I’m a security-focused full-stack developer and systems integration specialist based in South Africa.
I build practical web applications, e-commerce platforms, business systems, and secure digital products.
I contribute tested improvements to public software projects, working across unfamiliar codebases, automated testing, documentation, CI and technical review.
My recent contribution work demonstrates the ability to:
- investigate existing architecture and project conventions;
- implement focused fixes without unnecessary scope expansion;
- write regression tests and validation checks;
- work with Python and JavaScript/TypeScript project tooling;
- use Git branches, forks and pull requests safely;
- respond constructively to technical review feedback;
- diagnose edge cases and refine an implementation;
- deliver changes that pass real project CI pipelines.
Only merged upstream contributions are listed here.
| Project | Contribution | Merged PR |
|---|---|---|
| Heliobond | Completed a Stellar Wave Program issue by making 64-character Stellar transaction hashes mobile-friendly while preserving the complete value for copying and Stellar Expert links; added focused regression tests and differential QA against a broken upstream baseline. | #520 |
| Agent Trust | Added a genuine multi-process SQLite concurrency regression for escrow release semantics, proving exactly one contender can release an escrow and that settlement/review side effects occur exactly once under overlapping execution. | #12 |
| Tapflow | Reduced the dashboard’s largest production JavaScript chunk from ~542 kB to ~285 kB (~47%) with measured Vite/Rollup chunking, then added independent Brotli first-load and raw chunk-size regression guards. | #520, #525 |
| Tapflow | Extended multi-architecture Docker CI from build-only validation to runtime smoke testing of the exact relay images, including endpoint checks, persisted configuration, forced-failure cleanup and architecture regression guards. | #565 |
| Stenion | Built current-registry CSV/JSON export end-to-end: persisted-state API semantics, deterministic download output, PostgreSQL-backed integration validation, then registry UI export controls with desktop/mobile QA. | #139, #143 |
| NexusMem | Added true end-to-end MCP stdio regression coverage through the built CLI, validating JSON-RPC channel integrity, local BM25 fallback when embeddings are unavailable, and detection of protocol-breaking stdout contamination. | #9 |
| Plumbline | Added a Go static-analysis rule for missing authored Soroban contractmeta! metadata, deliberately narrowing detection to avoid multi-file false positives and validating the rule against the official Soroban SDK behaviour. |
#27 |
| gettext-tstrings | Added deterministic asyncio concurrency regression coverage proving task-local translation isolation, module-level lazy-string correctness and translation-state restoration across overlapping tasks; mutation testing confirmed the regression detects process-global leakage. | #36 |
These contributions complement my broader experience in software delivery, systems integration, QA and release governance, cybersecurity, telecommunications and technical leadership.
Mzansi Select is a South African e-commerce storefront project focused on creating a clean, trustworthy online shopping experience for curated products.
Skills shown: Shopify, e-commerce, storefront UX, product catalogue planning, QA, release control, customer-facing copy.
V-Property is a property/rental platform project focused on helping users browse, manage, and work with property-related information through a web application.
Skills shown: full-stack development, database-backed apps, product delivery, Git workflow, deployment planning, stakeholder preview readiness.
- Full-stack web application development
- Secure-by-design development
- QA-aware engineering
- Business systems and API integration
- E-commerce and product platforms
- Cybersecurity learning and authorised security research
I also practise authorised security research through bug bounty and vulnerability disclosure programmes.
My current focus areas include:
- OWASP Top 10 awareness
- access-control review
- IDOR/BOLA methodology
- information-disclosure analysis
- scope validation
- low-noise testing
- evidence minimisation
- clear vulnerability reporting
Some reports have been accepted or closed as informational, which I treat as learning evidence rather than confirmed high-impact findings.
Private programme details, report contents, target names, screenshots, request/response data, and reproduction material are not published unless disclosure is explicitly approved.
This profile only includes public, recruiter-safe project summaries. Private client work, security research evidence, credentials, supplier details, and confidential project material are intentionally excluded.
I’m open to software development, full-stack, QA-aware engineering, systems integration, and security-focused development opportunities.
- Email: Fhatuwani.Sikhwari@sikhwarigroup.co.za
- GitHub: github.com/Fhatu12
- LinkedIn: linkedin.com/in/fhatuwani-sikhwari-60013a1a
- Website: sikhwarigroup.co.za
Built by SG Digital | A division of Sikhwari Group (Pty) Ltd

