I ship upstream fixes to .NET, TypeScript, and Apple/container, build benchmark and agent tooling on the side, and write about software security.
Portfolio | Projects | Open Source PRs | Google Scholar | LinkedIn
Six lanes I'm actively contributing in, June 2026 snapshot:
- .NET and data systems — EF Core correctness, migrations, relational behavior.
- Developer tooling — RefactoringMiner (MCP/WebDiff, AST-diff), compiler fixes in TypeScript and
typescript-go. - Local infrastructure — Apple
containernetworking, hostname/DNS, Compose compatibility. - SRE and agent evaluation — SREGym benchmark scenarios, context compilation, patch validation tied to tests.
- Agent runtimes — schema/tooling fixes in LangChain, DeepAgents, and the OpenAI Python SDK.
- Research — software security, LLM agent security, empirical SE (papers below).
69 public authored PRs — 58 outside my own repos, 44 merged.
| Project | What it does |
|---|---|
| ChannelDeck | Native macOS IPTV player for Xtream-style APIs. Multiview, local recording, saved layouts, M3U export. |
| ctxhelm and HelmBench | Local-first context compiler and MCP context broker, plus benchmark work for AI coding agents. |
| PatchSmith | Coding agent for software-maintenance tasks. Sandboxed patch validation, evidence reports per patch. |
| 1brc-csharp | .NET 10 take on the One Billion Row Challenge. |
| Yet-Another-C-Compiler | C/C++ compiler. |
| CSE-306 / CSE-314 | Coursework: 8-bit MIPS pipeline, ALU, FPU; low-level C++ OS work. |
| Project | Lane | Notable PRs |
|---|---|---|
| dotnet/efcore | EF Core correctness, migrations, relational behavior | #38493, #37560, #37415, #37380 |
| SREGym | Kubernetes/SRE benchmark scenarios | #828, #821 |
| tsantalis/RefactoringMiner | MCP server, WebDiff, AST-diff, perf | 15 PRs incl. #1063, #1085, #1101 |
| apple/container, Container-Compose | Apple container networking, DNS, Compose | apple/container#1810, #1811, #1815, Container-Compose#119 |
| microsoft/TypeScript, typescript-go | Compiler behavior, declaration emit, type-system edge cases | TypeScript#62836, #62899, #62931, typescript-go#3314 |
| langchain-ai, openai/openai-python | Agent/tool schema, model API behavior, CLI reliability | langchain#34248, #34201, openai-python#2765 |
Two threads I'm publishing in: AI for software engineering, and software/LLM-agent security.
- An Empirical Study on Remote Code Execution in ML Model Hosting Ecosystems — ~45k repositories across five ML model hosting ecosystems. Submitted to TOSEM 2026.
- The Choice Can Be the Attack: Auditing Aligned Backdoors in LLM Agents — endpoint black-box audit for detecting triggers that change which valid option an LLM agent picks.
Software Engineer at IQVIA (healthcare systems). Incoming M.Sc. in Computing Science at the University of Alberta, starting September 2026 — joining U-A-Goose.
Reach me if you're working on reproducible benchmarks, reviewable patches, runtime evidence, or LLM agent security.
- Portfolio: tanzimhromel.com
- Email: tanzimho@ualberta.ca or romel.rcs@gmail.com




