Frank Xue — software engineer, mostly Rust
Building auditable tools for code, systems, and agents.
Independent work across repository context, cryptographic software, and local developer infrastructure — with release state, evidence, and limitations kept explicit.
Review selected work(02) About
A short version, for the impatient.
In a sentence
I'm a software engineer who cares about clarity: code that can be audited, tools that explain their state, and interfaces that do not make routine work feel mysterious.
Read the longer version(03) Selected work
Outcomes, mostly in Rust.
-
gm-crypto-rs
Pure-Rust SM2 / SM3 / SM4 SDK with constant-time-designed secret paths and in-CI leak-regression gates. Public v1.11.0 is on crates.io. Read more →
-
RepoLens
Repository context and typed memory for AI coding agents, built to help sessions restart with grounded project understanding. Private pre-release — source not public today. Read more →
-
ghrunners
One-shot macOS observability for GitHub Actions self-hosted runners — launchd state, process trees, logs, and API status as typed findings — plus guarded launchd control. Private/local today. Read more →
-
Explainer Engine
A deterministic pipeline that renders narrated concept videos where every on-screen claim is verified against the source at a pinned commit before a frame is drawn. Private/local. Read more →
(04) Notes
Latest notes.
-
A constant-time claim is a trust problem, not a comprehension problem
Explaining constant-time execution is the easy part, and it isn't what a skeptical reader needs. What transfers warrant is a leak detector that must fail on ... Read →
-
Skipping the releases that change nothing
A published version is a promise about bytes, not a diary of work. Here's why some of gm-crypto-rs's hardest cycles were never published at all. Read →
(05) Contact
Say hello.
Direct
GitHub is the most direct way right now — @frankxue831. An issue or discussion on any of my repos reaches me too.
Other ways to get in touch