Skip to content
View canblmz1's full-sized avatar

Highlights

  • Pro

Block or report canblmz1

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
canblmz1/README.md

Can Bilmez

Backend systems, developer tooling, and fail-closed execution safety

Reliability · Testing · Open Source · Execution Integrity

I work on systems where “valid-looking” is not the same as “safe to execute.”

TypeScriptNode.jsPythonFastAPIPostgreSQLGitHub Actions


Open-source impact

ProjectWorkOutcome
Atomic AgentClosed malformed / ambiguously terminated native tool-call execution paths across native OpenAI-compatible and Qwen-tagged flowsMerged upstream in PR #144 as dcf77f1 after maintainer re-probes
Vercel AI SDKReported unsafe automatic tool execution after length, error, content-filter, and other terminal statesReproduced across v5, v6, v7; fixes/backports merged on all three lines; co-author credit on the resulting fix commits; v7 shipped in ai@7.0.70
TugtainerImplemented configurable container update / rollback lifecycle hooks across backend, executor, persistence, UI, docs, and testsMerged upstream in PR #217
Roo Code / RoomoteResponsibly reported an environment-configuration exposure issuePublicly acknowledged in the v0.39.1 release notes

Atomic Agent — fail closed at the real dispatch boundary

AtomicBot-ai/atomic-agent#144 prevents truncated or malformed native tool-call arguments from silently becoming executable input.

The final patch covers:

  • malformed non-empty function.arguments → parse failure, never silent {} fallback;
  • bare EOF with pending tool calls → fail closed unless a real terminal signal was observed;
  • Qwen tagged calls → same termination-safety decision as native calls;
  • final SSE events without a trailing blank line → flushed and parsed correctly at EOF;
  • parallel tool calls and stream-read failures → zero dispatch;
  • zero-argument calls and clean provider termination → preserved.

The maintainer re-ran the original probes plus additional EOF/UTF-8/abort cases before merging the patch to main.

Vercel AI SDK — report → reproduce → fix → backport → release

#19063 report#19066 v7#19120 v6#19121 v5ai@7.0.70

A tool call should not execute just because its arguments parse. The terminal model state is part of the execution contract.

Verified contribution ledger →


Shipped

Fail-closed execution integrity for streamed LLM tool calls.

0.4.2 is published on npm with provider terminal-state handling, incremental argument evidence, schema validation, identity correlation, one-shot execution decisions, and AI SDK execution guards.

npm install prefix-safe-json@0.4.2

The release path is independently auditable: the published npm tarball is reproducible byte-for-byte from the tagged source, SLSA provenance is verified against the exact package/version bundle npm authenticated, and the verifier fails closed when release identity cannot be established.

AI SDK v5/v6/v7 · streaming JSON · tool calling · schema validation · reproducible release · fail closed


Featured projects

Executable compliance testing for AI coding instructions. Turns CLAUDE.md, AGENTS.md, Cursor rules, and similar repository instructions into sandboxed scenarios with scored reports, CI integration, SARIF output, provider comparison, and regression-oriented evidence.

AI agents · developer tooling · sandbox testing · CI · SARIF

PR-scoped mutation testing for JavaScript / TypeScript. Uses StrykerJS to focus mutation testing on changed lines and turn surviving mutants into actionable review signals instead of broad, expensive mutation runs.

mutation testing · StrykerJS · TypeScript · GitHub Actions · CI quality gates


Current upstream work

  • Node.jsnodejs/node#64954: recursive readdir with Buffer encoding across callback, sync, promises, and withFileTypes paths.
  • Trendyol BaklavaTrendyol/baklava#1220: fix a resize-listener reference leak in bl-pagination and prove cleanup with a regression test.
  • Vercel AI SDK docsvercel/ai#18770: distinguish truncation from malformed JSON before jsonrepair in the cookbook flow.
  • Sandbase Harnesssandbaseai/sandbase-harness#73: open prefix-safe-json@0.4.2 integration pilot for confirmation-required tool execution; not an adoption claim unless merged.

Engineering style

  • Reproduce against current upstream before proposing a fix.
  • Prefer regression tests that fail on the old behavior.
  • Test the real execution boundary when side effects are involved.
  • Compare patch failures against a clean baseline before calling them regressions.
  • Keep security and reliability claims scoped to what the evidence proves.
  • Fail closed where ambiguous state can trigger an irreversible action.

Current focus

Backend systems · AI agent/tool execution safety · developer infrastructure · testing systems · OSS reliability

looks valid ───────────────► safe to execute
not the same thing

Popular repositories Loading

  1. ruleProb ruleProbPublic

    Test whether your CLAUDE.md, AGENTS.md and .cursor/rules actually survive AI agent execution. Extract rules, generate sandbox scenarios, score compliance.

    TypeScript 7

  2. tautest tautestPublic

    TypeScript 6

  3. promptfix promptfixPublic

    Python 2

  4. dbsnap dbsnapPublic

    TypeScript 2

  5. Project-Prompt-Generator Project-Prompt-GeneratorPublic

    Python 1

  6. canblmz1 canblmz1Public

    Config files for my GitHub profile.