Skip to content
View marmar9615-cloud's full-sized avatar

Block or report marmar9615-cloud

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
marmar9615-cloud/README.md
MarMar Labs — Build. Verify. Ship. AI products, open source, and security research, alongside a metallic double-M emblem illuminated in violet.

Hey, I'm Marcel.

I run MarMar Labs, an independent software and research lab in Minneapolis, Minnesota. I build AI products, contribute fixes to the open-source tools I use, and do security research through HackerOne.

My work sits where AI agents, developer tools, and real-world reliability meet: making useful software, tracing what breaks, and backing up a fix with evidence.

Website · HackerOne · X · LinkedIn · Email

Building

Project What I'm building
SignAI An iPhone app for scanning, understanding, signing, and tracking agreements. Optional AI review, an agreement vault, and deadline reminders. On the App Store.
stui Streamlit-inspired interfaces that run in the terminal. Python widgets, session state, reruns, tables, and a full-screen data explorer, built on Textual. Install from PyPI.
RetryProof Deterministic retry-fault testing for n8n workflows. Human-approved invariants, AI-proposed repairs, and before/after replay evidence in a controlled lab. Try the lab.
NeverGuess Preflight for AI-assisted code changes: architecture, risks, missing tests, rollout notes, and a better prompt before the agent starts editing.
AgentBridge An experimental action layer for agent-ready apps: typed manifests, permissioned MCP tools, confirmations, and audit logs. TypeScript SDK.
MarSWE-Bench An agentic coding benchmark with original multi-file debugging tasks across five languages, hidden behavioral tests, and a public score/cost leaderboard.

Contributing to

155 merged pull requests across five upstream projects, as of October 9, 2026. These are contributions to other maintainers' repositories, with a few examples below.

Project Merged PRs Selected work
AnythingLLM 76 Stop scheduled jobs after switching to multi-user mode; restore AstraDB document embedding.
RAGFlow 39 Honor exact chat ID/name filters; fix file deletion crashing an entire commit.
Synara 17 Parse skill frontmatter as YAML; reveal macOS app bundles in Finder.
OpenClaw 16 Send pairing approvals from the approved account; respect configured Slack image limits.
OpenHands 7 Encode branch names in provider URLs; correct remote URL port parsing.

Browse my public merged pull requests →

Security research

I research trust boundaries in developer tools, AI agents, APIs, CLIs, and CI/CD systems. My approach combines source review, controlled reproductions, responsible disclosure, and retesting fixes.

My published security record documents $7,000 in rewards, 13 distinct rewarded reports, and 7 retest awards. That is the September 11, 2026 public snapshot; the reward total includes retest awards.

Find me on HackerOne as realmarmarlabs. I share public outcomes and methodology while keeping private reports and program details confidential.

Research & how I work

Frontier AI stress-test audit — a reproducibility-oriented collection of prompts, transcripts, artifacts, and verification notes on reasoning and code generation. An artifact-based audit, with its limitations documented. Read the preprint.

I work across Python, TypeScript/JavaScript, Go, React Native, and developer infrastructure. I use AI coding tools heavily, then check the result against the actual application: reproduce the failure, make the smallest useful fix, and verify the behavior.

If you're building agent tooling, practical AI products, or open-source infrastructure, reach me at founder@marmarlabs.com.

Pinned Loading

  1. agentbridge-protocol agentbridge-protocol Public

    An AI-native action layer that helps apps expose structured, permissioned actions for agents through manifests, MCP tools, confirmations, and audit logs.

    TypeScript 1

  2. stui-terminal stui-terminal Public

    A tiny Streamlit-inspired terminal UI experiment for Python.

    Python 1

  3. frontier-ai-stress-test-audit frontier-ai-stress-test-audit Public

    Artifacts, prompts, transcripts, and verification notes for a reproducibility-oriented audit of frontier AI systems on verifiable reasoning and code generation.

    TeX

  4. RetryProof RetryProof Public

    Deterministic retry-fault testing for consequential n8n workflows, built with GPT-5.6 and Codex for OpenAI Build Week.

    TypeScript

  5. infiniflow/ragflow infiniflow/ragflow Public

    RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superior context layer for LLMs

    Go 92k 10.9k

  6. Mintplex-Labs/anything-llm Mintplex-Labs/anything-llm Public

    Stop renting your intelligence. Own it with AnythingLLM. Everything you need for a powerful local-first agent experience

    JavaScript 66.9k 7.5k