John Wu

R&D Team Lead · Full-Stack Engineer · AI Code Review & LLM Tooling · ESG SaaS

Ten years of shipping systems into production: government, IoT, healthcare, SaaS. The last two went into AI code review and LLM tooling. The project I still talk about is WiSide. On New Year's Eve 2020, 15 of its scanners counted 113,000 people walking through Taipei.

About

I've built systems in government, IoT, healthcare and SaaS. WiSide is the one I'm proudest of: a crowd intelligence platform whose application and output layers I wrote alone from scratch, running on 314+ scanners across Taiwan by 2021. Twice I've been invited into a founding engineering team by people who had already worked with me for years, which I read as a better signal than anything a CV can carry. My work now sits where AI meets engineering process. At work I built the AI code review platform that runs in our CI, and I'm still its only maintainer. Outside it I open-source an agent orchestration framework and the tooling around it.

0
People detected, NYE 2020
0+
WiSide scanners deployed
0
Peak team size (5–12 through reorgs)
0+
Years shipping production systems

Technical Skills

Backend

Node.js (NestJS)TypeScriptRESTful APIMicroservicesPHP (Laravel)ASP.NET (C#)PostgreSQLMySQLRedis

AI / LLM

LLM IntegrationPrompt EngineeringRAG / Hybrid RetrievalAgent OrchestrationClaude CodeAI Code ReviewSDD

Frontend

JavaScriptTypeScriptHTML5CSS3Tailwind CSSAstro

DevOps / Cloud

DockerKubernetes (K8s/K9s operations)Terraform (IaC)GitLab CI/CDGitHub ActionsGCPAWSAzure

Tools & Practices

GitCode ReviewAgile/ScrumSystem DesignOpenAPI v3.0Cross-functional Collaboration

Experience

  1. R&D Team Lead

    Cedars Digital May 2024 – Present
    • Leading an R&D team through the company's v2.0 platform rewrite (in progress). Team size ranged 5–12 engineers (FE, BE, Singapore remote) across multiple reorgs. Every reorg meant rebuilding the team's working rhythms from scratch, and the team kept shipping through all of them. Now I am coaching every member toward full-stack ownership.
    • Backend developer for the supply chain management system in the v2.0 rewrite: milestone planning with the PO, and integration with the frontend team and two other product lines through OpenAPI v3.0 interface contracts. Together with the software development manager I introduced Specification-Driven Development (SDD) and implemented the spec-kit → contract → integration flow that carried an architecture-level redesign. I built and still maintain the cross-product contract layer alone (40+ interface YAMLs).
    • 2025-08 · AI code review v1.0 released into GitLab CI/CD. Config-driven from day one: shared and system-specific review standards compose into a prompt, a new service onboards by registering in config with zero code changes, and the LLM sits behind a pluggable provider layer.
    • 2026-04 · v2.0 added a self-reflection pass and rolled out across frontend and backend microservices repos. Two internal survey rounds showed most engineers modify code on its suggestions before merging, with reliance growing each iteration.
    • 2026-08 · v2.1 added a production retrieval layer: a self-built embedded vector store with hybrid BM25 + embedding ranking.
    • 2026-08 · The standards knowledge base I had seeded months earlier paid off for the first time on a live team question: for the HCFC-22 emissions-classification problem, I dispatched an AI agent into its GHG Protocol Corporate Standard text (ch. 4 & 9) and it dug out the answer — compute the true value, exclude it from the total per the standard, disclose it separately. The same sentence of the standard requires both computing the value and keeping it out of the total.
    • 2026-07 · Upgraded the backend stack (NestJS 9→11, Node 24, TypeScript and Jest 30), resolving version-pinning issues across the repos.
    • 2026-06 · Selected and rolled out the team's frontend technical design-doc standard, a 10-section template with 4 standard diagrams, enforced by a validator.
    • 2025 · Convened the annual Infrastructure-as-Code initiative, codifying the existing GCP architecture into Terraform under GitLab version control.
    • 2024–now · Built an internal engineering knowledge base holding onboarding, system architecture, environment setup, and internal tech shares in one place. It started as a way to stop answering the same questions twice. New engineers actually rely on it now.
  2. Sr. R&D Engineer

    Cedars Digital Aug 2023 – Sep 2024
    • A technical lead I had worked with before brought me in as one of the founding backend engineers, to build the carbon footprint and emissions management SaaS platform from scratch (Node.js, Nest.js, PostgreSQL, Redis, GCP). v1.0 shipped and reached multiple enterprise clients.
    • Promoted to Team Lead in May 2024. The contract title was updated a few months later. The work stopped being only about writing code and started being about the people writing it too.
  3. Sr. R&D Engineer

    Taiwan Data Science Co. Aug 2018 – Mar 2022
    • My manager at Alliance Digital Technology recruited me to help start the engineering team. I was one of the first engineers in the door.
    • Built WiSide's application layer (Laravel + Vue.js management backend) and output layer (real-time crowd dashboard + event reports) solo; the edge scanners and the ELK pipeline were team work. Sitting on the boundary between two layers I did not control forced a discipline I have kept ever since. Define the interface contracts first, then let both sides evolve against the contract. The scanner protocol and the ELK query schema were versioned independently, so when the ELK team upgraded the server, the change stopped at the interface layer and application logic never moved. By Sep 2021 there were 314+ scanners across Taiwan; 20 of them detected 55,000 attendees at a 2019 political rally, and 15 counted 113,000 people at Taipei's 2020 New Year's Eve. Featured at 22+ exhibitions.
    • Constituency management system for a New Taipei City legislator, holding 39,600+ constituent records and 100+ field visit logs (Nov 2019 – Jul 2021), with Excel import/export and an iOS app backend.
    • Douzo!, an e-commerce platform run with Chunghwa Telecom and local governments in Yunlin, Chiayi, and Tainan, connecting farmer-producers directly with consumers. I built the shopping-cart frontend with three other engineers, then took over its merchant accounting platform frontend and finished the remaining features.
    • MND access-control system, integrating hardware from 4 vendors across multiple bases nationwide.
    • Beigang Hospital questionnaire system. Separate database layer, redesigned questionnaire UI.
  4. R&D Engineer

    Alliance Digital Technology Sep 2017 – Aug 2018
    • My manager at iPanSec referred me into a mobile-identity venture founded by Taiwan's National Development Council, five major telecom carriers, and EasyCard Corp. There I built ADTC-IFI, a full-stack vending machine sales visualization platform that pulled sales data out of an ELK backend and put it on a dashboard (Laravel + jQuery + GCP). I developed the site solo, working with two data engineers. I also wrote a PHP sample API and its usage docs for Mobile Connect, the company's mobile-identity product, then integrated a partner manufacturer's product with it for the press conference launch demo.
    • I left when my direct manager moved on to start Taiwan Data Science Co. and brought me along.
  5. R&D Engineer / Software Engineer

    iPanSec · TanoSecure · Gapertise Dec 2015 – Aug 2017
    • The kind of work I have kept coming back to across my career. Build the system that drives someone else's tools, then turn their output into something a business can use.
    • Three entities, one technical founder. The core team stayed together as he became CTO at the latter two.
    • Built A4P, a full-stack APK security analysis platform. A Python subprocess calls a local MobSF instance to analyze Android APK files, and a web crawler, which I built with two crawler engineers, scrapes the generated report pages and reformats the data into structured security reports. A4P played a key role in the company's security-lab certification. A decade later at Cedars I reused that same architecture for AI code review, with an LLM API where MobSF used to sit.
    • Delivered the MJIB IP blacklist management system, integrated with hardware network management equipment and visualizing data out of an ELK backend.
    • Led a team of 4 engineers (FE + BE) building an IoT device marketplace. I rewrote a customized Node-RED build solo (login, localization, custom nodes) and integrated a partner library into it, so the platform could drive LEDs, ultrasonic sensors, and buzzers directly.
  6. Software Engineer

    Weshine Technology Dec 2012 – May 2015
    • First job out of university, and I spent nearly three years of it embedded on-site at Chunghwa Telecom, working on MVDIS III, the government's motor vehicle information system (ASP.NET / C# / MSSQL / Informix). My piece was the image management subsystem. The original contract specified a Windows app only; when the client later asked for web access, I built the subsystem's web features solo. Everything around it came with the job too. SA/SD documents and operation manuals, image-recognition hardware testing (scanners, cameras), QA, QC, customer support, and integration work that meant aligning specs and interfaces with 20+ engineers across 12 vendor companies. Separately I contributed to a self-service kiosk project and built the company's website.
    • This is where I learned what shipping software at scale with a team actually costs, and that QA is not the part you cut.

Featured Work

Side Projects

MRInspect

A CLI that reviews GitLab merge requests with an AI model, written in pure Go. It runs as a non-blocking CI job: reads the diff, loads the team's own review standards, and posts one structured comment back onto the MR.

253 test functions run green under `go test -race`, and it ships as a GitHub Release plus a GHCR container image, so a team adds one job to `.gitlab-ci.yml` and is done. Prompts are the part unit tests can't pin down, so there's an offline harness of 4 fixtures × 3 modes — a reproducible qualitative dogfood eval loop I re-run whenever I change one.

GoDocker
View on GitHub ↗

ReleaseGuard

Release gating at the MR level: four specialised agents inspect the diff in parallel, then an arbitration layer collapses their signals into one recommendation, HOLD or REVIEW or PROCEED.

The arbitration rules are the actual product, so the reasoning is written down: 21 architecture decision records, plus a false-positive feedback loop where GitLab labels feed back into HOLD precision, now measured by a replay harness over imported merged MRs. The first tagged release ships CI (go test -race, lint, a Docker smoke test asserting HOLD/REVIEW/PROCEED) and public GHCR images, and the arbitration layer fails closed to REVIEW when any agent panics or times out. Designed and fully tested; not yet run against live traffic.

GoGitLab MRLCOV callgraphDocker Compose
View on GitHub ↗

excelTemplateParser

Turns a pile of same-format Excel files into another format. You author the mapping once and reuse it; it runs on a single machine under Docker, with no login.

The queue turned out to be the hard part, not the parsing. An interrupted run reloads its state from Redis and still notifies the browser when it finishes, and 332 automated tests keep that behaviour honest.

ReactViteTypeScriptFastAPI
View on GitHub ↗

tlor-orchestration

A Claude Code orchestration framework built on one bet: pin model, effort and tools inside each role, so cost and permissions stop being a per-prompt decision. 14 Middle-earth agent roles, institution dispatch rules, a 3-lens adversarial review panel, opt-in guard hooks.

Dispatch is cost-tiered on purpose (haiku→sonnet→opus): volume work goes cheap, judgment goes expensive. Around that sit 6 institution rules with a plugin-owned/user-owned split, the rivendell-council adversarial panel, four opt-in hooks (verify-gate, institution-guard, dispatch-guard, stdd-test-guard), 14 skills of which 7 form an opt-in STDD spec-to-code pipeline, and CI via GitHub Actions. I drive it daily in my own Claude Code sessions.

Claude CodePythonBashMarkdown
View on GitHub ↗

phosphorpulse

The Rust rewrite of phosphorflux: same bytes out of the statusline renderer, plus a full-screen ratatui TUI. STDD spec to a released v0.1.0 in under two days.

Byte-parity with the TypeScript original was non-negotiable; 11 hermetic golden fixtures enforce it, and 64 tests run green on a dual-platform (Linux + macOS) CI matrix. cargo-dist ships four-platform binaries, and a built-in migrate command carries a phosphorflux config over. Warm render came out ~36-57x faster on local measurements (not a committed benchmark), and idle CPU at a 1s refresh sits near ~0.7% of a core instead of ~25%.

Rustratatuicrosstermserde
View on GitHub ↗

phosphorflux

Themed statusline for Claude Code, built end-to-end with my own agent-orchestration framework and spec-driven TDD. Empty repo to npm-published in 3 days.

Retired and succeeded by the Rust rewrite phosphorpulse (https://github.com/twjohnwu/phosphorpulse), so what outlived the code was the process. 461 tests across 101 files, with more test LOC than src LOC, an ajv-validated config wizard that writes atomically into Claude settings, bilingual docs, and a spec→test→ship trail anyone can audit.

TypeScriptReactInkajv
View on GitHub ↗

video-to-transcript

Video and audio to transcript without anything leaving the machine: no API, no upload, ASR on the Apple Silicon GPU via mlx-whisper (Metal/MLX). It doubles as a Claude Code skill.

The part worth building was the hallucination guard: chunked transcription keeps Whisper out of its repetition loop. The VTT chunks then get merged and deduped, and OpenCC s2twp converts the result to Traditional Chinese.

mlx-whisperffmpegPythonClaude Code Skill
View on GitHub ↗

devutils-skill

Claude Code skill that hands text straight to DevUtils.app on macOS over the devutils URL scheme, so an AI CLI stops writing a throwaway markdown file every time.

The whole skill is four steps: classify the input, look up the tool ID, URL-encode, open. All 40 DevUtils tools go through that same path.

Claude CodemacOS URL schemeSkill markdown
View on GitHub ↗

Certifications