I feel like I'm getting better. I'm limiting myself to 4 agents at a time and still maintain trad dev workflows so I don't miss anything. For me its like working with a dev that's much better than me and I'm watching , reviewing and learning. I still control the workflow so it doesn't get away from me and i layer agents throughout the workflow to check each others while i go. Reading so many post about how much devs are putting out comparatively made me worry at first, but I find that focus and control is doing me well. that's why no more than 4 agents at a time. That give me the bandwidth to review and learn as the base code is being written. I don't have any more bandwidth in me....but then again I have launched 4 open source projects in 1 week so.....
Before you launch your vibe coded project, run this prompt first:
“Perform a comprehensive audit of the application, covering security, reliability, concurrency, accessibility, and UI consistency.
Review the relevant codebase, architecture, data flows, API interactions, authentication and authorization logic, state management, async operations, error handling, and user-facing interfaces. Trace important flows end-to-end rather than reviewing files in isolation.
Specifically investigate:
Security vulnerabilities and data exposure
- Authentication and authorization flaws, including missing server-side permission checks, privilege escalation, insecure direct object references, and cross-tenant data access.
- Sensitive information exposed through client-side code, environment variables, API responses, logs, analytics, URLs, local storage, session storage, cookies, error messages, or source maps.
- Injection risks, including SQL, command, template, prompt, HTML, and script injection where applicable.
XSS, CSRF, SSRF, insecure redirects, unsafe file uploads, path traversal, weak session handling, insecure token storage, and missing security boundaries.
- Overly permissive database rules, API endpoints, CORS policies, storage buckets, webhook handlers, or third-party integrations.
- Secrets, API keys, credentials, internal endpoints, personal data, or implementation details that could be unintentionally exposed.
- Missing validation and sanitisation at trust boundaries. Do not assume client-side validation is sufficient.
Race conditions, concurrency, and state integrity
- Duplicate submissions caused by repeated clicks, retries, refreshes, or concurrent requests.
- Non-idempotent operations that can create duplicate records, payments, messages, bookings, jobs, or side effects.
- Stale state, optimistic update failures, lost updates, conflicting writes, and out-of-order async responses.
- Effects, subscriptions, listeners, timers, and requests that are not correctly cleaned up.
- UI states where actions remain available while an operation is already in progress.
- Cache invalidation problems and inconsistencies between client state, server state, and persisted data.
- Multi-tab, multi-device, and poor-network scenarios where relevant.
Reliability and failure handling
- Unhandled promise rejections, swallowed errors, silent failures, infinite loading states, broken retry loops, and incomplete rollback behaviour.
- Missing loading, empty, error, offline, timeout, and partial-success states.
- Failure paths that leave data or the UI in an inconsistent state.
- Assumptions about API responses, nullability, ordering, timing, or network availability that could cause production failures.
- Memory leaks, unnecessary rerenders, expensive operations, and obvious performance bottlenecks that materially affect the user experience.
Accessibility
- Semantic HTML and correct use of landmarks, headings, labels, lists, tables, buttons, and links.
- Keyboard navigation, logical tab order, focus visibility, focus trapping, and focus restoration.
- Missing or incorrect accessible names, labels, descriptions, and ARIA attributes.
- Colour contrast, text legibility, touch-target sizes, zoom behaviour, reduced-motion support, and reliance on colour alone to communicate meaning.
- Screen-reader behaviour for modals, menus, dropdowns, tabs, toasts, validation errors, loading states, and dynamically updated content.
- Forms with unclear instructions, inaccessible validation, missing autocomplete attributes, or poor error recovery.
- Test against WCAG 2.2 AA expectations where applicable.
Visual and interaction consistency
- Inconsistent spacing, typography, colour usage, border radii, shadows, icon sizing, alignment, component dimensions, and responsive behaviour.
- Components that visually appear identical but behave differently, or behave identically but are implemented inconsistently.
1/2
Our thoughts on the importance of AI sovereignty.
1. Your AI sovereignty dictates your institution’s future. Sovereignty is the precondition for choice. Relinquishing sovereignty transfers the future choices of your institution to others, who are likely to exploit it for their gain and your loss.
2. Data retention is your treasure. Transfer it at your own peril. Your ability to win is dictated by your ability to recognize and use your unique edges, and you keep winning by compounding the underlying data to generate new insights. Transferring that data hands over access to your pre-existing winning plays and yields the means of production for new ones.
3. Tokenmaxxing hijacks your value orientation and decreases your institutional fortitude and intelligence. The pursuit of high token usage incentivizes disposable scripts over robust software — with the addictive feeling of false progress. There is a reason why those selling tokens refuse to charge based on value.
4. Controlling your weights is controlling your fate. Weights are the distilled form of hard-won, accumulated institutional knowledge. If you let others control your weights, you are allowing them to migrate the alpha of your business to theirs.
5. There is no contradiction between sovereignty and alpha. The architecture that maximally preserves sovereignty is one that enables institutions to own their tribal knowledge, and to compound it as alpha.
6. Politicizing the technical issues involving sovereignty is what your adversary wants. Techno-politicization is the wellspring of false sovereignty. Techno-politicization drives decisions that seem to reduce dependency, but ultimately limit agency — especially on the battlefield in the West.
7. Real expertise is existential. Allowing politics or favoritism to determine your technical decisions rewards whoever is best at politics, not whoever is right. Listen to those closest to the problems, not those speaking most compellingly about them.
8. Learn from institutions that are winning or that have consistently delivered. Institutions facing existential threats do not have the luxury of making technical decisions based on political preferences.
9. Only listen to institutions, countries, and people who have a proven record of being right. A track record of correctness is the best and only signal for future correctness. Judging something as right or wrong based on who you like is exceedingly misguided.
If they really start to gatekeep who gets to use the best models, that is a declaration of war.
This prospect fills me with the most sincere, bodily cypherpunk will-to-power that I've ever felt (at least since I was a teenager). If they really go down this route, I would go all-in on building the most psychotic swarms of open-source models and fine-tunes possible, all geared toward a Chaotic Good jamming of the entire institutional public sphere. If we didn't do that, all of political life and the marketplace of ideas would be over before we know it.
It's one thing if the top models become too expensive for me or others to use (I'm already pricing that in, and if you can't build something profitable enough to climb that ladder as it gets pulled up, then that's fair enough).
But if the ladder gets pulled up politically, now, so only select institutional players get access to the most intelligent models, then any mature American man should be as energized as gun collectors are around the 2nd Amendment, or liberal women are around Planned Parenthood.