Skip to content
View PIsberg's full-sized avatar
🤖
🤖

Block or report PIsberg

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
PIsberg/README.md
T-800 heads-up display. PETER ISBERG. Guardrails for the machines that write the code. Power cell: Java 26. Location: Gothenburg, SE. Directive: no fate but what we compile.

Read the book deversity.se Email me

About

I am a software developer in Gothenburg, Sweden, working mostly in Java. My open source work keeps returning to one question: when AI agents write most of the code, what keeps the system correct?

My answers so far are annotations that fence off the code an agent must not touch, tests that force concurrency bugs to reproduce on demand, a local firewall against prompt injection, and a book about the architecture that holds it all together.

Ask me about Java, AI guardrails, static analysis, MCP servers, and why a green test suite is not proof.

The book

Cover of Vibe Coding Architecture at Scale Vibe Coding Architecture at Scale. Vibe coding gives you speed. Vibe Architecture gives you scale. When syntax is free, structure is your only asset. Get it on Amazon.

How it fits together

Eight of these projects are stations on one line: the path a change takes from an AI agent to production.

Pipeline from AI agent to production. Before it writes: skill3 teaches the agent current skills, llm-fw filters prompts before the model. While it writes: vibetags fences off code it must not touch, axiom shows what a change just broke, ghost-mcp gives it hands on the desktop. Before it ships: codekoll runs static analysis for silent bugs, async-test-lib forces concurrency bugs to fire, codekarta maps what was actually built.

Open source

Guardrails for AI agents

vibetags: Java annotations as AI guardrails. Mark the code an agent must not rewrite, and it stops rewriting it. Works with Claude, Cursor and Codex. llm-fw: Local prompt injection firewall. Malicious prompts are blocked and logged, clean ones pass through. axiom: The codebase as a live queryable graph, so an agent can see what it just broke. skill3: Relearns a technical skill for an agent, anchored to a target model cutoff, and vets the result. ghost-mcp: MCP server that exposes OS level UI automation to AI clients.

Java correctness and analysis

async-test-lib: Forces concurrency bugs to happen using synchronized barriers, then names the one that fired. codekoll: Static analyzer for Java that finds the bugs which compile perfectly and detonate in production. codekarta: Parses Java source and emits SVG maps: call graphs, exception flow, state machines. blindbean: Homomorphic encryption hidden behind ordinary Java objects and annotations.

Toolbox

Primary: Java, Spring Boot, Gradle, Maven. Also fluent: Rust, TypeScript, Go, Python. Platform and AI: Docker, GitHub Actions, Claude, MCP, Linux, IntelliJ IDEA.

Activity

GitHub contribution stats Repositories per language

Building with AI agents and want it to stay correct? Get in touch: isberg.peter@gmail.com

Pinned Loading

  1. async-test-lib async-test-lib Public

    @AsyncTest (async-test-lib) is an enterprise-grade test framework that makes concurrency bugs reproducible and detectable. Rather than hoping random thread scheduling will expose bugs, async-test f…

    Java 8 1

  2. vibetags vibetags Public

    VibeTags is a Java annotation processor that acts as AI guardrails for code generation tools like Cursor, Claude, Gemini, and Codex CLI. It allows developers to control AI behavior through simple a…

    Java 25 6

  3. bashful-cli bashful-cli Public

    Bashful gives your CLI tools a REST API — no code required

    TypeScript 5 1

  4. blindbean blindbean Public

    BlindBean is a developer-first Java 26 library that makes Homomorphic Encryption (HE) invisible to the end user. It allows you to perform secure, private arithmetic on encrypted data using standard…

    Java 4 1

  5. llm-fw llm-fw Public

    A local prompt injection firewall that intercepts traffic between your tools and every major LLM API before it leaves your machine. Malicious prompts are blocked and logged; clean ones are forwarde…

    TypeScript 6 1

  6. skill3 skill3 Public

    Skill3 is a lightweight Java CLI that relearns a technical skill for an AI agent. It discovers documentation sources, scores them for authority and freshness (anchored to a target model's knowledge…

    Java 6 1