Prakhar Gupta

Backend & full-stack developer. Second year of CS at Manipal University Jaipur.

NowWriting compute-waste detectors at WeMakeDevs × AWS Environmental Hacks. Fixing bugs in OWASP cve-lite-cli.

About

I build client websites at Schrader, a digital marketing agency in Michigan, and contribute to open source in my spare time: 9 merged PRs at OWASP, 5 at Sugar Labs.

Most of my own projects are civic tools for Delhi. The latest, JanSamadhan, routes complaints to 10 city authorities and won the India Innovates '26 grand finale.

Experience

Schrader, Web Developer

Jul 2026 – Present

Traverse City, Michigan · Remote

  • Joined as a freelancer, now on the team. 57 merged PRs across the agency's client and in-house sites.
  • Rebuilt the agency's own site in Next.js, including a PageSpeed and Lighthouse audit tool used in sales pitches.
  • Built and maintain sites for local businesses, with contact forms backed by Resend and Turso.

Projects

JanSamadhan

2026

Grand Finale winner, India Innovates '26

Civic grievance platform for Delhi, running as a ward pilot. 300+ users, all organic from X, Reddit and campus. Complaints come in through a Gemini chatbot, a web form or WhatsApp and go to one of 10 authorities against an SLA.

The hard part: Catching duplicate complaints within 20 m with PostGIS before they're filed, scoring 250 ward polygons live, and escalating overdue tickets inside Postgres instead of app code.

Compute-waste scanner

2026

WeMakeDevs × AWS Environmental Hacks · in progress

Clones any public repo and reports code, infra, logging and LLM patterns that waste compute, with the exact line as evidence. I wrote 45 of its ~120 detectors and the AWS scan API.

The hard part: Proving waste from static evidence alone, never running the scanned code, and making detectors written in Python and TypeScript by four people pass one shared contract.

Python · TypeScript · AWS Lambda · API Gateway · S3 · Next.js

RailMind

2026

Dispatch decision support for Indian Railways on a simulated 437 km Delhi–Kanpur corridor. Cuts cascade delay by 10% against first-come-first-served dispatch.

The hard part: A beam-search lookahead (depth 4, width 8) that plans train conflicts in under 200 ms, behind a safety layer that rejects any unsafe plan.

oracle-academy

2026

A terminal client for Oracle Academy's Student Hub: sign in once via SSO, then list classes and work through sections from the CLI.

The hard part: Oracle's edge blocks headless Chromium, so it keeps one real browser alive over CDP, imports cookies from your browser (including Chrome's App-Bound Encryption on Windows), and falls back to Docker with noVNC.

Leafline

2026

1st Place, InnovateNSUT '26

Civic issue reporter for Delhi and the prototype that became JanSamadhan. I built the role logic, citizen and authority dashboards, and the chat assistant's backend.

The hard part: Routing free-text and spoken complaints to the right department, using Groq for classification and Google Speech for voice input.

Open source

OWASP / cve-lite-cli

Dependency vulnerability scanner for JS/TS projects · 760 stars

9 merged
  • #1202

    The usage scanner silently stopped at 5,000 files, so --only-used could hide real vulnerabilities. It now flags the cut-off and keeps those findings.

    Before this, a vulnerable repo could scan green.

    +702 −103

  • #1183

    Fixed the semver check that four rules depend on: ^0.25.0 was matching every 0.x release instead of following npm's 0.x rule.

    It was reporting vulnerable versions npm could never install.

    +36 −5

  • #1271

    HTML reports printed fix commands relative to wherever the report was generated. They're now relative to the scanned project, so they actually run.

    +111 −23

Show 6 more
  • #1231

    Compact mode showed three findings without saying more were hidden. It now states how many and how to see them.

    +330 −2

  • #1230

    Replaced 39 hard-coded CLI flag strings with constants, so a typo is a compile error instead of a silently ignored flag.

    +173 −93

  • #1229

    Merged seven copies of the flag-conflict error message into one helper.

    +11 −7

  • #1228

    Added braces to the last 11 single-line if statements in the CLI.

    +33 −11

  • #1181

    Fixed a pluralization bug in OA008 messages and sorted versions numerically instead of alphabetically.

    +20 −2

  • #1200

    Wrote the docs page for the OA010 Vulnerable Floor override rule.

    +115 −3

Sugar Labs / musicblocks-v4

Visual programming for music, used in classrooms · 125 stars

5 merged
  • #850

    Added Duplicate: copies a brick and everything attached below it into a new, independent tower, with undo and redo.

    +408 −11

  • #919

    Clicking empty workspace didn't clear the selection, because a pan layer was swallowing the click. Fixed it and wrote a test that actually catches it.

    The old test clicked the canvas directly, so it passed while the bug was live.

    +274 −22

  • #871

    Dropping a dragged brick left it selected, because the drag ended with a stray click. That click is now ignored.

    +192 −28

Show 2 more
  • #942

    Moved the drag-click guard, copied in three places, into one shared hook after review feedback.

    +131 −23

  • #646

    Nested bricks with thick outlines were drawn too wide. Fixed two width formulas in the SVG path.

    +3 −1

FaceGate / FaceGate-Mac

Face ID app locker for macOS · 560 stars

4 merged
  • #124

    Shipped v1.3.0: the lock window is now reused instead of rebuilt, which fixed camera drops and a memory leak.

    Rapidly locking and unlocking could bypass face authentication.

    +474 −62

  • #140

    Shipped v1.3.1: fixed duplicate Touch ID prompts on multiple monitors, locked apps flashing before the lock screen, and a frozen overlay traced to cleanup running out of order.

    +513 −173

  • #110

    Rapid lock cycles could leave the camera stopped on a black screen. Camera start and stop now run in order on one queue.

    +64 −25

Show 1 more
  • #105

    Added a setting to disable the emergency quit shortcut, so the app can't be killed by hotkey without authenticating.

    +32 −6

Recognition

Education

Manipal University Jaipur

B.Tech, Computer Science & Engineering · SGPA 8.45

2025 – 2029

Mount Litera Zee School

Class XII, CBSE (PCM + Computer Science) · 91%

2024