Software engineer in Dhaka, Bangladesh. Backend systems, web, mobile, desktop and applied AI—currently at Nimble Software Lab, previously shipping enterprise insurance, pharmaceutical and government systems at Brain Station 23.
I build developer and product tools in the open, and I publish what does not work yet alongside what does. Every repository below states plainly what is implemented, what is planned, and what will never be supported. This page does the same.
Ten repositories, all MIT or Apache-2.0. None of them has a v1.0 release yet. These are specifications and foundations being built in public, and every repository states what is implemented, what is planned for v1.0, and what will not be supported.
| Stage | What it means |
|---|---|
| Building | Working code in the repository, checks passing. Not a release. |
| Foundation | The project shell builds and is tested. No product feature yet. |
| Specified | Specification, architecture and roadmap published. Implementation not started. |
ContextPact · any agent, same approved context
A local-first context and coordination layer for people who move between AI tools or run several agents at once. Durable knowledge, current decisions and task ownership live outside any single AI product, so the context follows you rather than the vendor.
- Implemented and tested — context and workspace contracts, local workspace layout, SQLite schema bootstrap with WAL and FTS5, TypeScript build and test pipeline.
- Experimental —
initandstatuscommands, MCP bootstrap and status surfaces. - Planned for v1.0 — context-pack retrieval and supersession, task leases and structured handoffs, guided agent connection, import, export and recovery.
TypeScript · SQLite · MCP · MIT
InstallGate · nothing executes unchecked
A local-first npm registry firewall, so the same dependency policy applies whether an install was started by a developer, a script or an autonomous coding agent. A scanner only helps when somebody remembers to run it; this is designed to sit on the registry path instead.
- Implemented and tested — typed
allow/warn/approval_required/blockverdicts, deterministic balanced and strict policy rules, npm registry request classification, adoctorcommand, automated Go checks. - Planned for v1.0 — the registry gateway itself, content-addressed tarball quarantine, integrity verification, explainable evidence, expiring human approvals, SQLite audit history.
- Unsupported in v1.0 — private registries, other package ecosystems, cloud accounts, AI-generated security verdicts.
Go · npm · supply-chain security · Apache-2.0
Workforce OS · coordinate agents and people through Notion
An operating protocol and Claude Code plugin for turning rough instructions into structured work, routing it to the right worker and keeping one shared system of record accurate—so work done through agents is not trapped in chat history.
- Implemented — the operating contract, three agent profiles, four commands, setup and operating skills, packaged as a Claude Code plugin.
- Planned for v1.0 — the bot gateway, scheduled heartbeat, and verified installers for other agents, Telegram and Discord. A clean-install release has not been published yet.
Claude Code plugin · Notion · agent workflows · MIT
DiskClearance · see what goes, keep what matters
A safety-first desktop application for understanding and reclaiming storage, built around explainable findings, review before action, and an honest distinction between moving to Trash and deleting permanently.
The Tauri shell builds and passes its checks. It exposes exactly one command, a status probe that reports scanningImplemented: false and deletionImplemented: false—with a test asserting it stays that way until the features exist. Scanning, duplicate detection, application removal and cleanup are all planned for v1.0.
Rust · Tauri · React · MIT
Specification, architecture and roadmap are public. No implementation yet.
| Project | What it will do | Planned stack |
|---|---|---|
| Code Clearance | Evidence-based quality and security clearance for AI-generated code—scan, correlate, challenge, verify the fix, and produce a commit-bound report that discloses its own coverage and residual risk. | CLI · MCP · CI · SARIF |
| StackBraid | A product skeleton where backend, web and mobile all implement one OpenAPI contract, so the frontend never knows which backend serves it. Ships auth and nothing else. | .NET · Python · Angular · Next.js · Flutter |
| RecordMint | Self-hosted browser video messaging. Press record in a tab, share a link, and the file sits in storage you own. No native app, no vendor account. | TypeScript · browser media · S3-compatible |
| Beziera | An HTML-native design canvas driven by the coding agent you already run, closing the loop an agent normally cannot: write, render, look, fix. | React · MCP |
| ShortReelCuts | Prompt-driven short-video creation that shows every decision it made underneath the result, and lets you change any one of them. | TypeScript · AI video · self-hosted |
| OhMyLife | A self-hosted home for personal records—memories, people, papers, plans—that an AI keeps current so you only ever visit. | Next.js · MCP |
- Specification, architecture and roadmap are published before implementation starts.
- Dependencies are audited for licence and maintenance before they are added—a licence that binds the user is a defect, not a detail.
- A planned feature is never described as a finished one, in a README or anywhere else.
- No throwaway
v0.1. The first public release of each project is a complete v1.0. - Decisions are written down so another engineer—or another agent—can continue without guessing.
- System behaviour stays explainable, especially around AI, security and anything destructive.
NimbleScribe · available now
Offline, on-device AI dictation for macOS and Windows. Hold a shortcut, speak, and clean text appears at the cursor in any application. Nothing leaves the machine.
Website · Downloads & releases
.NET · Python · Whisper · local LLMs · SQLite
| Area | Technologies |
|---|---|
| Languages | C#, Python, TypeScript |
| Frontend | React, Angular, Next.js |
| Backend | .NET, FastAPI, Node.js |
| Data | PostgreSQL, SQL Server, MySQL, SQLite, Firebase |
| Applied AI | LLM integrations, RAG, Whisper, local models, PyTorch, Keras |
| Delivery | Docker, CI/CD, GitHub Actions, AWS, Azure, Cloudflare |
Not a keyword list. Different products need different tools, and the useful skill is knowing how the pieces fit—and where complexity is not earning its keep.
| When | Work |
|---|---|
| 2026 — now | Building software at Nimble Software Lab |
| 2023 — 2026 | Software Engineer II, Brain Station 23 |
| 2023 | Data Science & Business Analytics internship, The Sparks Foundation |
| 2017 — 2022 | BSc in Computer Science & Engineering, Ahsanullah University of Science and Technology |
Across those roles I have worked on production systems spanning enterprise workflows, SaaS, AI-assisted products, mobile applications and internal automation. Client work stays anonymized where confidentiality requires it.
Co-author of “A Deep Learning Approach to Distinguish Normal Pneumonia and COVID-19 Pneumonia with Segmentation of Affected Areas of Chest X-Ray”—recipient of the Best Paper Award at ICCCT 2023.
I am documenting the longer journey from engineer to product builder: what I build, what I learn, the decisions that change the work, and the life happening around it.



