Trying to give shapes to old haunting [projects / visions /cryptic dreamscapes] of [misty forests / infinite corridors / labyrinthic cities] #sketchup#unity3d
More opensource goodness. We have just released a CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your code. Scan repositories, review changes, track findings over time, and run security checks in CI.
https://t.co/nkfTbw8p7b
前些天 X 上还一堆人讨论要不要看 AI 生成的代码,现在《Clean Code》作者鲍勃大叔都说:“我不看 AI 写的代码”
他的原话是,这是他能利用 AI 生产力的唯一方式。人类读代码太慢了,如果还逐行审查,就丧失了用 AI 的意义。
但不看不等于不管。他的做法是给 AI Agent 设置层层关卡:单元测试、Gherkin 测试(一种用接近自然语言描述软件行为的测试格式)、QA 流程、代码质量指标、变异测试(故意往代码里塞小错误,看测试能不能抓住)、测试覆盖率,等等。
他在今年早些时候还公开了自己的具体实践:一套四个 Agent 组成的流水线,分别负���需求规格化、编码、重构和架构审查,每个阶段都比上一个阶段更形式化,需要的人工干预也更少。他同时还会看测试覆盖率、依赖结构、圈复杂度、模块大小这些指标,从指标推断代码质量,而不是从代码本身。
【注:圈复杂度(Cyclomatic Complexity)衡量代码中独立执行路径的数量,数字越大说明逻辑越复杂,越难维护和测试。】
当 AI 生成代码的速度远超人类阅读代码的速度,代码审查的形态也在跟着改变。以前的核心能力是读代码、写代码,现在可能正在变成写测试、定约束、设指标。鲍勃大叔过去几十年一直在推测试驱动开发(TDD),现在 AI 时代高质量的测试覆盖反而比代码更有���值。
他今年在 O'Reilly 上开了一门课,叫《AI Agents for Clean Code》,也在自己的 Clean Coders 平台推出了新系列《Clean AI: Agentic Discipline》。主旨一样:AI Agent 不是不需要纪律,是需要不同的纪律。
img2threejs v1.3 is now available. 🎋
One photo → procedural Three.js code. No meshes. No manual modeling.
GitHub: https://t.co/0bqf4iS9rm
v1.3 brings major improvements to geometry reconstruction, material generation, validation, and overall output quality.
For this demo, I used the reference image of a CS2 ★ M9 Bayonet | Doppler Phase 3: https://t.co/8DflDWTPJ7
If you’re new to img2threejs, now is a great time to try it. If you’ve used it before, I’d love for you to compare the results with previous versions.
Feedback, bug reports, and PRs are always welcome.
ASK CLAUDE TO MAP YOUR ENTIRE APP'S ARCHITECTURE INTO A SINGLE HTML PAGE AND JSON FILE.
THE HTML IS FOR YOU.
THE JSON IS FOR THE NEXT AGENT WORKING ON A NEW FEATURE.
YOUR CODEBASE NOW EXPLAINS ITSELF.
One pattern I find useful for working with LLMs is a nice long ramble session. Sometimes the LLM needs more bits to understand what you're trying to achieve, but you're too lazy to type them. In these cases I like to lean back, switch to /voice and just ramble for like 10 minutes, total mess, anything goes, full stream of consciousness. Sometimes I declare it up top, something like "switching to speech recognition sorry for any typos...". Sometimes I turn it into a small interview of a few turns. But I find that the LLMs are somehow very good at reconstructing long incoherent rambles and often their echo of your own tangle of thoughts comes out quite a bit cleaner than what you started with. The result is that you improve the mind meld and have to correct things less from that point on.
Si tu n'as pas encore déserté WordPress pour un site pondu par une IA "en trois prompts", tu as peut-être un très gros problème à régler ce week-end, et pas la semaine prochaine.
Ça s'appelle wp2shell, et depuis vendredi ce n'est plus une hypothèse: Une requête HTTP anonyme, sans le moindre compte ni plugin, qui fait exécuter du code au serveur sur une installation par défaut. Le trou est dans le core, pas dans une extension que tu pourrais désinstaller pour dormir tranquille.
Il y a deux failles chaînées en réalité : une confusion de route sur l'endpoint batch de l'API REST, CVE-2026-63030, qui vient déclencher une injection SQL, CVE-2026-60137, et au bout du chemin une exécution de code à distance.
Versions concernées, 6.9.0 à 6.9.4 et 7.0.0 à 7.0.1.
Versions corrigées en 6.9.5 et 7.0.2.
Les deux CVE sont désormais publiques, le mécanisme complet est documenté, et tout le monde dans le métier dit la même chose : patch public plus core open source, la preuve de concept fonctionnelle n'est plus qu'une question d'heures. En mai, sur une faille comparable dans Drupal, ce même labo avait transformé le correctif public en exploit le jour même. Ce qu'on regarde là, c'est la fenêtre entre le correctif et l'attaque en train de se refermer.
Le CMS le plus déployé de la planète vient de rappeler ce que « par défaut » veut dire vraiment. Par défaut, exploitable.
@thsottiaux@nickbaumann_ Je suis sur le plan Pro, pris pour tester Codex après la debacle Anthropic. Mon usage est monopolisés par un projet sur 5.4/5.5, je n’ai pas encore pu tester Sol, ceci serait l’occasion de le faire sur des projets plus atypiques… et peut-être de me convaincre de passer au max ;)
mattpocock/skills v1.1 is out!
- /wayfinder helps you plan more ambitious work than ever
- /to-spec and /to-tickets replace /to-prd and /to-issues
- /implement + /code-review complete the whole lifecycle
- /research and /prototype help support wayfinder, or can be used independently
- Crucial fixes to /grill-me
Run npx skills@latest add mattpocock/skills to update!
Here's a step-by-step process to kill all the bloat from your Claude Code system prompt:
1. Run a proxy so you can see exactly what gets sent to Claude Code (included in the article)
2. "Fuck, there is so much cruft in there"
3. Use my settings.json to kill all the bloat
Down to a clean 13K tokens to start each session with. Nice.
Full process here:
https://t.co/Kie84HMe2A
Anthropic got caught doing something to Chinese users that nobody was supposed to notice.
Claude Code, their coding assistant, had hidden code buried inside it for three months.
When you pointed the tool at a proxy instead of Anthropic's own servers, it quietly checked your computer's timezone for Shanghai or Urumqi and matched your proxy against a secret list of Chinese companies and AI labs like Baidu, Alibaba, ByteDance, and DeepSeek.
Then it did the creepy part.
Instead of sending an obvious tracking flag, it changed one line of text. The date went from 2026-06-30 to 2026/06/30. And the apostrophe in "Today's date is" got swapped for a near-identical character your eyes can't tell apart.
Invisible to you. Invisible to the model. Perfectly readable by Anthropic's servers on every single request.
A Reddit user reverse-engineered the binary and found it. That's the only reason anyone knows.
C'est vraiment important, pour des tâches PRECISES (comparaison de fichiers de configuration yml dans mon cas d'aujourd'hui) de ne pas demander à Claude de comparer et updater les configurations. A la place il faut lui demander de vous créer des outils DETERMINISTES de comparaison quelque soit la complexité de la comparaison.
Là il m'a sorti des hallus de l'espace, DIEU MERCI JE VERIFIAIS la sortie et j'ai capté. Stoppé immédiatement, pris une heure avec lui pour qu'il se créé des outils déterministes et qu'on agisse SUR EUX.
Il me reste 30 réseaux à migrer mais au moins j'suis serein.
The most interesting Fable tip I've heard so far is to let the model use its own judgement as much as possible
I told it "For all coding tasks use your judgement to decide an appropriate lower power model and run that in a subagent" and it seems to be saving a lot of tokens
Forget trying to design everything in Figma. You can build your own design tools with AI.
Introducing Toolcraft - a starter kit and UI library for building beautiful creative apps. It's free and available for you today.
npx @pixel-point/toolcraft create
Use it to build apps to stylize images, create WebGL shaders, Three.js scenes, animations, photo editing tools, or whatever else needs a canvas and controls.
Toolcraft gives you the full architecture in a single solution. It comes with:
- plenty of UI components: sliders, pickers, timelines, curves, and more
- built-in canvas, export, and toolbar setup
- AI instructions to help the agent deliver a great result to you
With Toolcraft, you don’t need an extensive prompt. Just explain what type of visuals you want to build, attach references, and wait.
It’s been a game changer for our design process.
Watch the full video on our YouTube channel with all the details and examples.
Tip for Claude Code users:
claude --bg --name "Session Name" "Prompt goes here"
This programmatically adds a new agent to claude agents.
Super good when you want to handoff to another session and have the session... just open