What's your test for telling a vendor from a partner?
(we build our own stuff too - Canopy, free + source-available, because we run 10+ AI coding agents a day 👇)
yes, a warning before opening file:// executable links is reasonable.
calling it RCE is where it gets silly. if the chain is "render a clickable link, user holds ctrl, user clicks it, OS opens the target", that’s not remote code execution. that’s delegated user execution with bad affordances
it’s wild how different OpenAI and Anthropic feel as products right now.
OpenAI: "we had a good week, here are more limits, go build"
Anthropic: "we noticed you are using your paid subscription in a suspiciously subscription-like way. here’s a ban, please fill out a google form. talk soon, probably never"
same market, completely different relationship with users
Don't just reset Codex rate limits for fun, it costs money.
Don't just reset Codex rate limits for fun, it costs money.
... but the vibes are good ...
I have reset Codex rate limits for ALL paid plans to celebrate a good week and allow everyone to build more with GPT-5.5. Enjoy
@jahirsheikh8 "reviewing AI output" is doing a lot of work here.
someone still has to understand the system, design the architecture, catch subtle bugs, reject bad tradeoffs, and own the result in production
this is actually insane. especially if you know that the guy, Łatwogang, who started it all said he thought he will raise maybe 500k 🥹🩷
#CancerFighters
@shadcn every time. pointer cursor is an affordance signal. browser users have 25 years of muscle memory telling them "this is clickable" - no reason to fight that