Cybersecurity student based in Sichuan, China.
I turn real problems in AI agents, security research, and developer tooling into verifiable, maintainable software.
📊 At a Glance
📬 Connect
🤖 LLM Toolchain
- Agent Runtime — Build local-first, resumable, and auditable AI agent workbenches with explicit state, policy, approval, tool boundaries, and long-running task recovery.
- Security Engineering — Contribute to real-world vulnerability benchmarks, vulnerability-chain annotation, evaluation tooling, and security dataset quality.
- Developer Tools — Turn recurring failures into reusable tools and ship small, verifiable improvements to open-source projects.
| Programming Languages |
|
| Application Development |
|
| AI Coding Tools |
|
|
A local-first, resumable, and auditable workbench for general-purpose AI agents. Unified model routing, Mission / Run state, SQLite persistence, policy approvals, budgets, event streams, and controlled tool boundaries. 197 commits · Go control plane · CLI / TUI / Web / Windows Desktop |
An evidence-driven Android experiment for detecting and safely undoing unwanted cross-app jumps. Accessibility + UsageStats timelines, deterministic rules, one-shot Back / Home recovery, JSONL evidence export, latency truth, and real-device test matrices. Android 9–16 · Kotlin / Python tooling · MIUI 14 architecture documented as No-Go |
| Area | Project | Selected work |
|---|---|---|
| Agent memory | TencentCloud/TencentDB-Agent-Memory |
Dify / Vercel AI SDK adapters, FTS reliability, capture idempotency, and provenance |
| Vulnerability research | Tencent/VulnGym |
Vulnerability-chain data, evaluator improvements, auditable review, and trace-cleanup tooling |
| Browser tooling | silentmeowing/Search-Translate-Guard-for-GitHub |
12 merged PRs covering input handling, release packaging, and compatibility |
| Student community | pppolf/SCSWiki |
6 merged PRs adding course resources, student guides, and privacy-processed materials |
Selected pull requests
TencentDB-Agent-Memory#469— stabilize recall prompt prefixes with deterministic scene orderingTencentDB-Agent-Memory#473— isolate keyword-query semantics across SQLite and TCVDBTencentDB-Agent-Memory#474— preserve concurrent updates during Persona generationTencentDB-Agent-Memory#476— add idempotent retries for gateway capture requestsVulnGym#11— deliver conservative, auditable code-location repair with reproducible artifactsopen-code-review#512— reorganize coding-agent integrations across five localized READMEs
Build the system. Verify the boundary. Ship the fix.

