Skip to content
View HaroonTaufiq's full-sized avatar
😎
Messing with the code
😎
Messing with the code

Block or report HaroonTaufiq

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
HaroonTaufiq/README.md

Hi there! I'm Haroon Taufiq — Full-stack Engineer building with Agentic AI

Full-stack engineer building product-grade TypeScript applications and agentic AI systems.
Most of my recent work sits where those meet — LLMs as orchestrators over real, deterministic backends.


🔭 Currently Building

  • Agentic systems with LangGraph and the Vercel AI SDK — typed tools over deterministic backends
  • Full-stack products on Next.js, tRPC and Drizzle over Postgres / Supabase

🌱 Currently Learning

  • Agent orchestration patterns — MCP, A2A and the OpenAI Agents SDK
  • Running agent workloads on Dapr and Kubernetes

🚀 Selected Work

Next.js · TypeScript · Supabase · AI SDK

A multi-user AI finance companion. The model routes to typed tools rather than reading transactions directly, and heavy analytics are precomputed at ingest.

Decision — raw rows never enter model context. Cost and latency stay flat as a user's history grows, instead of scaling with it.

Python · FastAPI · LangGraph · Supabase

Autonomous P2P and affiliate oversight — a LangGraph agent swarm reporting into a Control Room dashboard.

Decision — findings stream over WebSockets rather than polling, so operators watch checks land as they complete.

React · Node.js · PostgreSQL

An auth and authorization reference build: JWT access with refresh rotation over HTTP-only cookies, OAuth2.0 through Google, GitHub and Keycloak, and role-based access control.

Decision — mTLS for service-to-service identity alongside tokens for users — certificates authenticate machines, tokens authenticate people.

Express · React · Vite · TanStack Query

A counselor action-center built as an npm-workspaces monorepo over a shared TypeScript contract.

Decision — feature first, hardening second and deliberately — request-ID logging, error middleware, integration and frontend tests, and CI landed as an explicit follow-up pass rather than being retrofitted under pressure.

Earlier ML and GenAI work: GAN-FashionGen (TensorFlow GANs) and Streamlit × GenAI projects. All repositories →

💡 What Drives Me

System design is the part I actually care about — how the pieces are arranged, where state lives, and what path a request takes to reach an answer.

Agentic AI is the sharpest version of that problem I've found. A model on its own is a guess generator; what makes it useful is the system around it — typed tools instead of free-form prompting, deterministic computation instead of asking a model to do arithmetic, precomputed data instead of a stuffed context window. Most of what I build is an attempt to make the model the smallest, most replaceable part of the system.

⚙️ How I Work

  • Spec before code. Each unit of work gets a written spec — goal, enumerated items, tests, explicit out-of-scope, and a ship gate — agreed before implementation starts. Several of my repo READMEs are design notes in the same spirit: they name the approach I rejected before the one I shipped.
  • Prefer the deterministic path. If Postgres can compute it, the model shouldn't. Precompute at ingest and keep the hot path cheap.
  • Test-driven where it counts. Vitest and Testing Library with MSW on the frontend, supertest against the API, Playwright end to end.
  • Reviewed before it merges. Implementations go through multiple logged review rounds between two different models, with an independent verification pass. Migrations are linted and replayed against a disposable Postgres, accessibility assertions run inside the Playwright suite, and scheduled jobs guard against schema drift.
  • Agents work from a written contract. An AGENTS.md pins conventions, invariants and known pitfalls, and each phase runs in its own git worktree so parallel work can't collide.
  • Ship it end to end. Deployed, reachable and documented — not just a repository.

🧰 Technology Landscape

TypeScript Next.js tRPC Drizzle Supabase Playwright

Languages TypeScript, Python, JavaScript, SQL
Frontend Next.js, React, React Native (Expo), Tailwind CSS, shadcn/ui, TanStack Query, React Hook Form, Framer Motion, Vite
Backend & data Node.js, Express, FastAPI, tRPC, Drizzle, PostgreSQL, Supabase, MongoDB, Redis, Zod, Pydantic
AI & agents Vercel AI SDK, LangGraph, LangChain, OpenAI, Anthropic, Gemini, MCP
ML & data science TensorFlow, OpenCV, NumPy, pandas
Testing & CI Vitest, Jest, Playwright (+ axe), Testing Library, MSW, supertest, Squawk, GitHub Actions, Docker
Tooling pnpm, ESLint, Prettier, Sentry, CodeRabbit, Vercel, Render

🎓 Education

Bachelor's degree in Computer Science — Air University

📫 Contact

If you'd like to work on something together, or you just have a question, get in touch.

LinkedIn Email GitHub

Pinned Loading

  1. AU_BLOG_WEBSITE AU_BLOG_WEBSITE Public

    JavaScript

  2. Medicare-app Medicare-app Public

    JavaScript

  3. Netflix-clone Netflix-clone Public

    JavaScript

  4. fullstack-security-implementation fullstack-security-implementation Public

    Auth and authorization reference build — JWT with refresh rotation, OAuth2.0 (Google/GitHub/Keycloak), RBAC and mTLS.

    TypeScript