downloads
5Cisco security certifications

Break systems responsibly

Access-control testing, network investigation, protocol analysis, and disclosure work grounded in reproducible evidence.

Ship tools people keep

Open-source and product engineering across Python, TypeScript, Next.js, MCP, SQLite, and applied AI.

Work across layers

From BLE packets and macOS databases to cloud infrastructure, computer vision, and human-facing product decisions.

Working set

Python / TypeScript / React / Next.js / MCP / Network security / Vulnerability research / Nmap / Kubernetes / Terraform / SQLite / Computer vision

Work / selected engagements

Learning where the stakes are real.

Security, scientific infrastructure, robotics, health data, and applied AI—work shaped by systems that have to function outside a demo.

Jun – Aug 2026Current

Lila Sciences

Engineering Intern

Contributing to engineering at an autonomous science company combining AI, robotics, and experimental infrastructure.

Engineering / AI / Autonomous Science

Nov 2025 – PresentCurrent

Phoenix Fire Labs

Co-Founder

Developing Prometheus, an autonomous wildfire monitoring system using computer vision and drone integration for real-time detection and tracking.

Python / Computer Vision / Drones

Jul – Sep 2025

Tompkins Robotics

Information Security Intern

Ran scoped Nmap and packet-capture investigations, diagnosed production connectivity across VPNs and VLANs, and contributed to Kubernetes and Terraform workflows.

Network Security / Kubernetes / Terraform

Jun – Sep 2024

Bluestone Health

Project Intern

Standardized healthcare eligibility data, delivered a CRM-integrated back-end platform, and designed the operator-facing experience.

Data Integration / Healthcare / Full Stack

Jul – Dec 2023

Expak Logistics

AI Software Developer

Built an intelligent assistant connecting company data across Freshdesk and Salesforce for fast, conversational access.

AI / API Integration / Python

Builds / public artifacts

Proof over pitch.

Tools and products are strongest when someone else can install them, inspect them, or rely on them.

Flagship open source / macOS + MCP

Mac Messages MCP

A secure MCP server that gives AI assistants controlled access to the macOS Messages database—search, analyze, and send with intelligent iMessage and SMS/RCS fallback.

PythonSQLitemacOSMCP
44K+package downloads

Autonomous systems

Prometheus / FireDrop

Computer vision and drone integration for continuous wildfire detection, tracking, and faster situational awareness.

Phoenix Fire Labs · Co-Founder

Python / Computer Vision / Drones / AI

Developer utility

treecat

A Go CLI and interactive TUI that turns codebases into syntax-highlighted context for LLMs, documentation, and code review.

Homebrew + native packages · automated releases

Go / TUI / Homebrew / GoReleaser

Network tooling

NetSift

A dependency-free packet-capture explorer that defensively decodes PCAP and PCAPNG files into terminal answers and deterministic structured output.

Dependency-free runtime · cross-platform CI

Python / Networking / PCAP / TLS / DNS

Network systems

PixelChangeCheck

A Rust screen-sharing system that transmits changed regions through direct QUIC, relay-backed NAT traversal, native viewers, and zero-install browser viewing.

Direct QUIC + relay NAT traversal

Rust / QUIC / LZ4 / MJPEG / Networking

Security research

EmojiStega

A steganography tool that hides encrypted payloads inside emoji variation selectors, exploring a covert channel in Unicode.

Encrypted Unicode covert channel

Node.js / React / Cryptography / Unicode

Live product

Stamina Timer

An AI-assisted men's health training platform built around structured exercises, progression, and confidence.

staminatimer.com · production

AI / Health Tech / Product

Developer utility

Claude Code Countdown

Tracks Claude Code rate-limit resets and sends timely SMS reminders before access returns.

Live service · Twilio notifications

Next.js / Twilio / Developer Tool

Computer vision

OneCard Scan

Digitizes student IDs for Apple Wallet and Google Pay using Gemini Vision and mobile pass tooling.

Senior capstone · deployed prototype

Python / Gemini Vision / PassKit

Research / responsible disclosure

The finding is only useful if the evidence holds.

Two published access-control vulnerabilities in Splashin, documented with reproducible impact and disclosed responsibly.

Read the full assessment →Inspect the repository

High severity

CVE-2025-45156

CVSS7.5

Update interval bypass exposed continuous location data

The backend did not enforce the advertised 600-second update restriction. Direct API calls could retrieve current location data at arbitrary intervals.

Endpoint
get_user_locations_by_user_ids_minimal
Impact
Unauthorized real-time tracking
Status
Published / disclosed

Critical severity

CVE-2025-45157

CVSS9.1

Missing subscription validation bypassed premium controls

A premium-only location request lacked server-side authorization, allowing free users to force immediate target updates through push notifications.

Endpoint
location-request
Impact
Complete access-control bypass
Status
Published / disclosed

Training / context

Computer science, security, and the worlds around them.

Formal study at Notre Dame, industry security training, and a visual practice shaped by four years of animation.

2025 — 2029 / Notre Dame, Indiana

University of Notre Dame

BA, Computer Science

Coursework and campus work spanning cybersecurity, artificial intelligence, political systems, and practical engineering. Active in Cyber Club, UAV Club, Wall Street Club, and club volleyball.

Verified security training

Cisco certifications

  • Cisco Ethical Hacker
  • Network Defense
  • Endpoint Security
  • Cyber Threat Management
  • Introduction to Cybersecurity

Visual work / recognition

Animation & honors

  • Best 3D Animated Film — Our Small World
  • Scholastic Art & Writing Honorable Mention
  • While America Sleeps — four showcase nominations
  • Johns Hopkins CTY — High Honors

Contact / open channel

Have a hard problem worth opening up?

Security research, applied AI, developer tooling, or something that crosses those boundaries—send the useful context and I’ll respond directly.

Emailcarterlasalle@gmail.comGitHub@carterlasalleLinkedIn/in/carter-lasalle