Skip to content
View WAHIB-EL-KHADIRI's full-sized avatar
πŸ‘‹
πŸ‘‹

Block or report WAHIB-EL-KHADIRI

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
WAHIB-EL-KHADIRI/README.md

Terminal: whoami -- AI engineer and systems developer from Morocco, building agent infrastructure in Rust

Rust TypeScript Python PHP Docker Β Β·Β  Portfolio dev.to LinkedIn Email

Star AgentOS on GitHub


πŸ’Ό What I build

Correctness in developer tooling, mostly in other people's repositories. Two strands, and the evidence for both is below rather than asserted here:

  • Auto-fixers that corrupt the code they fix. Linters are trusted to rewrite whole repositories unattended. I round-trip a project's own test corpus through its --fix and check the output still parses β€” which found data-loss bugs in a 9.8k-star SQL linter, and found nothing at all in ruff, which is reported just as plainly.
  • Release pipelines that execute their own inputs. ${{ ... }} is substituted as text before the shell parses the line, so a tag name stops being data β€” usually in the one job holding the publishing credentials.

You can run the first one against your own repository right now. No install, about a minute, nothing left behind:

uvx --from "autofix-safety[ruff] @ git+https://github.com/WAHIB-EL-KHADIRI/autofix-safety" autofix-safety-ruff . findings.json

It will almost certainly come back clean β€” that is the common result, and findings.json records the tool version, corpus and flags so a clean run is checkable rather than just reassuring.

Also Rust systems work: AgentOS, a runtime for supervising long-lived agents and replaying their runs offline.

Web and business systems too β€” multi-tenant Postgres, RBAC, offline-first frontends, bilingual FR/AR interfaces with real RTL β€” but those repositories are private, so treat this paragraph as context rather than as evidence.

Based in Morocco, working across EMEA and US-morning hours. Open to product engineering, contract work and consulting.

wahibelkhadiri06@gmail.com Β· LinkedIn

πŸ”’ Work in other people's repositories

15 merged pull requests into 12 repositories I don't own, reviewed and accepted by their maintainers. The through-line is release-pipeline security: ${{ ... }} is pasted into a shell as text before bash parses it, so a tag name or dispatch input stops being data and becomes part of the program β€” almost always in the one job holding the publishing credentials.

Release-pipeline hardening

  • PrefectHQ/prefect β€” βœ… merged: the release ref was expanded into two shell bodies in the jobs that publish to PyPI, one of them holding id-token: write for Trusted Publishing (#22882)
  • thingctx/thingctx β€” βœ… merged: pinned every third-party GitHub Action to a commit SHA across CI and release workflows (#127)
  • dbt-labs/dbt-core β€” the workflow that publishes to GitHub, PyPI and Docker: dispatch inputs expanded unquoted into an echo and into a command substitution (#15994)
  • sqlfluff/sqlfluff β€” βœ… merged: release workflow: the version input reached a command substitution and a step carrying GITHUB_TOKEN (#8375)
  • sktime/pytorch-forecasting β€” PyPI release workflow: tag name expanded into the tag check that gates the build, plus a least-privilege permissions: block the file had never declared (#2385)

Bugs found by tooling I wrote

Found with autofix-safety, a scanner I wrote: two adapters, one invariant, and results recorded so they can be checked rather than believed β€” tool version, corpus commit, command, environment, limitations. The runs that found nothing are recorded the same way (ruff, across 1,607 of its own fixtures and 1,805 CPython stdlib files, clean), and so is the finding that stopped reproducing once upstream fixed it. The issues below are the part you can verify without taking my word for any of it.

A linter's core promise is that fixing valid input leaves valid input. Almost no project tests that across its whole corpus β€” fixtures are tested for parsing, and rules are tested for their fix, but not for the two composed. So I wrote a scanner that asserts it, and pointed it at a 9k-star SQL linter.

I also pointed it at ruff β€” 1,607 fixtures, --select ALL --fix --unsafe-fixes, with CPython's own ast.parse as the judge rather than the tool under test. It found nothing. Reporting that too, because a method that only publishes its hits is a sales pitch.

  • sqlfluff/sqlfluff β€” fix could weld adjacent tokens together, so the file it writes lexes differently from the one it read: in Oracle, two keywords β€” MULTISET EXCEPT β†’ MULTISETEXCEPT β€” fused by LT01. Upstream fixed the arithmetic case I led with (#8395), which made my opening example stale. Closed unmerged, and the reason was reviewability rather than correctness β€” too verbose, and missing a real-world query as the motivating test. Worth recording as written (#8415)
  • sqlfluff/sqlfluff β€” RF06 unquotes both halves of a MySQL/MariaDB 'user'@'host' account specification, which is syntax rather than a quoted identifier. CREATE USER, GRANT, DROP USER and DEFINER = all come back unparsable, on the default rule set (#8462)
  • sqlfluff/sqlfluff β€” lint-result caching for files that came back clean, so a pre-commit run stops re-parsing files nothing touched (#8418)

Correctness, performance and dead code

  • sktime/sktime β€” βœ… merged: removed mutable default arguments (B006) from the ConvTimeNet backbones (#10730)
  • vprusso/toqito β€” βœ… merged: vectorized the depolarizing-channel Kraus-operator construction (dropped the dΒ² nested-loop allocations), verified identical output across dims/parameters (#1921)
  • Tracer-Cloud/opensre β€” βœ… merged: fixed a CLI config-precedence bug so OPENSRE_INTERACTIVE and config.yml are honored when no --interactive flag is given, with a regression test (#4387)
  • RonaldHensbergen/composable-data-stack β€” βœ… merged: removed an unreachable default-credential security branch (dead code / false coverage) with regression tests (#344, #345)
  • vedaant00/opendot β€” βœ… merged: grep no longer crashes on paths outside the workspace; list_files honors the shared ignore set (#73, #61)
  • masumi-network/Citadel β€” βœ… merged: dropped a dead session_trace re-export facade, then covered the notification gateways and logging utils (#130, #131)
  • skodaconnect/myskoda β€” βœ… merged: added the missing SoftwareStatus enum members so updates in progress stop failing to parse (#641)
  • abduznik/instrumation β€” βœ… merged: the duplicate-address scanner no longer breaks on empty or None input (#137)
  • mldsveda/PyScrappy β€” βœ… merged: aligned the GitHub scraper's default result count with the MCP tool (#82)
  • every-app/open-seo β€” a self-hosted container can silently serve a stale client build: the entrypoint fingerprints a hardcoded env list that has to mirror vite.config.ts's envPrefix, and only a comment keeps them in sync (#316)

πŸ›  My own projects

Project Stack
autofix-safety β€” round-trips a linter's own test corpus through its --fix and checks the output still parses. Found data-loss bugs in sqlfluff; found nothing in ruff, and publishes that too. Python Β· pip install from git Β· MIT
CI Release
AgentOS β€” runtime for AI agents: supervised lifecycle, gRPC bus, secrets vault, deterministic trace replay. Rust Β· 10-crate workspace Β· Apache-2.0
CI Release
AI Content OS β€” 8 specialized agents, a visual workflow engine, and a router that picks the right model per task. Python Β· FastAPI + React
CI
TaskFlow Pro β€” task management on a custom MVC; the domain layer stays free of framework and persistence concerns. PHP 8.1 Β· PSR-12 Β· PHPStan level 5
CI

✍️ Writing

🧩 Contribute

AgentOS is open to contributors: issues labelled good first issue and help wanted cover Rust internals, CLI ergonomics and docs. Design questions live in Discussions.


41 pull requests into repositories I don't own β€” 17 merged Β· 11 open Β· 13 closed

313 commits Β· 25 issues Β· 11 stars across 5 projects

Public contributions, counted 2026-10-03 by a daily Action Β· contributor to 28 repos I don't own

Pinned Loading

  1. AgentOS AgentOS Public

    Runtime infrastructure for AI agents β€” lifecycle, supervision, secrets, and deterministic time-travel replay. Built in Rust.

    Rust 6 3

  2. autofix-safety autofix-safety Public

    Round-trip a linter's own test corpus through its --fix mode and check the output still parses. Found data-loss bugs in sqlfluff; found nothing in ruff, and says so.

    Python 1

  3. ai_content_factory ai_content_factory Public

    Multi-agent AI content creation platform β€” 8 specialized agents, visual workflows, FastAPI + React

    Python 3

  4. taskflow-pro taskflow-pro Public

    TaskFlow Pro β€” task & project management system in PHP 8.1, custom MVC with Clean Architecture

    PHP 1