I build deterministic developer tools, local-first engineering workflows, and carefully scoped computational research prototypes.
I am a Computer Programming student at Ondokuz Mayıs University in Samsun, Türkiye.
My public work focuses on developer tooling, web security, automation, AI-assisted engineering, and computational biology. I care about explicit scope, deterministic behavior, useful tests, readable documentation, and claims that stay within the available evidence.
AI is part of my workflow, but not an autopilot. I remain responsible for project direction, technical decisions, validation, documentation, and releases.
- Developer tooling: rule-based security checks, CLI ergonomics, SARIF, and CI integration.
- AI-assisted engineering: local-first supervision, isolated worktrees, verification gates, recovery controls, and portable evidence.
- Computational research: reproducible protein-structure preparation and geometry-based pocket analysis with explicit scientific boundaries.
- Product work: focused web applications that are small enough to ship, test, and maintain.
Deterministic security checks for Next.js projects before review or deployment. The CLI reports practical signals around secrets, routes, configuration, XSS, raw SQL, command execution, authentication, uploads, and rate limiting without using AI at runtime.
Current state: v0.3.0 line · 20 deterministic rules · 429 passing tests · terminal, JSON, Markdown, GitHub, and SARIF reports.
A local-first supervision and evidence layer for Codex. CEWP adds explicit scope, isolated worktrees, bounded retries, deterministic verification, independent review, recovery controls, and portable receipts while leaving code generation to Codex.
Current state: v0.14.0-beta.1 source line · npm beta CLI · local Codex plugin and MCP bridge · supervised checkpoints, Coordinator Mode, and a versioned workflow runtime.
A local computational research prototype for preparing protein structures, detecting geometry-based pocket candidates, and inspecting versioned heuristic measurements through a FastAPI and React application.
Current state: source-only v0.1.0 release · canonical static detector · quality-gated experimental NMA layer · bounded Mol* viewer integration.
BioVoid is not a clinical, diagnostic, validated binding-prediction, or drug-development system. Its outputs require independent scientific review.
A security-aware Python ZIP inspection and safe-extraction toolkit. Archives are inspected before extraction with deterministic risk signals, dry-run support, integrity checks, and explicit safety gates.
Current state: v0.3.0 public alpha · CLI and optional PyQt6 GUI · install from a local checkout · not yet published on PyPI.
A Japanese-learning MVP for Turkish-speaking beginners, with kana practice, local SM-2 review, structured lessons, quizzes, XP and streak tracking, mini stories, kana drawing, and N5-style practice.
Current state: pre-Phase 4 stabilization · usable local MVP · optional Supabase authentication and sync · local mode works without Supabase.
My bilingual personal portfolio for presenting public projects, technical direction, learning progress, writing, and contact links.
- Prefer small, testable releases over vague feature piles.
- Keep security tooling deterministic and make uncertainty or false-positive behavior visible.
- Treat AI-assisted development as supervised engineering with reviewable evidence.
- Separate working prototypes from validated scientific or production claims.
- Keep public documentation useful, bounded, and honest about unfinished work.
Actively using: Python, TypeScript, JavaScript, Node.js, Next.js/React, FastAPI, Git/GitHub, SQLite, GitHub Actions, npm, and Docker.
Currently strengthening: SQL, algorithms and data structures, debugging, testing, code reading, documentation, and software architecture.



