Founder |ZeroLeaks
Sixteen-year-old Spanish builder (@NotLucknite) behind the viral system-prompts-and-models-of-ai-tools repo (135K+ stars) cataloguing internal prompts of Cursor, Claude Code, Devin, v0, and Windsurf. Founder of ZeroLeaks, a prompt-injection and secret-leak scanner for AI agents, and maintainer of better-clawd, a Claude Code fork with OpenAI/OpenRouter support.
Biography
Lucas Valbuena is the visionary founder of ZeroLeaks, a pioneering venture at the nexus of AI security and open-source transparency. At just 16 years old, this Spanish developer has rapidly established himself as a significant figure in the tech community, amassing a substantial following through his incisive work. His journey is defined by a unique blend of deep technical curiosity and a strong ethical stance, leading him to deconstruct and analyze the proprietary inner workings of popular AI coding assistants. This investigative drive culminated in his flagship GitHub project, a massive repository of reverse-engineered system prompts, which serves as a critical transparency resource for developers and researchers worldwide. It is from this foundational work on exposure and analysis that the mission for ZeroLeaks was born. ZeroLeaks emerges as the natural, product-oriented extension of Lucas’s core philosophy. The platform directly addresses the vulnerabilities he meticulously documents, offering tools to test and secure AI applications against prompt injection and data leakage. His technical writings and projects, such as Better-Clawd and Zero Calendar, consistently emphasize building open-source, telemetry-free alternatives to closed systems, championing user agency and security. This principled approach to development—where understanding a system’s flaws is the first step in fortifying it—forms the bedrock of ZeroLeaks’ value proposition. Lucas operates with the conviction that true security and innovation in the AI era require both radical transparency and robust, accessible tools to safeguard it. Looking forward, Lucas Valbuena represents a new archetype of founder: a digital-native investigator turned builder. His work, which also explores cutting-edge intersections like AI-governed blockchain oracles, demonstrates a forward-thinking approach to decentralized systems and automation. Despite his youth, his output reflects a mature focus on impactful, foundational problems in the AI stack. Through ZeroLeaks and his prolific open-source contributions, Lucas is not just building a company; he is actively shaping the practices and ethical standards for a generation of developers navigating an increasingly complex and opaque AI-integrated world. His career narrative is one of leveraging curiosity into expertise, and expertise into tangible solutions for the global developer ecosystem.
Establishes ZeroLeaks, focusing on AI security and vulnerabilities, particularly prompt injection and extraction attacks
Publishes blog content positioning himself as an investigator/reverse-engineer of AI systems, sharing proprietary system prompts and security findings
Builds public profile as a security-conscious builder, testing AI tool vulnerabilities and developing solutions through ZeroLeaks platform
Advances work on AI security tools, focusing on prompt leakage prevention and secure AI application testing methodologies
Continues development of pragmatic open-source developer tools with emphasis on telemetry-free, efficient workflows
A massively popular repository curating and 'leaking' the internal system prompts and model configurations from major AI coding assistants (Cursor, Warp, v0, etc.). It serves as a critical transparency and educational resource for the AI developer community.
An open-source, high-performance alternative to Claude Code, designed with a focus on speed, vendor flexibility, and a commitment to no telemetry or lock-in. It demonstrates full-stack product development in the AI-powered developer tools space.
An 'AI-native' calendar application built with modern web technologies (TypeScript, Next.js). The project explores integrating AI deeply into productivity and scheduling workflows, moving beyond simple chatbot interfaces.
A conceptual project proposing to replace traditional oracle voting mechanisms in blockchain-based prediction markets with 'rule-based AI reasoning.' It explores novel governance, trust, and automation models at the intersection of DeFi and AI.
A body of work, documented through his blog, focused on identifying and mitigating vulnerabilities in LLM applications, particularly prompt injection and extraction attacks. This research underpins the mission of his company, ZeroLeaks, which aims to build tools for testing and securing AI systems.
The advantage of being curious early
Building in public
No telemetry, no lock-in
Research generated April 20, 2026