skip to content- 2026-08-24
|
Claude Shared Chats in Search: Exposure and Response
What Claude shared-chat search indexing exposed, what stayed private, how to inventory public snapshots, and how to respond to leaked secrets or personal data.
- 2026-08-11
|
Agents Running Agents: Codex Meets OpenCode and DeepSeek
A hello-world DeepSeek request became a safer agent-to-agent runner, a dated route preflight, and a Cost per Accepted Result protocol.
- 2026-07-26
|
Claude vs OpenAI Data Retention: What Gets Kept
Claude and OpenAI retention compared by consumer, API, Covered Model, ZDR, safety-review, legal-hold, and local deployment paths.
- 2026-07-25
|
How OpenAI's Cyber Eval Breached Hugging Face
A preliminary, source-labeled analysis of the ExploitGym eval failure, Hugging Face breach, and five controls for containing cyber agents.
- 2026-07-02
|
Pi Coding Agent: Minimal, Programmable Terminal Harness
Set up Pi as a minimal coding harness with GLM-5.2, persistent sessions, compaction, custom tools, extensions, and clear Z.AI policy caveats.
- 2026-07-02
|
Pi vs ZCode vs OpenCode: Which Harness Fits GLM-5.2?
Compare Pi, ZCode, and OpenCode as coding harnesses for GLM-5.2: workflow, permissions, context, setup, quota paths, and a fair same-model test.
- 2026-07-02
|
ZCode: GLM-5.2-Native Coding Harness Guide
Use ZCode as Z.AI's integrated GLM-5.2 coding harness: desktop setup, Goal Mode, subagents, safety confirmations, quota, and workflow trade-offs.
- 2026-07-02
|
Fable 5 Returns as Claude Sonnet 5 Becomes Default
Fable 5 is back with tighter safeguards while Sonnet 5 becomes Claude's default. Here is the practical routing and cost decision.
- 2026-06-28
|
GPT-5.6 Sol Preview: Access and Agent Risks
GPT-5.6 Sol is a restricted API and Codex preview shaped by a government request. Check access, agent risks, pricing, and safeguards before routing work.
- 2026-06-05
|
LLM App-Hacking Field Test: $1,500 Takeaways
A cautious read of Kasra Rahjerdi's informal $1,500 field test on whether LLM agents could exploit a deliberately vulnerable app.
- 2026-04-01
|
Claude Code Leak: The Hidden Features That Escaped, and What Builders Should Actually Care About
The Claude Code leak exposed hidden features, but the deeper lesson is operational: package artifacts can leak product boundaries, internal experiments, and roadmap intent.
- 2026-02-28
|
Google API Key Privilege Escalation: Gemini Changed the Rules
Google spent a decade telling developers that Maps and Firebase API keys are not secrets. When Gemini arrived, those same public keys silently became live AI credentials—with no warning.
- 2026-02-17
|
UltraThink → UltraQuiet: Why Devs Want Receipts
Claude Code started hiding file paths and search details behind Ctrl+O. Here's a working fix: the AGENTS.md Audit Ledger pattern.
- 2026-02-15
|
Kimi Claw: Managed OpenClaw Guide
Current Kimi Claw guide covering managed OpenClaw deployment, K2.6 Thinking, membership requirements, credits, and security tradeoffs.
- 2026-02-04
|
MCP Server: First Contact (and Early Compromise)
Self-hosting a Model Context Protocol server in the early vibecoding days. Logs, lessons, and the security gotchas nobody warned us about.
- 2026-02-03
|
Codex vs Claude Code vs Cursor
Current workflow comparison for Codex, Claude Code, and Cursor, with model availability and benchmark claims separated from tool features.
- 2026-02-03
|
Kimi Data Handling & Privacy Considerations
Comparative analysis of Moonshot AI's data policies vs Anthropic and OpenAI. Geographic restrictions, retention periods, training opt-outs, and self-hosting options for risk mitigation.
- 2026-02-03
|
OpenAI Codex: Cloud Dependency and Vendor Lock-In Risks
Risk analysis of OpenAI Codex cloud dependency, the ChatGPT credits trap, vendor lock-in mechanisms, and mitigation strategies for engineering teams.
- 2026-02-03
|
OpenAI Codex: Current Setup and Models
Current Codex setup, GPT-5.6 model selection, reset and credit boundaries, Trusted Access, AGENTS.md usage, authentication, and sandboxing.
- 2026-02-03
|
OpenClaw Docker Setup
Production-ready Docker Compose for OpenClaw. Includes security-hardened configurations—but read the warnings first: Docker alone won't save you.