Skip to content
View chief-builder's full-sized avatar

Block or report chief-builder

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
chief-builder/README.md

Murali Kurukunda

Engineering executive who still builds. By day I lead enterprise platform teams that run API, foundation-model, and MCP gateways at large scale, connecting agents to enterprise systems. On my own time I build and measure the pieces that make agents safe to run with real data and real permissions.

What I work on here:

  • Agent identity and permissions. Agents that act as the signed-in person, with scoped, auditable access and no shared tokens.
  • Evidence over opinion. Controlled, repeatable experiments on agentic harnesses, not demo videos.
  • Governance you can run. Validators, registries, and rollout gates that let an enterprise say yes to agents safely.
  • Modernization with agents. Agent teams that map, test, and migrate legacy codebases, built on lessons from leading large migrations. See modernization-agent.

Featured

Repo What it shows
mcp-healthcare-reference A lab for an enterprise MCP platform: multi-IdP identity hub, a three-tier Kong gateway, certificate-bound machine identity, stateless MCP servers over synthetic FHIR, and a vault-backed token broker for SaaS egress.
vendor-token-broker An MCP gateway that lets Claude Code and other assistants use GitHub, Linear, Jira, and Cloudflare as each signed-in person, with no one handling tokens and read-only tools by default.
cli-vs-mcp Claude Code across baseline, CLI-skill, and MCP tool surfaces with paired seeds and N=5 trials. MCP completed every task within its tool surface; the CLI-skill arm used 1.5–2.7× the tokens.
local-vs-remote-mcp Local stdio vs. remote streamable-HTTP MCP: token cost, latency, and prompt-injection exposure, with transport isolated from server implementation.
mcp_tool_description_validator 57 rules for MCP tool definitions covering LLM compatibility, security, and spec compliance. CLI, HTTP service, and SARIF output for CI.
codex_rollout_healthcare An executive rollout plan for a governed AI coding platform in regulated healthcare: gateway policy, identity claims, metering, chargeback, and explicit rollout gates.

More

Elsewhere

  • NYSE panel on enterprise AI connectivity, with Kong, McKinsey, and Mistral AI
  • Earlier talks: InfoQ (real-time CQRS cache for banking), Dashcon 2018 (serverless statements engine), Rackspace Solve
  • LinkedIn

Code and opinions here are my own and don't represent my employer.

Pinned Loading

  1. cli-vs-mcp cli-vs-mcp Public

    Harness comparing Claude Code performance across CLI skill, MCP server, and baseline tool surfaces. Playwright and GitHub experiments with N=5 runs.

    TypeScript 2

  2. codex_rollout_healthcare codex_rollout_healthcare Public

    Rollout plan for a governed AI coding platform in regulated healthcare: gateway policy, identity claims, metering, chargeback, and explicit rollout gates.

    HTML

  3. local-vs-remote-mcp local-vs-remote-mcp Public

    Research harness comparing MCP over local stdio vs remote streamable HTTP: token cost, latency, and prompt-injection security across transports (GitHub + Playwright experiments).

    TypeScript

  4. mcp-healthcare-reference mcp-healthcare-reference Public

    Enterprise MCP platform lab: multi-IdP identity hub, three-tier Kong gateway, certificate-bound machine identity, and a vault-backed token broker over synthetic FHIR.

    Python

  5. mcp_tool_description_validator mcp_tool_description_validator Public

    Governance validator for MCP tool definitions: 57 rules for LLM compatibility, security, and spec compliance, with CLI, HTTP service, and SARIF output for CI.

    TypeScript

  6. vendor-token-broker vendor-token-broker Public

    MCP gateway that lets Claude Code and other assistants use GitHub, Linear, Jira, and Cloudflare as each signed-in person, with no token handling and read-only tools by default.

    Python