HNHacker News
TopNewBestAskShowJobs

LeonidBugaev

424 karma · joined November 27, 2011

Head of Engineering at Tyk.io

Indie open-source developer of https://goreplay.org.

Helping OSS community via https://helpwanted.dev/

Would love to chat with you!

leonsbox@gmail.com

https://www.linkedin.com/in/leonidbugaev/

submissionscomments
LeonidBugaev··on MCP was always a bad idea?
It is all useful, and depends on the distribution channel and surface complexity. I use both MCP and CLI in my case.

Having the CLI allows you to have the huge application with the big surface be available to the AI agent and so they'll be able to learn it on demand. For example my app has more than 1,000 help pages. There are no other ways to load all this information into the CLI context and to be frank it will be quite stupid. Instead I use progressive discovery.

It first reads the original help message to understand which stage of the flow it is right now. It auto-discovers the topics through the error messages and through the various hints. It has an Elasticsearch-like search inside its own help command so it's a full self-contained application with self-discoverability, which has a graph, ontology and the full developing flows inside of it. All of those parts are automatically given to the AI only when it actually needs them.

And to be frank if you look at the latest YCombinator batch, all of the companies are building the custom harness. What I'm calling above CLI is actually a custom harness, which is running inside someone else's agent group.

Having remote MCP allows me to give limited read-only surface to clients which not supposed to run any CLI commands. And while MCP has similar patterns, like bundling docs and prompts, it is not as flexible as CLI and does not allow huge scale.

LeonidBugaev··on [dead]
So much energy in my life was spent making compromises between quality and speed, or pushing technical dev priorities. Constantly growing backlog, and guilt for the choices I had to do. What if we could fix the bug problem with AI? I mean, completely.
LeonidBugaev··on [dead]
When you are measuring how intelligent model is, in fact you mostly measure how good it was following the plan, or question, based on your own intelligence.

Difference is subtle, but crucial. And it is so easy to be confused, while measuring small model performance, like various Flash variants or local models.

Smaller models became quite good at doing the work under the well specified goal, like fixing the well specified bug. But can it find the bug, without you giving it any clues?

In my benchmark the answer is mostly No. Being able to invent the questions - thats the real intelligence - and thats where the big models show true strength.

LeonidBugaev··on [dead]
About 2 years ago I have created a small project https://helpwanted.dev OSS community to match people who looking for contribution with projects who actually ask for the help. It is very active and actual as ever! So a few reflections on whats the current pulse in the OSS community. What works and what not. Big projects are closing down. And now we have so many new people being enabled to fulfil their own ideas and it is renaissance of the OSS not the end of it! Bigger projects will find a way how to fix contribution inflow. But we should look at it as opportunity to find the people with the same interests.
LeonidBugaev··on Local code search engine for reference coding
"Install XERJ (docs: https://xerj.org/llms.txt), Allows you to write prompts like "index this project's sources, and set up reference coding: clone and index the open-source repos closest to what we're building, and search how they solved a problem before writing code.". Saves up to 5x tokens.
LeonidBugaev··on GLM-5.3: Frontier coding with emergent cyber capabilities
Not only attackers. I have to switch to Kimi or GLM even in cases of basic issue triage on my own projects! Current guardrails are ridiculous.
LeonidBugaev··on Don't be a meat proxy
I recently had experience working with one of the top security audit firms that collaborate with OpenAI on their cybersecurity tools. What struck me is that they found a lot of various issues (not all of them ended up to be legit, but a lot is) and filled the backlog of the project. However every collaboration with that

person was essentially a proxy for some security-related agentic prompt: - Hey, agent, open the issue! - Hey, I clarified it with the agent! - Agent disagrees! - Agent agrees!

LeonidBugaev··on MiMo Code Is Now Released and Open-Source
Thats exactly same as Claude Code offer: https://code.claude.com/docs/en/quickstart
LeonidBugaev··on Stolen Gemini API key racks up $82,000 in 48 hours
Thankfully Google has some basic protection for it. I accidentally commited my google api token, as part of some OTEL trace JSON file, and within a few minutes my key was automatically locked by google, and marked as leaked (with exact link pointing where it has happened).
LeonidBugaev··on "Token anxiety", a slot machine by any other name
I had a few useful examples of this. In order to make it work you need to define your quality gates, and rather complex spec. I personally use https://github.com/probelabs/visor for creating the gates. It can be a code-review gate, or how well implementation align with the spec and etc. And basically it makes agent loop until it pass it. One of the tips, especially when using Claude Code, is explictly ask to create a "tasks", and also use subagents. For example I want to validate and re-structure all my documentation - I would ask it to create a task to research state of my docs, then after create a task per specific detail, then create a task to re-validate quality after it has finished task. You can also play around with the gates with a more simple tooling, for example https://probelabs.com/vow/

Hope it helps!

LeonidBugaev··on Mermaid ASCII: Render Mermaid diagrams in your terminal
Nice one! I had my own spin on this issue as well, but from the other angle https://github.com/probelabs/maid

Getting AI to generate valid mermaid diagrams on scale extremely hard. With maid i'm hitting 100% accuracy.

Maid is basically built from scratch mermaid parser, without any dependnecies, which knows how to auto-fix common AI slop diagramming issues.

LeonidBugaev··on Show HN: A MCP server and client implementing the latest spec
It does not implement the Auth :)

(mcp auth is terrible btw)

LeonidBugaev··on The Agent2Agent Protocol (A2A)
To put it simple:

A2A is for communication between the agents. MCP is how agent communicate with its tools.

Important aspect of A2A, is that it has a notion of tasks, task rediness, and etc. E.g. you can give it a task and expect completely in few days, and get notified via webhook or polling it.

For the end users for sure A2A will cause a big confusing, and can replace a lot of current MCP usage.

LeonidBugaev··on Show HN: Chat with any GitHub repository via MCP
Hello HN!

I'm building Probe https://probeai.dev/ for a while now, and this this docs-mcp project is showcase of its capable. Giving you a local semantic search over any codebase or docs without indexing.

Feel free to ask any questions!

LeonidBugaev··on Show HN: Make open-source contributions fun and meaningful
Nope, it is simply fresh issues with "help wanted" and "good first issue" labels.
LeonidBugaev··on Show HN: Find active open-source projects looking for help
I do maintain big OSS projects and and try to contribute as well.

However contribution experience can very bad, if you follow the path of picking the most famous objects. Good luck contributing to Node, Rust, Shadcn and etc - they do not need your contribution, their PR queue is overloaded and they can't handle it. Plus you need to get to their internal circles first, though quite complex process.

The world is much bigger. There are so many help required from the smaller but still active projects.

Just recently I raised 3 small PRs, and they reviewed the same day!

As a my respect to all the OSS community, I have build https://helpwanted.dev/ website, which in the nutshell shows latest "help wanted" and "good first issue" issues, from all over github in the last 24 hours.

You would be amazed how many cool projects out of there looking for the help!

LeonidBugaev··on Show HN: I made a tool to clean and convert any webpage to Markdown
One of the cases when AI not needed. There is very good working algorithm to extract content from the pages, one of implementations: https://github.com/buriy/python-readability
LeonidBugaev··on Garnet – A new remote cache-store from Microsoft Research
Plus in production, with high load, Redis cluster is way more common, which kind of solve single-threaded concern.
LeonidBugaev··on Ruby on Rails: The Documentary [video]
What I really appreciate about Rails, is the strong vision, and not becoming another bloated framework for building "enterprise grade" applications. This is a 20-year-old framework, which does not afraid to radically change with time, and still being seen as Punk compared to rest

It was so heartwarming to remember my Rails story, its been 20 years ago since I started using it! https://twitter.com/buger/status/1723040883325460818

LeonidBugaev··on Launch HN: Codeparrot (YC W23) – Automated API testing using production traffic
I hope so! But I also hope that I will be also able to monetise some of this movent. GoReplay dual licensed under AGPL and Commercial license. I also sell special appliance licenses.

If anyone in this thread wants to build a product based on GoReplay technology (capture network traffic directly, via AWS Traffic Mirroring or k8s), sent me message :)

LeonidBugaev··on Launch HN: Codeparrot (YC W23) – Automated API testing using production traffic
I love to see more activity in this area!

I'm maintainer of GoReplay https://github.com/buger/goreplay and work in this area for the last 10 years.

It is quite hard problem to solve, because you have to deal with state difference between test and production environments. Love your approach to mocking dependencies, and leveraging OpenTelementry. It potentially can solve some of state issues. But still require modifying user code. I wonder if it can be done purely using OpenTelementry (e.g. you depend on typical OTel setup), and then read the data directly from OTel DB.

Cheers!

LeonidBugaev··on Cucumber maintainer has been laid off
I think BDD has very bad reputation because people associate it with test automation. And it is actually pretty terrible tool to teschnicall describe tests.

What BDD is good at, is defining project requirments, it is a thinking tool. Especially if used correctly, with examples and etc. It is a business not engineering tool.

LeonidBugaev··on Password protect a static HTML page
I had more simple and dumb approach in past. Lets say you have some password like "super-secret". Just place a secret "html" with content under the directory with the same name as your password. In public page have some prompt with password. When user enter password, you either redirect, dynamically inject iframe with your page. Since there is no way to list files/dirs of http server, it does pretty good job.
LeonidBugaev··on D2, a diagram scripting language that turns text to diagrams, is now open source
1. Is it possible to re-use part of diagram, like require statement in PlantUML?

2. Any plans for native C4 model support, or examples how to emulate it?

3. What about layout control? By default D2 generate way nicer layout, but it is synthetic. How I can tune it, give some hints, etc?

LeonidBugaev··on Show HN: We built a tool that automatically generates API tests
If you are looking for a more general tool, which can do not only API tests, but also interact with Databases and etc, but still use declrative syntax, try Venom https://github.com/ovh/venom
LeonidBugaev··on Making fifty TIC-80 carts in a weekend
If you liked this fantasy console approach, you should also check https://www.lexaloffle.com/pico-8.php, it is not OSS, but have really great community and support.
LeonidBugaev··on Show HN: I made Ankify that converts notes to Anki cards
I'm using this plugin for Obsidian and very happy so far https://github.com/st3v3nmw/obsidian-spaced-repetition

Essentially no need convert your notes to Anki cards, your notes litelarly became spaced repetition cards.

LeonidBugaev··on An embeddable Prolog scripting language for Go
If you are interested in logic programming itself, check http://minikanren.org/. Go community has a bunch of its implementations.
LeonidBugaev··on Masscan: TCP port scanner, scanning entire Internet in under 5 minutes
Question: how do you actually run it without getting banned?

I've got banned pretty hard by both my local home ISP and using Linode servers, when tried such scanners. Mass port scanning is easy to track, and it usually forbidden all ISP ToC.

LeonidBugaev··on Show HN: Time travel debugger for web development
Do you support it only for dynamic languages, where possible to monkey patch code?

All the debuggers mentioned above for the backend work only under Linux, because from what I understand, they use `ptrace` syscall, and on Mac have completely different format, and different capabilities.

Do you plan support Golang, especially on Mac, maybe with custom fork, or similar?

Thank you!

Page 1 of 5Next →