Correctness in developer tooling, mostly in other people's repositories. Two strands, and the evidence for both is below rather than asserted here:
- Auto-fixers that corrupt the code they fix. Linters are trusted to rewrite
whole repositories unattended. I round-trip a project's own test corpus
through its
--fixand check the output still parses β which found data-loss bugs in a 9.8k-star SQL linter, and found nothing at all in ruff, which is reported just as plainly. - Release pipelines that execute their own inputs.
${{ ... }}is substituted as text before the shell parses the line, so a tag name stops being data β usually in the one job holding the publishing credentials.
You can run the first one against your own repository right now. No install, about a minute, nothing left behind:
uvx --from "autofix-safety[ruff] @ git+https://github.com/WAHIB-EL-KHADIRI/autofix-safety" autofix-safety-ruff . findings.jsonIt will almost certainly come back clean β that is the common result, and
findings.json records the tool version, corpus and flags so a clean run is
checkable rather than just reassuring.
Also Rust systems work: AgentOS, a runtime for supervising long-lived agents and replaying their runs offline.
Web and business systems too β multi-tenant Postgres, RBAC, offline-first frontends, bilingual FR/AR interfaces with real RTL β but those repositories are private, so treat this paragraph as context rather than as evidence.
Based in Morocco, working across EMEA and US-morning hours. Open to product engineering, contract work and consulting.
wahibelkhadiri06@gmail.com Β· LinkedIn
15 merged pull requests into 12 repositories I don't own, reviewed and
accepted by their maintainers. The through-line is release-pipeline security:
${{ ... }} is pasted into a shell as text before bash parses it, so a tag name
or dispatch input stops being data and becomes part of the program β almost
always in the one job holding the publishing credentials.
Release-pipeline hardening
- PrefectHQ/prefect β β
merged: the release ref was expanded into two shell bodies in the jobs that publish to PyPI, one of them holding
id-token: writefor Trusted Publishing (#22882) - thingctx/thingctx β β merged: pinned every third-party GitHub Action to a commit SHA across CI and release workflows (#127)
- dbt-labs/dbt-core β the workflow that publishes to GitHub, PyPI and Docker: dispatch inputs expanded unquoted into an
echoand into a command substitution (#15994) - sqlfluff/sqlfluff β β
merged: release workflow: the version input reached a command substitution and a step carrying
GITHUB_TOKEN(#8375) - sktime/pytorch-forecasting β PyPI release workflow: tag name expanded into the tag check that gates the build, plus a least-privilege
permissions:block the file had never declared (#2385)
Bugs found by tooling I wrote
Found with autofix-safety,
a scanner I wrote: two adapters, one invariant, and results recorded so they can
be checked rather than believed β tool version, corpus commit, command,
environment, limitations. The runs that found nothing are recorded
the same way (ruff, across 1,607 of its own fixtures and 1,805 CPython stdlib
files, clean), and so is the finding that stopped reproducing once upstream
fixed it. The issues below are the part you can verify without taking my word
for any of it.
A linter's core promise is that fixing valid input leaves valid input. Almost no project tests that across its whole corpus β fixtures are tested for parsing, and rules are tested for their fix, but not for the two composed. So I wrote a scanner that asserts it, and pointed it at a 9k-star SQL linter.
I also pointed it at ruff β 1,607 fixtures,
--select ALL --fix --unsafe-fixes, with CPython's own ast.parse as the judge
rather than the tool under test. It found nothing. Reporting that too, because
a method that only publishes its hits is a sales pitch.
- sqlfluff/sqlfluff β
fixcould weld adjacent tokens together, so the file it writes lexes differently from the one it read: in Oracle, two keywords βMULTISET EXCEPTβMULTISETEXCEPTβ fused byLT01. Upstream fixed the arithmetic case I led with (#8395), which made my opening example stale. Closed unmerged, and the reason was reviewability rather than correctness β too verbose, and missing a real-world query as the motivating test. Worth recording as written (#8415)
- sqlfluff/sqlfluff β
RF06unquotes both halves of a MySQL/MariaDB'user'@'host'account specification, which is syntax rather than a quoted identifier.CREATE USER,GRANT,DROP USERandDEFINER =all come back unparsable, on the default rule set (#8462) - sqlfluff/sqlfluff β lint-result caching for files that came back clean, so a pre-commit run stops re-parsing files nothing touched (#8418)
Correctness, performance and dead code
- sktime/sktime β β merged: removed mutable default arguments (B006) from the ConvTimeNet backbones (#10730)
- vprusso/toqito β β
merged: vectorized the depolarizing-channel Kraus-operator construction (dropped the
dΒ²nested-loop allocations), verified identical output across dims/parameters (#1921) - Tracer-Cloud/opensre β β
merged: fixed a CLI config-precedence bug so
OPENSRE_INTERACTIVEandconfig.ymlare honored when no--interactiveflag is given, with a regression test (#4387) - RonaldHensbergen/composable-data-stack β β merged: removed an unreachable default-credential security branch (dead code / false coverage) with regression tests (#344, #345)
- vedaant00/opendot β β
merged:
grepno longer crashes on paths outside the workspace;list_fileshonors the shared ignore set (#73, #61) - masumi-network/Citadel β β
merged: dropped a dead
session_tracere-export facade, then covered the notification gateways and logging utils (#130, #131) - skodaconnect/myskoda β β
merged: added the missing
SoftwareStatusenum members so updates in progress stop failing to parse (#641) - abduznik/instrumation β β
merged: the duplicate-address scanner no longer breaks on empty or
Noneinput (#137) - mldsveda/PyScrappy β β merged: aligned the GitHub scraper's default result count with the MCP tool (#82)
- every-app/open-seo β a self-hosted container can silently serve a stale client build: the entrypoint fingerprints a hardcoded env list that has to mirror
vite.config.ts'senvPrefix, and only a comment keeps them in sync (#316)
| Project | Stack |
|---|---|
autofix-safety β round-trips a linter's own test corpus through its --fix and checks the output still parses. Found data-loss bugs in sqlfluff; found nothing in ruff, and publishes that too. |
Python Β· pip install from git Β· MIT |
| AgentOS β runtime for AI agents: supervised lifecycle, gRPC bus, secrets vault, deterministic trace replay. | Rust Β· 10-crate workspace Β· Apache-2.0 |
| AI Content OS β 8 specialized agents, a visual workflow engine, and a router that picks the right model per task. | Python Β· FastAPI + React |
| TaskFlow Pro β task management on a custom MVC; the domain layer stays free of framework and persistence concerns. | PHP 8.1 Β· PSR-12 Β· PHPStan level 5 |
- I Round-Tripped 2,249 Test Fixtures Through sqlfluff's Auto-Fixer. Eight Came Back Unparsable. β the method, including the check that found nothing and the finding that stopped reproducing once upstream fixed it.
- A GitHub Actions tag is a promise, not a fact: pinning by SHA the right way
- I Read 25 Release Pipelines Looking for One Bug. Four Had It. β the twenty-one that were clean are the point.
AgentOS is open to contributors: issues labelled
good first issue
and help wanted
cover Rust internals, CLI ergonomics and docs. Design questions live in
Discussions.
41 pull requests into repositories I don't own β 17 merged Β· 11 open Β· 13 closed
313 commits Β· 25 issues Β· 11 stars across 5 projects
Public contributions, counted 2026-10-03 by a daily Action Β· contributor to 28 repos I don't own



