Skip to content

Portfolio — 2026

I build production web systems with AI in the loop — and the test suites, release gates and live domains to prove they work.

Full-stack developer and CS student in Malaysia. I run agent-assisted workflows across Next.js, Cloudflare and Prisma, then hold the line on what ships: architecture, code review, tests, debugging and deployment are mine.

featured builds
6
verified test cases
150+
live production domain
1
unverified claims
0
01

Selected work

Six builds with verifiable engineering behind them — live domains, git history, test suites and runtime logs. Each card carries the evidence, not adjectives.

GS-01Production business platform · 2026

Gerbang Studio

The storefront and back office of my SSM-registered web studio — a hardened enquiry pipeline, leads CRM, demo manager and Telegram/Sheets automation on one domain.

My part — Solo build: product, copy, design system, schema, admin UI, tests, deployment and the custom-domain migration.

  • Next.js 16
  • React 19
  • TypeScript
  • Prisma 6 + PostgreSQL
  • Tailwind CSS 4
  • shadcn/ui
  • Bun

live — gerbangstudio.com.my — fetched and verified 2026-09-30

commits
22
release gate
39/39 tests
migrations
5 additive
scale
~27.8k LOC
Visit gerbangstudio.com.my
SR-02AI product (MVP) · 2026

SiteReport MY

Turns rough Malay/English field notes into structured internship logbooks and site-work reports — with an anti-hallucination contract encoded in the AI's output schema.

My part — Product spec, two-stage AI pipeline, Cloudflare Worker API, Sheets/Drive persistence with per-user isolation, and the 17-script validation suite.

  • React 19 + Vite
  • TypeScript
  • Cloudflare Workers
  • Groq · gpt-oss-120b
  • Google Apps Script
  • Firebase Auth

mvp — complete and validated locally via wrangler dev — deploy pending

test scripts
17
scale
~21k LOC
ai models
2 + fallback
storage
Sheets/Drive
ELV-03Internal control platform · 2026

ELV Control Hub

Simulation-first control platform for barrier gates, turnstiles, readers and CCTV — physical actuation stays behind a six-condition safety gate, and the UI can never fake success.

My part — Monorepo architecture, Fastify gateway, vendor-neutral access rules engine, device state machines, credential crypto, RBAC and the test suite.

  • Next.js 16
  • Fastify 5
  • npm workspaces
  • Prisma 6 + MySQL
  • JWT + RBAC
  • Vitest

verified — 94 test cases · in daily local use (runtime logs 2026-09-28)

workspaces
6
test cases
94
db models
17
scale
~16k LOC
KJ-04Desktop application · 2026

Project Koenji

A Tauri 2 command center that catalogs my projects and safely launches, supervises and stops their dev servers — every spawn is inventory-bound and injection-proof.

My part — Architecture, Express runner, integrity validator, Rust shell glue, Node SEA single-executable packaging, session test harnesses.

  • Tauri 2 (Rust)
  • React 19 + Vite
  • Express 5
  • three.js
  • Node SEA

verified — conventional commits + 12 session test harnesses

scale
~28k LOC
test harnesses
12
api routes
~45
fix commits
interleaved
PB-05Full-stack toy · 2026

Painted Burger V2

A gouache-style burger builder with a community layer — 27 ingredients, undo/redo, share links, comments, likes and a moderated hall of fame on Postgres.

My part — Full stack: builder UI and state, community API, Neon Postgres schema, soft moderation, a11y (keyboard drag, reduced motion).

  • Next.js 16
  • React 19
  • Prisma 6 + Neon
  • Zustand
  • Web Audio API

live — V1 at painted-burger-web.vercel.app

scale
~15.6k LOC
api routes
6
db models
3
extras
Web Share API
Open Painted Burger V1
GM-06Game development · 2026

HTML5 Arcade Games

Hand-built canvas games: a vanilla-JS merge-physics toy and a Y8 portal trio with the official ad SDK integrated — interstitial cadence, leaderboards, regression-tested fix builds.

My part — Game loops with fixed-dt clamping, 3-pass collision relaxation, procedural WebAudio, Y8 SDK wrappers, multi-build release debugging (RC2→RC6).

  • Vanilla JS
  • Canvas 2D
  • Web Audio
  • Y8 SDK v2

verified — SLIME-MERGE 3.7k LOC · dedicated Y8 regression test scripts

games
4
largest
11.6k LOC
ads sdk
Y8 minimal v2
builds
RC2→RC6

Also built

  • Kad Kahwin Studio

    Digital wedding-invitation builder: 18 canvas themes with batik/songket motifs, PDF/ZIP delivery, guest pages with countdown, ICS and Waze links — 21 unit tests plus 162 browser QA checks.

    Next.js 16 · Prisma/SQLite · jsPDF

  • Kaki Cetak

    Print-studio storefront demo with an order book: optimistic concurrency, transactional outbox + webhooks, DB-backed rate limiting, timing-safe staff auth.

    Next.js 16 · Prisma/PostgreSQL · svix

  • SME package line

    Three fixed-scope client-site tiers (RM499 / RM999 / RM1,499). The automation tier adds a zod-validated lead API, vitest suites and the client's own Google Sheet as a CRM via Apps Script.

    Next.js 16 · zod · Vitest · Apps Script

  • LeadPilot

    Lead-capture SaaS: Auth.js v5 credentials auth, custom per-IP rate limiting, timing-equalized login, DB health probe, three vitest suites.

    Next.js 16 · Auth.js v5 · Prisma

  • Roblox UGC pipeline

    Scripted Blender → Roblox accessory builds: Python construction scripts, fit previews on three body rigs, geometry validation JSONs and Studio import guides.

    Python · Blender · Roblox UGC

  • SME Website Factory

    Config-driven website engine (clone → edit one config → deploy) with a Cloudflare Worker lead endpoint: Turnstile, honeypot, timing checks, rate limiting — unit-tested with node:test.

    Vite · React 19 · CF Workers

02

Featured case studies

Three projects, opened up: the problem, the architecture, the decisions — and where AI helped and where I took over.

01

Gerbang Studio

A real studio's storefront, CRM and release process on one domain

Problem

My web studio needed more than a brochure: enquiries had to become a tracked pipeline I can act on, without paying monthly for someone else's CRM.

Approach

A one-page sales surface backed by a real back office. PostgreSQL via Prisma holds leads, notes, settings and an audit log. The public enquiry endpoint is a hardened pipeline — same-origin check, Turnstile siteverify, honeypot plus a 2.5-second time-trap, sliding-window rate limit and a payload cap. Admin auth uses scrypt hashing and HMAC-hashed session tokens, with login throttling.

My contribution

Everything: positioning and copy, the design system, the Prisma schema and five additive migrations, all API routes, the admin UI (leads CRM, package and availability managers, demo manager with secure image uploads), unit tests, the Netlify deployment and the custom-domain migration.

How AI was used

Built across agent sessions logged in a 54-entry worklog: each task starts with constraints up front — a frozen design system and a file-ownership table in AGENTS.md — then the agent implements, and I review diffs, run lint, typecheck and the unit suite, and probe live endpoints before any release. A scheduled reviewer agent audited my own passes.

Technical decisions

  1. Demo cover images are stored in Postgres with magic-byte MIME sniffing and a monotonic version counter — one moving part fewer than object storage, and immutable cache URLs that a deletion can never resurrect.

  2. Fail-open vs fail-closed is explicit: the public demo gallery survives a database outage; purchase-critical availability does not lie.

  3. Netlify with a custom domain — including a documented workaround for the OpenNext adapter shadowing netlify.toml redirects.

Debugging

Named fix passes are in the history: a package-select overflow on mobile, a Bing meta-description issue, and the redirect-precedence bug that required reading adapter behavior rather than guessing.

Testing

Twelve unit suites (~150 cases) cover the Turnstile fail-closed matrix, CSV formula-injection safety, admin auth and demo cover handling. The release gate records lint/typecheck/build PASS, 39/39 tests and a live 401/403 probe matrix before deploy.

Result

Live since September 2026 at gerbangstudio.com.my. Enquiries land in the CRM with Telegram notifications, and the lead engine is documented for reuse in client deliverables.

role
Solo developer & owner
timeline
Sep 13–29, 2026 · 22 commits
platform
Netlify + custom domain
status
Live — verified 2026-09-30
Visit the live site
02

SiteReport MY

An AI report writer that is architecturally forbidden from inventing facts

Problem

Interns and field technicians in Malaysia write messy site notes and need professional documents, not another blank template. The catch: LLMs invent details, and an invented work record is worthless — or worse.

Approach

A two-stage pipeline. Stage 1 extracts raw notes into a strict JSON schema — activities, materials, equipment, results, and an explicit unknowns list. Stage 2 writes the report from those facts only, and the anti-invention rules live inside the schema's field descriptions, so the constraint travels with every request. React SPA talks to a Cloudflare Worker; the Worker verifies Firebase tokens against Google's JWKS server-side and calls Google Apps Script (shared-secret auth) to persist to Sheets and Drive with per-user owner_id isolation.

My contribution

The product spec and its hallucination contract, both AI stages and the provider factory (Groq gpt-oss-120b with Gemini as a drop-in fallback), the Worker API, the Sheets schema with in-place migration and LockService, a client-side image optimizer, and the whole validation suite.

How AI was used

Design came from 38 generated screen mockups that were then frozen in a design handoff doc — AI explored, I chose and locked. Feature work followed numbered suites: each capability (auth isolation, autosave, photo security, history scale) shipped with its own deterministic test script before being called done.

Technical decisions

  1. Groq behind a provider factory — a second model is a config change, not a rewrite; a live smoke test asserts zero Gemini calls on the primary path.

  2. Google Sheets as the database: RM0 cost, auditable by non-engineers, with additive migrations, document locks and caching — an honest trade for an MVP.

  3. Photos are optimized client-side (1600px cap, quality 0.85) before they ever reach Drive.

Debugging

Auth isolation and photo security each have dedicated suites — a mocked multi-user store proves one account can never read another's records, and the real image optimizer runs against a mock Drive backend. A latency benchmark measures the live Sheets backend's list operations at scale.

Testing

Seventeen test scripts in three tiers: deterministic suites with dependency-injected mocks, live HTTP tests against wrangler dev, and live external validation (real Groq semantic checks, real latency benchmarking). Report-schema tests assert ACCEPT/REJECT on hallucination boundary cases.

Result

A complete, validated MVP that drafts real reports locally. Cloudflare deployment is the next step — the worker is already configured for wrangler deploy.

role
Solo developer
scale
~21k LOC + 17 test scripts
platform
Cloudflare Workers + Google Apps Script
status
MVP complete — deploy pending
03

ELV Control Hub

A control platform for physical devices that refuses to fake a single action

Problem

Access-control work — barrier gates, turnstiles, card readers, CCTV — needs a way to rehearse operations before touching real hardware, and software that can never claim a physical action succeeded when it didn't.

Approach

A simulation-first monorepo: a Next.js dashboard, a Fastify gateway, and four packages for shared domain logic, zod validation, device adapters and Prisma/MySQL persistence. Every command flows through capability checks, a simulation/physical branch, a pure six-condition safety gate, a PENDING record, adapter execution under timeout, adapter-confirmed result, audit and SSE broadcast. Every refusal is machine-readable and audited.

My contribution

All of it: the architecture, the vendor-neutral access rules engine with overnight time windows, the device state machines (barrier, turnstile, camera, NVR, reader), AES-256-GCM credential encryption, RBAC across four roles, the device simulator, and 94 test cases.

How AI was used

The project runs on a ten-rule AGENTS.md contract for agents — simulation first, no invented vendor APIs, physical actuation disabled by default, tests before success claims. Source comments cite spec sections; the agents worked from the spec, and I verified behavior against it.

Technical decisions

  1. No vendor API is invented: undocumented adapters refuse every action except connection tests, and return a list of the official docs required to implement more.

  2. Success is only reported after the adapter confirms it — the UI can never render a lie, and timeouts map to an explicit TIMEOUT state.

  3. MemoryStore by default with Prisma as an opt-in — the entire platform runs with zero setup, and the store contract keeps both honest.

Debugging

The safety-gate refusal matrix, the audit-log secret-leak scan and the visitor auto-check-in flow each began as failures found by their own test suites — the suites exist because the behaviors mattered, not the other way round.

Testing

94 hermetic test cases across nine files — adapter state machines, the safety gate matrix, RBAC, audit sanitization, visitor lifecycle — all via Fastify app.inject with no hardware or database required.

Result

A complete v0.1 platform in daily local use — runtime logs show sessions across all 18 dashboard pages. Real hardware adapters are the documented next step, gated behind the same safety rules.

role
Solo developer
scale
6 workspaces · ~16k LOC · 94 tests
platform
Local desktop (Windows launchers)
status
v0.1 — pre-hardware by design
03

How I build with AI

AI is my daily working instrument — agent sessions log every task, and the guardrails are written down before generation starts. What follows is the loop, as it actually ran on the projects above.

  1. Requirement

    Write the constraint before the code: spec files, frozen design systems, AGENTS.md rule sets. gerbang-studio's is addressed to future agents by name.

  2. Break it down

    Big asks become numbered task entries with owners and acceptance checks — 54 logged entries on gerbang-studio alone.

  3. Prompt with context

    Agents get the architecture, the guardrails and the exact files they may touch — not a vibe and a prayer.

  4. Inspect the code

    I read the diff before it lands. Generated code is reviewed like a pull request, not trusted like an oracle.

  5. Run it

    Dev server up, real data shapes, real browser. ELV Control Hub's runtime logs show every page exercised before it counted as done.

  6. Test expected behaviour

    Unit suites and browser matrices: 94 cases on ELV, 39/39 on the gerbang release gate, 162 browser checks on Kad Kahwin.

  7. Inspect logs & errors

    Probe matrices, latency benchmarks, audit trails. SiteReport's benchmark script timed real Sheets calls; ELV's audit log records every refusal.

  8. Debug

    Fixes are named and logged: a terminal viewport repair in Koenji, mobile overflow in gerbang, a redirect-precedence bug on Netlify.

  9. Regression-test

    Every fix gets a test that would have caught it — the Y8 ad-fix builds each carry their own regression scripts.

  10. Commit & deploy

    Conventional commits, release gates, deploy — then I verify the live domain myself. gerbangstudio.com.my was fetched and checked the day this portfolio shipped.

Tests before done

Nothing is finished because the AI said so. Featured builds carry 150+ verified test cases between them.

Evidence over claims

Every fact on this site traces to source files, git history, worklogs or a live domain. If it can't be verified, it isn't written.

Guardrails in the prompt

AGENTS.md contracts, frozen design systems, file-ownership tables — constraints first, generation second.

04

Technical experience

Grouped, not graded. Everything listed below appears in real project source code, configs or deployments — no percentages, no logo walls.

Frontend

  • Next.js 16 (App Router)
  • React 19
  • TypeScript (strict)
  • Tailwind CSS 4
  • shadcn/ui + Radix
  • Vite 8
  • Zustand
  • TanStack Query/Table
  • three.js (UI-level)

Backend

  • Node.js (20/24)
  • Express 5
  • Fastify 5
  • Next.js route handlers (REST)
  • SSE
  • Auth.js v5 / JWT
  • Firebase Auth (JWKS)
  • Zod

Data

  • Prisma 6
  • PostgreSQL (incl. Neon)
  • MySQL 8
  • SQLite
  • Google Sheets-as-DB
  • Google Drive storage

Cloud & deployment

  • Netlify (live, custom domain)
  • Vercel
  • Cloudflare Workers + wrangler
  • Google Apps Script
  • Caddy
  • Bun

Testing & tools

  • Vitest
  • node:test
  • Playwright (PDF & visual QA)
  • ESLint 9
  • sharp (asset pipelines)
  • Git — conventional commits
  • release-gate checklists

AI development tooling

  • ZCode (main orchestrator)
  • OpenCode
  • Google Stitch (design)
  • MCP servers (Blender, Roblox Studio)
  • structured LLM output (Groq/Gemini)
  • AGENTS.md governance
05

Development journey

Progression with dates taken from git history, migration timestamps and runtime logs — the recent, dense stretch of a fast-moving year.

  1. Mid-2026

    Agent-era foundations

    First agent workflow sessions on record — an opencode log titled “Building Echoes Below vertical slice” (June), an MCP server implemented from scratch with Node built-ins, and Blender/Roblox agent bridges.

  2. Aug 2026

    First end-to-end SaaS

    LeadPilot: Auth.js v5, Prisma migrations, custom per-IP rate limiting, vitest suites — its Prisma migration is dated 2026-08-23.

  3. Sep 1–3

    Project Koenji, sessions 1–4

    Cinematic desktop shell, safe process launcher, inventory-bound integrity validation, media showcase — conventional commits with fix commits interleaved between features.

  4. Sep 13

    The studio product line

    Three SME site tiers (RM499/RM999/RM1,499) built back-to-back, the SLIME-MERGE canvas game, and the first gerbang-studio commit.

  5. Sep 13–29

    Gerbang Studio to production

    Twenty-two commits from first scaffold to live custom domain: admin CRM, demo manager, security hardening, release gate 39/39, redirect-precedence fix, SEO passes.

  6. Sep 27–28

    ELV Control Hub v0.1

    A six-workspace control platform with 94 tests, built in two days on top of a written agent contract — and actually used, per its own runtime logs.

  7. Ongoing

    Computer Science at UiTM

    Degree in progress with Cisco networking coursework (CCNA modules) and a final-year project; SiteReport MY deployment and further Y8 submissions queued next.

06

About

I'm a Computer Science student in Malaysia who spends most of his time building actual products: a web studio with a live domain, an AI report writer with a hallucination contract, a device-control platform with a physical safety gate, desktop tooling, and arcade games.

I work with AI agents daily, and I'm comfortable saying exactly what that means: agents draft, I decide. Architecture, review, tests, debugging and deployment stay with me — that's where the interesting problems live, and it's the part I'd bring to a junior developer team on day one.

07

Contact

If you're hiring for junior developer or AI-assisted development roles — or want to talk about building something — my inbox and GitHub are open.

Open to junior developer and AI-assisted development roles in Malaysia.