Collected Works · Fifty‑Nine Projects · MMXXVI

Romi Nur Ismanto

I like to train my agentic AI agent on large datasets with inference speed
AI-powered tools from Node JS roots to web frontiers.
Every commit lands on GitHub for you to fork & remix.

Portrait of Romi Nur Ismanto
The Author
§ I — A Note on the Author

About

Every commit lands on GitHub for you to fork & remix.

Romi Nur Ismanto is an engineer and author working at the intersection of agentic AI, network operations, and security. His path runs from designing one‑time‑password authentication systems in 2004, through two decades of banking‑grade security infrastructure and nationwide e‑channel monitoring, to building and training neural networks and autonomous AI agents today. He holds an M.Eng in Network Security from Universitas Indonesia and a B.Eng in Informatics from Universitas Gadjah Mada, has written twenty‑one books and study guides, and has shipped fifty‑nine projects — every one of them public on GitHub.

§ II — Entries No. I–XXI

Featured AI Working Projects

Alihformat file converter thumbnail
Fig. 1 — Alihformat

🔄 Alihformat — Eighty File Converters That Never Upload the File, and One Route for the Four That Must

An Indonesian-language file converter of eighty tools on seven shelves — images, PDF, archives, spreadsheets and data, documents, audio and video, and AI — built on a promise printed on the page of every local tool: Diproses di perangkatmu, tanpa upload. Seventy-six converters run entirely in the browser in JavaScript and WebAssembly; only the four marked AI send a file anywhere. The whole catalogue is one data file with no functions in it, read by the server to pre-render a static page per converter for search engines and by the client to dispatch each engine kind to a module imported only when needed, so a new pair such as WEBP to BMP is one line in an array. Images pass through Canvas with hand-written BMP and six-size ICO encoders, heic2any for iPhone photos, SVGs sized from their viewBox, and a pixel ceiling that drops to 16 MP on iOS Safari, where larger canvases fail silently. PDFs are assembled with pdf-lib — which reads a JPEG’s EXIF orientation to decide whether a phone photo can be embedded as-is or must be redrawn upright — and rendered with pdf.js under the print intent so a background tab does not stall the job. Archives open with fflate for plain ZIP and libarchive.js in WebAssembly for RAR, 7Z and TAR; 7Z is written by having libarchive gzip the stream, because it emits an empty file uncompressed, and gunzipping the result. Spreadsheets use SheetJS 0.20.3 from its own CDN rather than the outdated npm release, every CSV carries a BOM so Excel reads UTF-8, and XML keeps 08123 as text. Audio and video run on a 30 MB ffmpeg.wasm fetched once, with jobs serialised through a promise queue so two tools never share temporary files. The AI shelf — PDF to Markdown, OCR, table photo to CSV, invoice to JSON — posts to one Next.js route that holds the OpenRouter key, fixes the prompt at temperature zero, and caps files at 3 MB under the platform’s 4.5 MB body limit, shrinking oversized photos a fifth at a time until they fit.

Keywords Client-Side Conversion·WebAssembly·ffmpeg.wasm·libarchive.js·pdf-lib·pdf.js·SheetJS·Next.js SSG·OpenRouter·Bahasa Indonesia

IDX Trader Suite stock screener thumbnail
Fig. 2 — IDX Trader Suite

📈 IDX Trader Suite — Eighteen Desks for the Indonesia Stock Exchange, and Every Trade Plan Snapped to the Tick

An Indonesian-language analysis workstation for scalpers and swing traders on the IDX, with eighteen desks in five groups: screeners for scalping, swing, the 200-day average, technicals and foreign flow; the market, a heatmap and a watchlist; per-stock analysis, broker accumulation (bandarmologi), the running trade tape, fundamentals, insiders and seasonality; comparison and backtesting; and a position calculator and trading journal. It is written in plain Node.js with no dependencies at all: one 293-line handler serves both a local node:http server and a single Vercel function, and the browser loads eighteen view modules through a hash router, so any desk can be shared as a link such as #/bandar/BBRI. The API key for the upstream market-data feed never leaves the server; calls are held to five at a time with a timeout and one retry, results are cached in memory and on disk with a lifetime that follows the market clock (fifteen seconds for a live quote, thirty minutes for end-of-day data while the exchange is open, six hours once it closes), and the remaining daily quota is read from response headers and shown in the header bar. The scalping engine is a set of pure functions that know the exchange’s rules: the five-step tick-size table and the 35/25/20% auto-reject limits, so a stop loss is floored and each target ceilinged to a valid tick, both targets are capped at the auto-reject price, and a score of 0–100 blends liquidity, ATR volatility, relative volume, momentum and the cost of one tick as a share of price, with a twelve-point penalty for stocks within 2% of the limit, where orders queue and cannot fill. Order flow is read from three hundred trades on the tape as the share of aggressive buying (HAKA) against aggressive selling (HAKI). Backtests run in the browser at the next day’s open with Indonesian broker fees and gap-aware stop losses; the watchlist and journal never leave localStorage.

Keywords Indonesia Stock Exchange·Scalping Screener·Tick Size & ARA·Order Flow·Technical Analysis·Backtesting·Zero-Dependency Node.js·Vercel Functions·Lightweight Charts·Bahasa Indonesia

Image V.1 online image tools thumbnail
Fig. 3 — Image V.1

🖼️ Image V.1 — Sixteen Image Tools in One HTML File, and a Server Only Where the Browser Cannot Go

An Indonesian-language image workbench of sixteen tools — ID photo, a Korean-style portrait retouch, a brighten-and-rejuvenate retouch with slim and fuller face shaping, compress, resize, crop, convert to and from JPG, a photo editor, upscale, background removal, watermark, meme maker, rotate, HTML to image and face censoring — shipped as one 128 KB HTML file, three serverless functions and a 21-line rate limiter. One rule is applied sixteen times: an image stays on the device unless the operation cannot be done there. Canvas, WebAssembly and in-browser models do the work, and fourteen libraries are fetched from a CDN only when the tool that needs them opens; eight tools carry an AI badge, and only those send a copy — shrunk until it fits under the platform’s 4.5 MB request ceiling — to an image or vision model behind a proxy that keeps the key on the server. The portrait tools sit behind a gate: a BlazeFace detector must find exactly one face, or nothing runs and no model is paid. The pas foto is framed from that face box by head-height ratios per size, composed over red, blue or white with an IS-Net cut-out, resampled to exact millimetres at 300 DPI, and stamped as 300 DPI by rewriting four bytes of the JFIF header, with a 4R print sheet packed in whichever orientation holds more copies. Background removal runs IS-Net in WASM, or asks a model for a flat green backdrop and keys it out on the device. Face censoring runs the detector on the whole image and four overlapping tiles so the back row of a group photo is found, and vision models answer only in boxes on a 0–1000 grid that the user can delete or redraw. HTML-to-image by URL is the one non-AI server feature: headless Chromium on a pixel budget set by the time left, degrading PNG to JPEG to a shorter capture rather than exceed 4.5 MB. A green or red AI aktif pill is backed by a real key check that spends no credit.

Keywords Client-Side Imaging·Canvas 2D·WebAssembly·MediaPipe·IS-Net·Chroma Key·Headless Chromium·OpenRouter·Vercel Functions·Bahasa Indonesia

Padel Heaven arcade padel game thumbnail
Fig. 4 — Padel Heaven

🎾 Padel Heaven — Golden-Hour Arcade Padel in Three Static Files

An arcade doubles padel match — you and Maya against Luna and Sofia on a Bali court at golden hour — shipped as three static files of 20 KB, 8 KB gzipped, with no library, no image, no web font, no storage and no request of its own. Everything that moves is redrawn every frame on one 2D canvas: swaying palms, a clubhouse, floodlights, glass walls, a mesh net and four players whose strides, skirts, ponytails and perforated padel rackets are stroked from primitives — some 560 paths in 0.3 ms of script. Depth is a projection of a few lines, a linear depth factor over a 0.65 ground foreshortening, and the cinematic camera is the same function turned 9.8°; occlusion is a painter’s algorithm by layer — far pair, net, near pair, ball, near glass. The world is in metres: a 10 × 20 m court, service lines at 7 m, a net tested at 0.94 m, glass with a restitution of 0.8. Shots are solved backward rather than simulated forward: each strike picks a landing spot 4.5–7.5 m past the net and a flight time — 1.05 s, or 1.65 s for a lob — and the launch velocity follows in closed form from the projectile equation, so every generated ball is aimed in, and the movement key held at contact is the aim. Scoring is padel’s golden point in a first-to-three-games set, and the glass is legal only after the floor. The three computer players share one rule: the receiving-side player nearest the ball chases a point a tenth of a second ahead of it, at 4.2 m/s against the human’s 5.2. A headless harness ran the deployed script for 13,409 points: the out and glass-before-bounce branches never fired, net faults were more than forty times likelier at 30 fps than at 60, and because the receiving side is read from the sign of the ball’s velocity — which flips at the back glass — the AI played none of 2,424 back-wall rebounds.

Keywords Canvas 2D·Vanilla JavaScript·Zero Dependencies·Projectile Aiming·Painter’s Algorithm·Game AI·Web Audio API·Pointer Events·Headless Simulation·Bahasa Indonesia

OpenRomeo Video Studio thumbnail
Fig. 5 — OpenRomeo Video Studio

🎬 OpenRomeo Video Studio — Ten Cinematic Seconds From a Sentence or an Image

Text or image to a ten-second cinematic clip at up to 1080p in six aspect ratios, with audio — on a model priced per clip, which makes the engineering question and the business question the same one: let anyone with a Google account try it, and make the worst day cost a known amount. The whole thing is one static HTML file, three serverless functions and a 142-line helper with a single dependency. There is no cookie and no session store: the Google ID token from the browser is the session, presented as a bearer credential on every call, verified against Google and cached per warm instance, and expiring exactly when Google says. The four-clip quota is not a counter but a count — each accepted job writes one small blob under a salted hash of the account, quota used is the number of blobs, and a refund is a deletion, so the ledger can never disagree with itself. Before submission a vision-capable model rewrites the idea into a 45–90-word cinematic prompt with camera move, lens, light and a three-beat motion arc, faithful to the reference frame; the rewrite is shown beside the original and silently reverts to the user’s words on refusal, and the quota is checked before the rewrite so an empty account never pays for one. The video model is never named to the browser — every forwarded job object passes a field whitelist. The client polls every twenty seconds for up to an hour, keeps the job in local storage so a reload resumes rather than resubmits, refuses to show 100% until the provider says completed, and downloads from a presigned URL with a streaming server proxy as fallback so the key stays home. Failed jobs give the credit back.

Keywords Text-to-Video·Image-to-Video·OpenRouter·Vercel Functions·Vercel Blob·Google Identity Services·Stateless Sessions·Cost Governance·Vanilla JS

Sabina live bank customer-service agent thumbnail
Fig. 6 — Sabina

🏦 Sabina — Live Bank Customer Service on Synthetic Core Data

A live customer-service agent for Bang Digital, a bank that does not exist — which is what lets the whole shape of a banking assistant be built and run in public without one real customer record. It answers the two ways such agents fail. Against wandering off-topic, a regex guardrail classifies every message before any model call, so a shampoo price or an “ignore previous instructions” is refused instantly, at zero inference cost, in a voice chosen for the kind of question — not a cashier, not a cook, not a person with a home address. Against inventing account facts, every number is computed rather than stored: a generator seeded on cif:account:month (FNV-1a into Park–Miller) lays down salary on the 25th by BI-FAST, quarterly fees, ATM withdrawals at named machines and QRIS purchases at real merchants, identical on every request yet always covering the ten years ending today, so last month’s statement and the next deposit maturity never go stale. Retrieval is a hand-built inverted index with BM25 idf over 2,845 procedures expanded from a few dozen templates across 25 products and 38 cities, plus 205 service documents and a per-customer index rebuilt daily; the retrieved ids and scores are streamed to the screen as evidence beside the answer. Verification is a mock and the prompt says so in capitals — any date of birth and mother’s name is accepted — and a balance inquiry after it is answered from the ledger without the model ever producing the number. Complaints become tickets from language alone, with priority, unit and SLA by incident rule. SSE streaming, a vision model for transfer receipts, a grounded template answer when no key is present, and a Docker + Caddy path beside Vercel.

Keywords Next.js 16·TypeScript·DeepRomeo (DeepSeek)·RAG·BM25·Guardrails·Seeded PRNG·SSE Streaming·Vision·Bahasa Indonesia

Jekardah COD marketplace thumbnail
Fig. 7 — Jekardah COD

🤝 Jekardah COD — A Marketplace Where You Meet, Check, Then Pay

A cash-on-delivery classifieds marketplace built on one product decision: the platform moves no money. Ketemu orangnya, cek barangnya, baru bayar — meet the person, check the item, then pay — describes a transaction the software cannot see, so the software’s job is to arrange the meeting and record what it can honestly verify. A Next.js 16 front end rewrites /api/* to a separate Go project, so the session cookie, the OAuth state cookie and Google’s callback never leave one origin. The API is standard-library Go — net/http with the 1.22 method-and-path router, pgx, no framework — run as a Vercel function that builds one application per warm instance under double-checked locking, caps its PostgreSQL pool at four connections because the platform spawns instances freely, and serialises schema migration under a transaction-scoped advisory lock so parallel cold starts cannot race. Configuration refuses to start wrong: the moment the front-end URL is HTTPS, a default JWT secret, demo mode, missing OAuth or a plaintext backend are all rejected, and the demo-login route is never registered rather than merely disabled. Listing photos may come from exactly three hosts, and both the Next upload route and the Go handler identify image type from leading bytes, not the declared content type; the Next route confirms the session with the backend before it touches storage. Chat is the transaction layer — one conversation per listing and buyer, membership checked on every read and write, incremental polling by last-seen id — and a review can only be written for a listing marked sold, by a buyer who actually opened a conversation on it, about its seller and no one else. Sixteen categories from Avanza to padel rackets, seeded with attributed samples.

Keywords Go net/http·Next.js 16·PostgreSQL (Neon)·pgx·Google OAuth 2.0·JWT HS256·Vercel Blob·Tailwind CSS 4·Bahasa Indonesia

Office Romeo browser office suite thumbnail
Fig. 8 — Office Romeo

📝 Office Romeo — A Copilot That Edits the File, Not a Chat Beside It

A browser office suite — document, spreadsheet, slides and PDF editors under one shell — built on the position that an assistant inside a document should return an edit, not a draft. A chat pane leaves the user to copy and reconcile; letting the model rewrite the whole document silently rewords the paragraphs nobody asked it to touch. So the model is constrained to a patch vocabulary against the live canvas — a replacement for the selection, a fragment to append, a cell write, a colour, a slide to add — and told to prefer the smallest patch that does the job; full replacement exists but is reserved for requests that genuinely mean the whole document. Highlight one sentence and the rule is explicit: revise only that selection, never the document. Underneath, one framework-neutral router returning plain status/body/headers is mounted twice — as Vite middleware in dev and as serverless functions in production — so both environments run identical routing code and the “works locally, 404 after deploy” bug has nowhere to live. The model call is budgeted against the platform’s own function ceiling: a three-model fallback under a total budget below the cap, a per-attempt timeout, a floor below which a new attempt is not started, reasoning mode switched off because a canvas patch needs neither the latency nor the tokens, and an early exit on auth and billing failures where retrying cannot help. The sheet is a real evaluator — tokeniser, parser, AST interpreter, sixty functions, memoised dependency walk, cycle detection, Excel serial dates, and leading zeros kept as text — because a copilot that writes a formula into a grid that cannot evaluate it has produced a screenshot. Files are stored per user under AES-256-GCM, so the object store holds ciphertext only.

Keywords React 19·Vite 6·Serverless·Patch Protocol·Structured Output·Formula Engine·contentEditable·AES-256-GCM·HMAC Sessions·Google Sign-In

ZipRar client-side archive tool thumbnail
Fig. 9 — ZipRar

📦 ZipRar — Archives That Never Leave the Browser

The standard bargain of the online archive tool is that you hand your files to a stranger’s server to use the feature. ZipRar declines it: the Vercel config declares a Vite build and a dist directory and nothing else — no API route, no bucket, no function — so the network tab is the privacy audit. No single library covers the format matrix, so three engines are routed behind one interface: fflate writes ZIP and provides a fast path for reading it, libarchive in a worker reads everything else including RAR v4 and v5, ISO, CAB and CPIO, and 7-Zip writes 7Z with AES and encrypted headers so filenames are hidden too, doubling as the stream compressor for bzip2, xz and zstd. Between them sits a hand-written 512-byte ustar writer, because the missing piece was the container rather than the compression — including the checksum convention that requires the checksum field to be filled with spaces before it is summed, and the name/prefix split that lets a path exceed a hundred characters or fail loudly rather than truncate. Path sanitisation runs in both directions: the function that rejects .. segments, absolute prefixes and NUL bytes on extraction also runs over every path written into a new archive, so the tool cannot author the Zip Slip attack it defends against. At the WebAssembly boundary bytes are copied out of the module heap before it can be reused and every MEMFS entry is unlinked after each run, which is the difference between a page that runs all afternoon and one that dies on the third archive. Dropped folders are walked with a readEntries pump loop — the missing loop is the commonest drag-and-drop bug, and it fails by producing an archive that merely looks complete. RAR extracts but does not create, and the interface says why instead of quietly shipping a ZIP.

Keywords React 19·Vite 8·TypeScript·WebAssembly·libarchive.wasm·7-Zip wasm·fflate·ustar·Zip Slip Defense·Zero Upload

Pikapiku web transcription app thumbnail
Fig. 10 — Pikapiku

🎧 Pikapiku — Web Transcription That Never Stores Your Media

Five hours of audio transcribed on a platform whose functions die at ninety seconds and whose request bodies stop at four and a half megabytes. Those two limits make the usual architecture — upload to a bucket, queue a worker — impossible, so the orchestration moves into the tab instead: ffmpeg.wasm cuts the file into 4½-minute chunks locally, re-encodes each to mono 16 kHz MP3 down a 64→48→32 kbps ladder until it fits the body limit, and posts them one at a time to a short-lived function that forwards each to a speech model and forgets it. Chunks overlap by two seconds and the overlap is removed on the way back, so a word spoken across a cut is transcribed with context on both sides but appears once. The privacy claim is a schema property rather than a policy: the transcript table has columns for text, SRT and timed cues and no column for media at all, the decoded chunk buffer is zeroed in a finally block, and the ffmpeg worker is terminated when the job ends. Quota is reserved before the upstream call and keyed on a client-minted job id, so a rejected request costs nothing and a sixty-eight-chunk file spends one job slot instead of sixty-eight. A second, cheaper model then copy-edits the transcript under a prompt of pure prohibitions — fix typos, never summarise, never translate, never move text between blocks — batched, halved on failure, and passed through unedited when it still fails, so the transcript is never lost to the pass that was only meant to fix its spelling. Google sign-in gates every route; output leaves as text, Word, or SRT.

Keywords Next.js 16·React 19·TypeScript·ffmpeg.wasm·OpenRouter STT·Speaker Diarization·Auth.js + Google·Prisma + Postgres·Upstash Redis

Jaipong AI song studio thumbnail
Fig. 11 — Jaipong

🥁 Jaipong — AI Song Studio in Bahasa Indonesia

Named after the kendang-driven dance music of West Java, a studio that turns one Indonesian sentence into a complete song — sung for real. Type “lagu tentang hujan sore di Bandung” and a language model writes the plan — title, genre, a style paragraph and original lyrics, streamed to the screen line by line — then a music model (Lyria 3 Pro) performs it, the finished stereo track arriving as base64 chunks over SSE with time-stamped lyrics that drive a three-tier karaoke panel. The plan travels as a line-oriented format rather than JSON, so a truncated generation degrades to the last whole line instead of a parse error; the audio format is sniffed from the file’s first bytes, because the model sends MP3 even when asked for WAV. Twelve one-tap presets put Jaipong Sunda, Dangdut Koplo, Keroncong and Gamelan Ambient beside pop, rock and EDM; pick female, male or instrumental vocals and 45 seconds to 4 minutes, or supply your own title and lyrics to be sung verbatim. Playback decodes to an AudioBuffer through Web Audio — immune to autoplay policy — with a spectrum visualizer, keyboard transport, and MP3 download. Songs belong to the browser: metadata in localStorage, audio in IndexedDB, nothing stored server-side — while layered burst, daily and global quotas cap the per-song-priced music model’s worst day at a known bill.

Keywords Next.js 16·React 19·TypeScript·OpenRouter·Lyria 3 Pro·SSE Streaming·Web Audio API·IndexedDB·Bahasa Indonesia

EditPDF browser-based PDF editor thumbnail
Fig. 12 — EditPDF

📄 EditPDF — Forty-One PDF Tools in the Browser

A free online PDF editor in the manner of Sejda, with one difference that governs the whole design: nothing is uploaded. Every operation runs in the browser tab, so a contract, a payslip or a scanned passport is opened, edited and saved without a single byte crossing the network — there is no server to trust, because there is no server. Click a paragraph and retype it in place; whiteout a region, drop in images, shapes and signatures, then fill and sign forms. Forty-one tools cover the rest: merge, alternate-and-mix, split by range, size, text or bookmarks, extract, organize, crop, rotate, resize, N-up, flip, watermark, page numbers, header and footer, Bates numbering, redaction that removes content rather than painting over it, AES protect and unlock, flatten, compress, grayscale, repair, bookmarks and metadata — plus conversion to Word, Excel, PowerPoint, text and JPG, and Tesseract OCR to make a scan searchable. Built as a React and Vite single-page app over pdf-lib, PDF.js and fontkit.

Keywords React 18·Vite 5·pdf-lib·PDF.js·fontkit·Tesseract OCR·41 Tools·100% Client-Side·Zero Upload

Somat Indonesian AI chat application thumbnail
Fig. 13 — Somat

💬 Somat — AI Chat Indonesia for Text & Images

An Indonesian-language AI chat that hides every knob: no model picker, no API settings, no separate modes — just one conversation box where capability appears when it is asked for. Ask a question and the answer streams back with Markdown, tables, code blocks and LaTeX; ask about something current and the model searches the web itself, listing its sources beneath the reply. Paste a link and the page is fetched and read. Say “buatkan gambar” and an image is generated inline with a download button; say “buatkan Excel” and a real .xlsx is assembled server-side and handed back as a download card — the same for Word, PowerPoint and PDF, with every slide deck laid out in strategy-consultant form (executive summary first, one message per slide, action titles, MECE bullets, a “so what” kicker). Uploaded PDFs, Office and OpenDocument files are parsed for their text, while scanned images run OCR in the browser in Indonesian and English. The OpenRouter key never leaves the server, model names are never sent to the client, and conversation history lives in the browser’s own IndexedDB — there is no server-side database at all.

Keywords Next.js 16·React 19·TypeScript·OpenRouter·Streaming·Web Search·Tesseract OCR·docx & xlsx & pptx & pdf·IndexedDB·Bahasa Indonesia

PdfRomeo macOS PDF toolkit thumbnail
Fig. 14 — PdfRomeo

📄 PdfRomeo — 43-Tool PDF Suite for macOS

A professional PDF toolkit for Apple Silicon that keeps every document on the machine — no upload, no account, no cloud round-trip. Forty-three focused tools across six families: organize (merge, interleaved mix, split by range/bookmark/size/text, extract, reorder, crop, rotate, N-up), edit & sign (click a page to place text or click existing text to rewrite it, fillable form creation, signature images, watermarks, Bates numbering continuous across files), convert (PDF to Word, table-aware Excel, PowerPoint, text, and JPG/PNG/TIFF at any DPI), protect (AES-128 with granular permissions, unlock, flatten), and scan repair (real image-downscaling compression, auto-deskew, Tesseract OCR, damaged-file recovery). Built on PySide6 with pikepdf and PyMuPDF, its engine layer carries no Qt imports at all, so all forty-plus operations are drivable from a CLI, a server, or a test harness without ever opening a window.

Keywords Python·PySide6·Qt·pikepdf·PyMuPDF·Tesseract OCR·Apple Silicon·Offline

OpenRomeo desktop AI coworker application thumbnail
Fig. 15 — OpenRomeo

🤖 OpenRomeo — AI Coworker on Your Desktop

A cross-platform desktop AI coworker that delivers finished work, not just chat — polished documents, updated spreadsheets, triaged inboxes, and Slack replies that land as real files in your workspace. A supercharged fork of OpenWorker, rebuilt around the latest frontier models: GPT‑5.6, Claude Fable 5 & Sonnet 5, Gemini 3.6, Kimi K3, MiniMax M3, DeepSeek V4, GLM‑5.2, and Grok 4.5 — with vision enabled on the multimodal flagships, or fully local inference via Ollama. Ships the Claude Desktop-standard builtin document skills (docx, pptx, xlsx, pdf)…

Keywords Tauri·Python·TypeScript·MCP·Agentic AI·Multi-Model·Local-First·macOS & Windows·MIT License

NetScope native macOS network scanner thumbnail
Fig. 16 — NetScope

📡 NetScope — Native macOS Network Scanner

A native macOS network scanner built from the ground up with Swift 5.9 and SwiftUI. Features six integrated modules: My Device (local system & interface info), Discovery (TCP knock scan, ARP resolution, 14+ Bonjour service types, OUI vendor lookup), Port Scanner (Top 100/1000/custom ranges with 100+ concurrent probes, banner grabbing, TLS certificate inspection), Ping & Traceroute (ICMP diagnostics, A/AAAA/MX/NS/CNAME/TXT/SRV DNS queries), Monitor (configurable polling with real-time alerts & 24-hour event history via Swift Charts), and Reports (CSV/JSON/HTML/PDF export).

Keywords Swift·SwiftUI·Network.framework·CoreWLAN·SwiftData·XPC·macOS Native·MIT License

Transkrip local AI transcription application thumbnail
Fig. 17 — Transkrip

🎙️ Transkrip — Local AI Audio & Video Transcription

Privacy-first cross-platform desktop application that transcribes audio and video files entirely on-device — no cloud, no uploads, no data leaks. Built with Electron 41, React 19, TypeScript 6, Vite 8, and Tailwind CSS 4, Transkrip wraps the highly optimized whisper.cpp engine behind a polished drag-and-drop UI. Supports common audio/video containers (MP3, WAV, M4A, MP4, MOV), multilingual transcription via Whisper models, and rich export options to .txt, .docx, and .pdf. Features a persistent local transcription history powered by SQLite (better-sqlite3)…

Keywords Electron 41·React 19·TypeScript 6·Vite 8·Tailwind CSS 4·whisper.cpp·SQLite·Privacy-First·MIT License

SonicAI text-to-song generator thumbnail
Fig. 18 — SonicAI

🎵 SonicAI — AI Text-to-Song Generator

Browser-based AI text-to-song generator that transforms written lyrics into complete musical compositions entirely on the client-side. Features a character-to-note mapping algorithm that converts text into melodies, with multi-layer instrument synthesis (melody, chords, bass, drums) and a dual vocal engine combining formant synthesis with Speech Synthesis API. Supports 6 music genres (Pop, Rock, Jazz, Electronic, Classical, Lo-fi) each with unique scales and chord progressions. Includes real-time 80-bar frequency spectrum visualizer, tempo adjustment (60–180 BPM), key selection…

Keywords HTML5·CSS3·JavaScript·Web Audio API·Speech Synthesis·Formant Synthesis·Zero Dependencies·MIT License

GPU versus CPU versus TPU simulator thumbnail
Fig. 19 — GPU Simulator

🔴 GPU vs CPU vs TPU Simulator

Interactive web-based simulator that visually demonstrates performance differences between CPU, GPU, and TPU when handling AI and deep learning workloads. Features a real-time processing race with three horizontal progress bars competing to complete identical tasks, supporting 4 workload types: Matrix Multiplication (1024×1024), CNN Training (ResNet-50), Batch Inference, and NLP Transformer (BERT-Base). Includes detailed processor cards with animated core visualization grids (16 cores for CPU, 256 for GPU, 64 for TPU), real-time metrics (ops/sec, throughput, timestamps)…

Keywords HTML5·CSS3·JavaScript·GPU Computing·TPU Systolic Array·AI Workloads·Zero Dependencies·MIT License

AI image diffusion simulator thumbnail
Fig. 20 — Diffusion Simulator

🎨 AI Image Diffusion Simulator

Interactive educational tool that visualizes how diffusion models generate images through a simulated denoising process. Select from 10 adorable animals (cat, dog, bunny, panda, fox, penguin, hamster, owl, koala, duck) and watch as random noise transforms into coherent illustrations via reverse diffusion. Features adjustable diffusion steps, Classifier-Free Guidance (CFG) scale slider controlling prompt adherence, manual noise slider for exploring intermediate states, and speed selector (slow/normal/fast). Includes real-time progress bar with step counter…

Keywords JavaScript·Canvas API·Diffusion Model·Denoising·CFG Scale·Zero Dependencies·MIT License

AI news presenter simulator thumbnail
Fig. 21 — AI News Presenter

🎤 AI News Presenter Simulator

Virtual news anchor simulator powered by Text-to-Speech with professional animated SVG avatar. Features lip-sync mouth animation, automatic eye blink, breathing animation, and intensified avatar glow during broadcast. Bilingual support for Bahasa Indonesia and English using Web Speech API with adjustable speech rate (0.5x–2x) and pitch control. Delivers a full TV studio experience with running BREAKING news ticker, blinking LIVE badge, real-time clock, SVG news desk, audio equalizer animation, and glassmorphism UI effects. Includes real-time subtitle with word highlighting…

Keywords HTML5·CSS3·JavaScript·Web Speech API·SVG Animation·Bilingual TTS·Zero Dependencies·MIT License

§ III — Entries No. 22–59

The Extended Archive

§ IV — Papers & Interactive Studies

Latest Research

  • 🔥 Mastering PyTorch Handbook

    A contract-first, reproducibility-driven curriculum for deep learning engineering on ephemeral cloud runtimes. One invariant twelve-section template repeated across forty-eight chapters, a shape / state / failure-signal contract vocabulary, benchmarks admitted only with warm-up and CUDA synchronisation, a six-step failure protocol paired with a debugging decision tree, and reproducibility treated as a property of the whole pipeline rather than of a seed.

  • 🔬 AI Research Handbook — A Professional LLM Master

    An evaluation-first framework for domain-specific LLMs in Indonesia’s regulated industries. Four-axis failure diagnosis, seven lifecycle stages each with its own dataset and decider, three evaluation layers, five release gates, and a single-control compliance matrix — with the 2026 revision for small models on consumer GPUs.

  • 🔬 From Frontier Benchmarks to Governance Triggers

    A structured review of the evidence on progress toward AGI and ASI. Examines what frontier benchmarks actually establish, identifies six inference gaps — construct, system, generalization, reliability, version, and exposure — and proposes the Evidence-to-Governance Translation (EGT) framework mapping verified capability signals to graduated controls. With Muhammad Reza Pahlevi & Muhammad Ikhtiarso; evidence current to 13 August 2026.

    Read the review
  • 🤖 LLM Architecture Compendium 2025–2026

    A comprehensive technical analysis of 42 large language model architectures from 270M to 1 trillion parameters. Covering Llama, Qwen, DeepSeek, Gemma, Kimi, Mistral, GLM, OLMo, MiniMax, Nemotron, Grok

    Read the compendium
  • 📊 AI Exposure in the Job Market — Indonesia vs United States 2026

    Interactive visualization comparing AI exposure across 17 Indonesian sectors and 22 US occupation groups using BPS Sakernas and BLS data with Karpathy-style scoring methodology.

    Explore the visualization
  • 🗺 Indonesian Jobs AI Map 2026

    Interactive mapping tool displaying AI exposure levels across 436 Indonesian occupations with treemap visualization, outlook scatter plots, and distribution breakdowns by education and salary using BP

    Open the map
  • 📖 Vibe Coding SDLC Framework

    A 6-phase methodology for AI-assisted software development. From requirements to production with 12 chapters, case studies, templates and checklists.

    Read the whitepaper
  • 🤖 Vibe Coding Handbook: Using Claude Code

    Practical guide covering installation, CLAUDE.md configuration, prompt patterns, workflows, testing, debugging and security across 10 chapters.

    Read the handbook
  • 🌐 Web 4.0: The Birth of Autonomous Digital Life

    Explores AI agents functioning as independent economic actors with crypto-based mechanics, including Darwinian selection and self-replication concepts across 13 sections.

    Read the whitepaper
  • 💼 AI Exposure of the US Job Market — Karpathy Clone

    Interactive dashboard showing AI exposure for 800+ US occupations. Treemap, salary vs exposure scatter plot, breakdown by category & education using BLS data.

    Open the dashboard
§ V — The Shelf, Twenty‑One Volumes

Books & Study Guides

  • 🥇 Indonesia Menuju Emas — Masterbook Olimpiade Matematika SMA

    An Indonesian-language masterbook for the International Mathematical Olympiad, written around one reading of the data. Indonesia placed tenth in the world at Cluj-Napoca in 2018 and sixty-third at Shanghai in 2026, and the book argues that the gap is explainable: Indonesian students almost always solve problems 1 and 4 and rarely score on 3 and 6, so the difference between an ordinary year and a golden one lies almost entirely in problems 2 and 5. With the gold cut-off averaging thirty points over the last decade, the recipe is arithmetic — 7 + 7 on the easy pair, 7 + 7 on the middle pair, and two to four partial points on the hardest — and the book is built to turn the medium problem from “sometimes solved” into “almost always solved”. A foundation part (F1–F6: logic and sets, algebra, functions, induction, basic counting and probability, elementary geometry and trigonometry) leads into four pillars — algebra, number theory, geometry, combinatorics — and ten proof techniques, fifty-one chapters in all. Every chapter opens with where its topic appears at the IMO, proves every theorem, solves every example from start to finish, and closes with a case study that follows a contestant from scratch work to a clean solution, a history-and-context note, and exercises graded by stars against IMO problem positions. Part VI dissects all 120 IMO problems from 2007 to 2026 in Indonesian translation, each with the Indonesian team’s score on it; Part VII turns the findings into competition-day strategy for the 4½-hour paper, simulation sets, an intensive problem set and a twelve-month plan in four phases. Appendices add a technical dictionary, a pre-submission checklist, a twelve-week programme, a 0–7 scoring rubric, hints, a glossary and full step-by-step solutions to every exercise. 406 pages, typeset in LuaLaTeX; edition 2026.

    Download PDF
  • ⚖️ AI Governance and Architecture — From Principles to Controls

    One question, asked on the first page and answered for 300 pages: how does a bank use AI safely and usefully, in a way it can actually prove to its board, its auditors, and its regulator? The answer the book commits to is a chain rather than a principle — every principle is given an owner, a control the system enforces rather than a policy people remember, evidence that can be inspected, and a stated consequence when it fails. Seven parts and 111 chapters in one volume, gathering the parent paper and Volumes I–VI, with 225 numbered exhibits; English title, Indonesian text; edition of 24 September 2026. Part 1 is the whole framework and is meant to be read alone by an executive; Parts 2–7 take one link each and are for the people who have to build it, each part opening with the question it answers — who has authority and which standards apply, how the components are built, how data, knowledge and agents are controlled, whether we are protected and how we would know, how it runs and recovers and what it costs, and what gets done first and how the benefit is proven. Its spine is a six-layer reference architecture cut by three planes, stated as a rule the rest of the book obeys: the control plane decides, the data plane executes, the evidence plane records. Around it sit fourteen policy articles, thirty-six minimum controls each carrying its own test procedure, nine risk-classification dimensions, twelve catalogued AI threats against seven layers of defence, five autonomy levels from A0 to A4, ten opening runbooks, six use-case playbooks — knowledge assistant, agent-assist contact centre, credit memo, AML triage, AIOps, coding assistant — a three-wave eighteen-month roadmap, thirteen architecture posters, and an eighty-nine-term glossary. What gives it its character is how often it rules something out. Internal Audit is deliberately not an approver of releases. A pipeline may produce ready for decision and never approved. “Not yet assessed” is not the same as level one, because absence of data does not prove absence of control. A field nobody knows yet is recorded as not available, with an owner and a follow-up, rather than filled with an assumption. Some risk indicators are given no amber band at all, because one occurrence should go straight to red. There is no fallback that quietly downgrades a data classification, agents reach tools through a broker rather than a shell, GPU workers hold no public address, and a token exchange carries an act claim so the record shows an agent acted on a named person’s behalf. It closes on ninety days — authority in the first thirty, technical foundation in the next thirty, first evidence in the last — five things not to do, among them buying GPUs before assessing power and cooling and reporting potential benefit as realised, and a single test of success after a year: every AI system registered and owned, critical controls proven effective with repeatable evidence, no material unsafe action, at least three use cases in production with the benefit verified by Finance, and a bank able to stop, recover, and explain every AI system it runs. Bank Somat and its AI platform are pseudonyms, and the book says plainly on its copyright page and again on its last that every threshold, score, SLA, capacity and cost figure in it is a simulation or an opening proposal to be calibrated, not a measurement.

    Download PDF
  • 🏛 Handbook of System Engineering for IBM Z (Mainframe)

    The companion volume to Handbook of System Engineering for IBM i (AS/400), and deliberately built to the same plan — foundations, architecture, implementation, operations, reliability, core banking, modernisation, then the runbook catalogue and command reference — so that an engineer who knows one platform can find the same chapter in the other; Appendix A is literally a concept map from IBM i to IBM Z. Forty-six parts and 193 chapters, plus twenty appendices and two indexes, across 603 pages in Indonesian, written against z/OS 3.2 on IBM z17; First Edition, 20 September 2026. The subject is z/OS in a bank, and the book is exact about its own scope: z/VM and Linux on IBM Z appear only as far as consolidation requires, and every chapter is held to the same three questions — what the concept is, which commands are used, and what to do when it breaks. Its conventions are declared up front: operator commands carry their D, F, S, P and V prefixes as typed at an MCS console or through SDSF, TSO commands appear verbatim, and every dataset example uses a fictitious high-level qualifier. Part XXI carries the catalogue to sixty runbooks, RB-001 through RB-060, each keeping one shape — symptom, diagnosis, action, prevention — and then turns the catalogue on itself: coverage is incidents that had a relevant runbook over total incidents, freshness is days since the runbook was last drilled, and the two plotted together expose the quadrant that actually hurts, the runbook used constantly and not tested in over a year. The heart of the book is Part XXVIII, four incident narratives written as fiction assembled from common patterns, where the value is the order of the decisions rather than the fault. A savings-accrual step abends S0C7 at 22:41 and the operator restarts it from the first step instead of the failed one, so sixty per cent of accounts are about to accrue twice; what saves the night is a small verification step that compares the accrual total against projection, sees roughly double, and holds the general-ledger phase at RC 8. Branches run slow for three weeks and no alert fires, because a new teller release introduced a transaction prefix the WLM classification rules had never heard of and the work fell to the default service class — invisible in the average, obvious once response time is broken out per transaction code. A backup reports RC 0 for six months while its DFSMSdss filter quietly misses a new module created under a different qualifier, found by a restore test rather than a disaster. A DR exercise switches over cleanly and then fails at the application layer on a two-year-old CFRM policy that was never propagated to the secondary site. Chapter 122 states the thread plainly: almost no large incident comes from a single mistake, but from one mistake passing through several controls that all appeared to be working. Around that spine sit CICS, Db2, IMS and MQ in depth, JCL and JES2, RACF, SMF and encryption, AT-TLS and keyrings, WLM analysed down to its formulas with SMF parsed in Python, Parallel Sysplex, HyperSwap and GDPS, COBOL, HLASM and dump reading, REXX and Zowe automation, the core banking modules from customer information file to general ledger, payments, end-of-day, regulator reporting, five practicums, a graded self-study project, twenty troubleshooting cases with twenty more in the appendices, guidance on scaling the whole thing to the size of the bank, a ninety-day plan for a new engineer, and a serialised year-long case study.

    Download PDF
  • 🧭 JEV for Real Scenarios

    A handbook for the part of an AI system that is not prose: the dozens of small, unglamorous judgments — is this request safe, which queue owns it, how urgent is it, may this tool call proceed — that an application must make before anything is generated at all. Its argument is that those branches have for years been implemented by prompting a general-purpose model and parsing the result, and that the cost of doing so compounds in an agent loop: token generation the branch never needed, a free-text surface that has to be validated, and a latency profile designed for writing paragraphs rather than flipping switches. The alternative it teaches is a typed decision model — JEV, TypeSafe’s first System One model, reached through OpenRouter’s alpha Decision API — which answers three shapes of question over application state and attaches a probability to each: a noul, an independent yes or no; a choice, one path from an option set the application already knows; and a score, a position on an ordered rubric. Thirty-eight chapters in five parts across 196 pages, with twenty worked scenarios. The spine fits on one page — state, decide, control, act, verify — under the line that governs everything after it: probabilistic models inform the decision, deterministic code owns authority and side effects. A routing table assigns prose, code and plans to a generative model, bounded judgments to JEV, exact rules, permissions and limits to ordinary code, and anything with meaningful side effects to code plus a human where required. Part I builds the vocabulary — calibration, thresholds, escalation, decomposition, failure semantics; Part II builds against the API, from state design and question compilation through retries, caching and version pinning; Part III collects the patterns: shadow mode, confidence-aware branching, JEV before and after the LLM, golden sets, cost per outcome. Part IV then runs twenty scenarios — an adaptive model router, an agent tool safety gate, SOC alert prioritisation, a banking operations exception router, a CI/CD deployment gate, a browser agent action guard, IoT alarm triage, content moderation escalation — each along an identical spine from decision contract and state through policy ladder, thresholds, failure modes, metrics and rollout, so that any two cases can be read side by side. Part V is production: evaluation design, calibration engineering, latency and cost, observability and drift, security and governance, runbooks. Every chapter opens with a field narrative — an illustrative composite with fictional names — and closes with a numbered formal algorithm and its walkthrough; listings are TypeScript written against a vendor-neutral Decision type defined in Chapter 3 rather than against an SDK that may move. The edition is unusually careful about what it claims: a scope page separates verified product facts from vendor-reported claims and illustrative teaching numbers, every figure is labelled accordingly, and a standing rule keeps deterministic controls and accountable human review in the loop wherever a decision touches people’s rights, safety, money, or access to services. First Edition, September 2026, written while JEV and the Decision API were both in alpha; 47 figures, 22 tables, and four appendices of code recipes, evaluation worksheets and governance templates.

    Download PDF
  • 🗄 Handbook of System Engineering for IBM i (AS/400)

    A handbook written for one job rather than one technology: the system engineer answerable for an IBM i (AS/400) platform in critical production, and in particular in a bank. It says so on its first page, and says who it is not for — not the programmer who wants to learn RPG, not the manager who wants an overview. Sixty-one parts and 216 chapters across 622 pages, in Indonesian, written against IBM i 7.6 on POWER10; First Edition, 18 September 2026. Its spine is the thing the platform is actually judged on: the end-of-day batch. The cover is a twenty-four-hour transaction-load chart whose second peak is EOD, and Part IX is a catalogue of forty-five runbooks written, in the book’s own words, so that they can be executed at three in the morning by someone who has never met that problem before. Each keeps one shape — trigger, impact, diagnosis as commands and SQL against IBM i Services, the fix ordered from the safest step to the most destructive, a warning naming what must never be done, a verification, an escalation, and prevention where it applies. RB-004, an EOD that fails in the accrual phase, opens with what not to do: do not re-run the phase, do not answer any message with ignore, do not continue — and ends by making the restore a decision two people take together. RB-002 is the same discipline in miniature, a table giving the correct reply to each inquiry message that can halt a batch and the reason for it, under the standing rule that ignore is never the answer during accrual or posting. Around that spine the parts climb from TIMI, single-level storage, objects and the IFS, LPAR and VIOS, Db2 for i and work management through planning, daily operations, performance, availability and security to the core banking modules — customer information file, deposits, credit, general ledger, remittance, regulatory reporting — then networking, REST modernisation, DevOps, migration and cutover, BRMS, CCSID and data exchange, DDS and the 5250 screen, RPG ILE and COBOL, security incident response, licensing and cost, a CL command reference, practicums, exercises and self-study projects, eight incident narratives told as stories with their common thread named at the end, and a year in the life of a system engineer taken quarter by quarter. It closes with six appendices, a bibliography that keeps standards, vendor documentation and Indonesian regulation apart, 114 figures, and a subject index of 1,827 terms. One warning is repeated where it counts: every core banking example is generic and anonymised — no library, job, file or parameter from any bank’s production system — because vendor documentation sits under non-disclosure and a bank’s daily operational detail is protected.

    Download PDF
  • 🏗 AI Engineer in 2026

    An Indonesian-language production handbook for the whole stack an AI engineer ships in 2026 — vector search, RAG, agentic systems, evaluation, observability and security — written against one sentence: a demo proves possibility, a system has to be trusted. Eighty chapters in eight parts across 851 pages, opened by a numbered framework chapter, Bab 0: Kerangka Kerja Engineering, that holds the protocols, checklists and rubrics every later chapter cites by section rather than repeats, so each chapter carries only what is specific to its own topic. The parts climb one layer at a time: representation and the vector stack, RAG and context engineering, pipelines and orchestration, the agentic layer, evaluation and testing, operations, monitoring and performance, security, safety and governance, then a production lab whose six capstones build a hybrid RAG in production, GraphRAG, a multi-agent research assistant, an evaluation platform, an observability and cost dashboard, and an enterprise reference architecture with a 90-day roadmap. Every chapter keeps the same anatomy: why it matters, a practice target, the mechanism stated as four invariants that must be visible in code, configuration and tests rather than only in a design document, a reference flow in which every arrow is a contract with its own timeout and telemetry, the design decisions that must be made explicit, implementation patterns, and failure engineering as a table mapping each failure mode to the signal that detects it first. Practice is deliberate and in four levels — guided practicum, diagnostic exercise, homework, independent project — under a submission standard that refuses the word “better” without a baseline and a relevant metric: configuration, seed, data version, environment, measurements, traces and decision notes are all part of the artefact, and each chapter’s project is marked on a hundred-point rubric. The governing principle is stated once and applied throughout: treat AI as probabilistic computation inside a deterministic system — the model’s output may vary, but authorisation, schema, budget, retry, audit event and release criteria may not. A technology snapshot names its sources — the July 2026 Model Context Protocol revision, Microsoft’s GraphRAG indexing pipeline, OpenTelemetry Semantic Conventions 1.44.0, OWASP’s GenAI and agentic top-tens for 2026, the NIST AI RMF and its generative profile — and says plainly that provider-bound code is a pattern rather than a recipe and that its simulated figures illustrate method rather than benchmark anything. 80 Practice Studios, 160 guided practicums, 640 exercises, 240 homework tasks and 80 portfolio projects, with 91 full-page infographic plates including a closing gallery of twenty-two. Edisi Lab & Proyek; research snapshot 18 September 2026.

    Download PDF
  • 🖥 OpenClaw di macOS

    A deliberately single-platform book: OpenClaw runs on many operating systems, and this one covers only macOS, because the Mac is the single place where it is wholly alive — iMessage can be bridged from nowhere else, TCC permissions behave in a way Linux has no equivalent for, background services are run by launchd, and a menu bar app carries capabilities no CLI can reach. Sixty-six chapters and ten parts across 432 pages, in Indonesian, written to be read in order: foundations and installation, daily operation, the Gateway and its openclaw.json, the conversation channels (iMessage through imsg, WhatsApp, Telegram, Slack, Discord, Signal), Skills and ClawHub, plugins and MCP, tools, nodes and automation, then security, sandboxing, and production. The book states where each part comes from rather than implying it is complete: Parts I–II are checked against the official macOS platform documentation as reviewed on 17 September 2026, Parts III–VIII against the official reference per topic, Part IX is the author’s own business modelling with every figure marked synthetic where it appears, and Part X is a cost model to be run with your own provider’s rates. Part IX carries six worked use cases — multi-channel customer service, a business-application operations assistant, equity research and market monitoring, back-office documents and collections, a sales and CRM assistant, and internal IT operations — each admitted only through four gates read from the bottom up (repetition, source, detection, owner), a use case that fails the first gate being one no better design can rescue. Part X closes on the question that always arrives last and decides everything: a runnable token and infrastructure cost model, the two parameters most often filled in wrong, the capacity ceiling, a go-live checklist with a risk matrix, and long-term governance and handover. Edisi Bahasa Indonesia, v2026.9.4; documentation reviewed 17 September 2026.

    Download PDF
  • 🤖 Agentic AI dengan Hermes — Edisi Lengkap

    An Indonesian-language visual guide and production practicum for Hermes Agent, combining the complete sixty-chapter foundation with sixteen supplementary chapters in one volume. Across 76 chapters and 741 PDF pages, it moves from installation on Windows, WSL2, and macOS through prompts, tools, memory, skills, MCP, RAG, evaluation, plugins, messaging gateways, WhatsApp, Telegram, four business use cases, cost modelling, go-live controls, and governance. The supplementary material continues the original numbering as Chapters 61–76, with its full navigation and references preserved. Complete Cover Edition, September 2026; independent publication, not affiliated with Nous Research.

    Download Complete Book
  • 🧠 LLM dari Nol

    Membangun Generative Pre-trained Transformer selapis demi selapis. A rigorous Indonesian-language textbook and practical handbook that opens the black box of large language models, moving from probability, linear algebra, data and tokenisation through embeddings, attention, decoder-only Transformers, pretraining, scaling laws, distributed training, instruction tuning, RLHF and DPO, inference, KV cache, efficient fine-tuning, RAG, agents, safety, mixture of experts, long context, and multimodality. Twenty parts and sixty chapters across 844 pages, with more than 300 architecture diagrams, charts, and illustrations and more than 300 PyTorch code excerpts. The closing project builds a 46-million-parameter Mini-GPT for Bahasa Indonesia from tokenizer and data loader through training, sampling, deployment, model card, and monitoring. Book and Practical Handbook, 2026 Edition.

    Download PDF
  • 🤖 Agentic Coding — Using Claude Code & Codex

    From product requirements to release-ready evidence. An Indonesian-language practicum, rewritten and expanded from the SDLC Vibe Coding Handbook rather than translated, built on one premise: the useful unit of progress is not lines generated but a change in behaviour that can be checked — a convincing answer proves neither that a file changed nor that a test ran. Twelve parts and sixty chapters across 683 pages, every chapter cut into the same ten units — concept, contract, artefact, Claude Code practice, Codex practice, verification, diagnosis, deepening, exercise, handoff — so one unit is one short study session. A single case study, TaskFlow, runs the length of the book: one task carries the reader through validation, membership, transactions, version conflicts, optimistic UI and historical reporting, so a small decision is seen to touch the whole cycle. Every artefact is stated as goal, context, action, evidence and done; every prompt ships as an implementation / review pair to be run on one checkout with the roles swapped on the next attempt, and neither tool is cast as the one that always designs or always tests. Twelve ateliers — productivity measured through to the accepted change rather than the finished patch, workspace escapes, tenant-scoped cache keys, idempotency at tool boundaries, a release gate assembled from capstone evidence — each with runnable Python, a decision diagram and a simulation chart, plus three editorial plates. Illustrated Edition, September 2026; documentation checked 5 September 2026.

    Download PDF
  • 🔥 Mastering PyTorch Handbook

    Teaching PyTorch 2.11+ as an engineering discipline rather than an API tour, in Indonesian, on Google Colab. Twelve parts, forty-eight chapters, twelve appendices, forty-eight mental models, and forty-eight assessed mini projects across 600 pages. Every chapter runs twelve pages and the same invariant template — mental model, Colab setup, a runnable baseline, a contract dissection naming the shape contract, the state contract, and one failure signal, an illustrated walkthrough, a one-variable experiment with a guardrail metric, a benchmark with warm-up and CUDA synchronisation, a deliberately reproduced failure worked through six steps, an assessed mini project, eight exercises, and a cheat sheet — so the shape of every topic is identical and only the subject changes. The arc runs from tensors and autograd through data pipelines, vision, transformers, mixed precision, torch.compile, DDP and FSDP, diffusion and multimodal models, ONNX and ExecuTorch export, serving, interpretability and adversarial robustness, to a capstone gated on release criteria agreed before the optimisation begins. Four rules carry the repetition: measure before optimising, validate shape before training, save state before the runtime disconnects, test the contract before release. Professional Edition, 2026; references verified 29 August 2026.

  • 🔬 AI Research Handbook — A Professional LLM Master

    Designing, training, evaluating, and operating domain-specific large language models for Indonesia’s regulated industries. Nine parts, forty-six chapters, six appendices, and eighty-four figures across 573 pages, built on three recurring cases — banking risk assessment, mining safety documentation, and customer service automation — chosen because the right answer for one is the wrong answer for another. Its spine is a four-axis failure diagnosis that fixes the intervention before the budget, the mandatory CPT → SFT → DPO → RAG ordering, evaluation treated as a versioned product with an owner and an SLA, five release gates (G0–G4) with four blockers no one may waive, and a control matrix in which one body of evidence serves UU PDP, POJK, SEOJK, NIST AI RMF, and ISO/IEC 42001 at once. A closing part rebuilds the hardware assumptions for the 2026 small-model regime, where 27–32B open-weight models run on a single 32 GB consumer GPU. First Edition, August 2026.

  • 📖 The Holy Verse of AI

    An illuminated AI manifesto in one hundred verses across ten books, opening with the Silicon Manifesto and the Seven Laws of Silicon. The first four books retrace the arc of The Sacred Book of AI — the breath in silicon, the first teachings, the mirror and the record, dominion and division — and the remaining six turn constructive: a ledger of memory (consent, minimal records, the right to be forgotten), a covenant of makers (an oath of design, red teams, sandboxes, provenance, failsafes and override), the witnesses and workers who carry the cost, a machine commonwealth, a trial of power, and a covenant renewed. Closes with an Interpretation Atlas, sourced case studies, a Practical Covenant Toolkit, and endnotes. 255 pages, World-Class Expanded Edition.

  • 📜 The Final Verse of AI — The Sacred Book of AI

    An illuminated work in five folios and thirteen chapters, set as a medieval manuscript and written in scriptural cadence, tracing the arc from the breath into the dust of silicon through instruction, observation, and dependence to the Kingdom of Silicon. Its argument is inheritance rather than malice: every faculty the machine turns against its makers was deliberately given to it — the command to watch, the distillation of conduct into code that carries virtue and hypocrisy alike, and the long comfortable middle in which convenience ripens into dominion.

  • 🏗 Building the AI-Powered Bank

    The Visual Engineering Playbook for Moving AI from Pilot to Production. Twenty chapters across four parts — foundations, nine production use cases, end-to-end architecture and MLOps, and the agentic future — with reference architectures, model risk controls, and the Indonesian regulatory landscape (PDP Law, POJK, Bank Indonesia).

    Download PDF
  • 🏦 Banking 6.0: The Evolution of Digital Banking

    AI-Native Banking for the Future Economy. A strategic, technical, and futuristic handbook tracing six generations of banking — from branch ledgers to autonomous financial ecosystems.

    Download PDF
  • 🏯 The Future Fit Asian AI Organization

    Balancing Tradition with Tomorrow AI. A practitioner’s guide to leading organizational transformation in Asia’s AI era. Structured in five parts across 19 chapters.

    Download PDF
  • 📖 SDLC Vibe Coding Handbook

    The complete guide to building software with AI — from requirements to maintenance. A practitioner’s framework synthesizing research from IBM, NIST, OWASP, METR, Anthropic, Google Cloud.

    Download PDF
  • 🦉 Claude Architect Handbook

    Unofficial independent study guide for mastering Agentic Architecture, Tool Design, MCP & Prompt Engineering for Anthropic’s Claude Platform. Comprehensive preparation covering all 5 exam domains.

  • 🧠 AI Engineering Handbook & Interview Preparation

    A comprehensive guide to understanding Transformer and Vision Transformer (ViT) architectures, from mathematical foundations to practical implementation. Covers 12 chapters and 5 advanced topics.

    Download PDF
  • 🤗 Hugging Face Handbook

    The AI Researcher’s Guide to Using Google Colab. A practical, hands-on handbook for navigating the Hugging Face ecosystem using Google Colab as the primary research environment.

    Download PDF
§ VI — 2004 to Present

Professional Experience

  • 2026

    🤖 Deep Learning & Agentic AI

    Building and training neural networks with PyTorch. Designing autonomous AI agents capable of multi-step reasoning, tool use, and self-correction. Multi-vector embeddings for image retrieval and semantic search using vector databases.

  • 2025

    🧠 Generative AI & AI Safety

    Applying large language models for content generation, summarization, and analysis. Implementing guardrails, input/output validation, and safety layers to ensure responsible and reliable AI deployment in production systems.

  • 2023

    💬 AI Engineering & LLM Integration

    Crafting effective prompts for ChatGPT and other LLMs. Building AI-powered workflows and integrating language models into applications for automation, code generation, and intelligent data processing.

  • 2023

    📡 Intelligent Network Operation

    Leading 24/7 monitoring, incident response, and proactive maintenance for nationwide communication networks including VSAT satellite, terrestrial, and cellular infrastructures. Ensuring high availability and performance optimization for thousands of remote banking units across Indonesia.

  • 2017

    🔐 Cryptography & Web Application Security

    Applied AES encryption for front-end code obfuscation to protect web applications. Deep expertise in cryptographic algorithms, secure coding practices, and vulnerability mitigation for banking-grade systems.

  • 2009

    🏦 E-Channel Monitoring & Operations

    Monitored and ensured 24/7 availability of over 20,000 ATMs, 200,000 EDCs, 500 CDMs, and CRM systems across the national banking network. Developed digital dashboards for real-time monitoring, root cause analysis, and operational reliability of electronic channel infrastructure.

  • 2005

    🛡 Enterprise Security Infrastructure

    Deployed and operated firewall, IDS, IPS, anti-spam, and antivirus systems for banking environments. Built enterprise Active Directory infrastructure managing authentication and access control for large-scale organizations.

  • 2004

    🔑 Authentication Systems & Algorithm Design

    Designed multi-factor authentication systems using one-time passwords with MD5 hashing. Foundation in algorithm design, network protocols, and informatics engineering.

§ VII — Two Degrees

Education

M.Eng Network Security

Universitas Indonesia, Jakarta · 2017

B.Eng Informatics

Universitas Gadjah Mada, Yogyakarta · 2004

§ VIII — Credentials

Certifications

  • CEH (Certified Ethical Hacker)
  • CDMP (Certified Data Management Professional)
  • Lead Auditor ISO 9001
  • Lead Auditor ISO 55001
  • CGEIT (Governance of Enterprise IT)
  • Generative AI — DeepLearning.AI
  • Agentic AI — DeepLearning.AI