I’m a security-focused full-stack developer and systems integration specialist based in South Africa.
I build practical web applications, e-commerce platforms, business systems, and secure digital products.
I am building a public engineering contribution record through scoped open-source work focused on documentation quality, contributor experience, QA guardrails, testing workflows, and secure development practices.
A governed MCP runtime for the Apple ecosystem.
- PR #406 — Merged contribution improving testing documentation, Jest/Zod guidance, and docs-drift validation.
- PR #412 — Merged contribution refreshing
CONTRIBUTING.mdagainst the current registration and drift workflow. - Recognised as AirMCP’s first external contributor.
Skills shown: documentation quality, contributor workflow, test guidance, docs-drift prevention, maintainer review response, secure automation awareness.
Python internationalisation tooling and translated documentation quality.
- PR #26 — Improved translated documentation quality by restoring missing Markdown link targets and adding regression coverage.
- Added parity checking for both inline Markdown links and reference-style Markdown link definitions.
- Responded to automated review feedback with a follow-up fix and validation.
Skills shown: Python testing, documentation QA, internationalisation support, regression coverage, review feedback handling.
Markdown reading and document tooling.
- PR #206 — Refreshed contributor guidance to match the current FastAPI, Next.js, and Tauri project structure.
Skills shown: contributor experience, technical documentation, project-structure review, onboarding improvement.
Mzansi Select is a South African e-commerce storefront project focused on creating a clean, trustworthy online shopping experience for curated products.
Skills shown: Shopify, e-commerce, storefront UX, product catalogue planning, QA, release control, customer-facing copy.
V-Property is a property/rental platform project focused on helping users browse, manage, and work with property-related information through a web application.
Skills shown: full-stack development, database-backed apps, product delivery, Git workflow, deployment planning, stakeholder preview readiness.
- Full-stack web application development
- Secure-by-design development
- QA-aware engineering
- Business systems and API integration
- E-commerce and product platforms
- Cybersecurity learning and authorised security research
I also practise authorised security research through bug bounty and vulnerability disclosure programmes.
My current focus areas include:
- OWASP Top 10 awareness
- access-control review
- IDOR/BOLA methodology
- information-disclosure analysis
- scope validation
- low-noise testing
- evidence minimisation
- clear vulnerability reporting
Some reports have been accepted or closed as informational, which I treat as learning evidence rather than confirmed high-impact findings.
Private programme details, report contents, target names, screenshots, request/response data, and reproduction material are not published unless disclosure is explicitly approved.
This profile only includes public, recruiter-safe project summaries. Private client work, security research evidence, credentials, supplier details, and confidential project material are intentionally excluded.
I’m open to software development, full-stack, QA-aware engineering, systems integration, and security-focused development opportunities.
- Email: Fhatuwani.Sikhwari@sikhwarigroup.co.za
- GitHub: github.com/Fhatu12
- LinkedIn: linkedin.com/in/fhatuwani-sikhwari-60013a1a
- Website: sikhwarigroup.co.za
Built by SG Digital | A division of Sikhwari Group (Pty) Ltd