HNHacker News
TopNewBestAskShowJobs

edf13

1,507 karma · joined October 20, 2017

hello at fieldlogic.uk
submissionscomments
edf13··on Claude partial outage
A few of us old boys can still maintain Cobol
edf13··on GPT-6 Sol and Luna
You also need to compare allowances on Codex vs. Claude Code
edf13··on If coding is solved, what now?: Measuring the sloppiness of code
Recent PR I had to review...

PR content:

``` Lots of AI slop.... .... .... Note: this will not build due to XYZ .... .... More AI slop .... .... End of PR ```

So the dev hadn't even read the PR comment himself and had blindly posted it!

edf13··on Show HN: ClaudeStatsBar: your session is 486k deep and nothing told you
It is AI gen - and it's not so much of a project, more of a quick tool/status bar.
edf13··on Show HN: ClaudeStatsBar: your session is 486k deep and nothing told you
Yes - we hook into that to add the cost/turn and the burn rate
edf13··on Show HN: ClaudeStatsBar: your session is 486k deep and nothing told you
I kept running into limits on my Claude Code sessions (Especially with leading edge models)... the main cause being session hygiene, not clearing or compacting my sessions often enough.

So I built this simple tool to show my current session status.

edf13··on Show HN: Grith – syscall-level supervision for AI agents
Hi,

I'm Dan and I staarted building grith AI earlier this year after getting annoyed with constant permission prompts from Claude Code and Codex.

I had previously built an email security service which relied on a pipeline of multiple filters, each one building up a score of an incoming message - allowing the system to auto approve or deny an message in almost all cases and if it was unsure it would add it to an email digest/report letting the user choose to allow or block.

This process is the basis for grith - we currently have 18 filters and 1617 patterns which build a score for every action a agent takes - everything <= 3.0 is automaticialy approved, everything > 8.0 is automatically blocked... the ones inbetween we prompt the user.

What this means in practice is that the user sees very little prompts - in a records 120 claude code session a user only ever had to respond to 0.27% of prompts... not 40 or so an hour you'd see in normal use and not the dangerously blind approval --dangerously-skip-permissions or auto mode would give you!

Grith is free with no account needed, no phone-home and open source. Paid tiers bring teams, online dashboards, centralised policies, verificable analytics and more.

Linux first with Windows and Mac launching soon.

edf13··on 216M Spy TVs – The LG Smart TV Problem [video]
Be interesting to know the true cost of smart TVs without the subsidized benefit of tracking that the "smart" element has.

A comparison of a dumb 4k panel vs the equivalent "smart" tv for example>

edf13··on Ask HN: How do you manage skills files?
One thing to consider when you do look at how you manage your installed skills - is the security side of them.

You also need to manage the authority of each skill too. Signed skills is a step in the right direction, but it only proves provenance and doesn't prove behavior.

(Related: https://news.ycombinator.com/item?id=49597166)

edf13··on Inception-style curved map for turn-by-turn directions
Any video demo available - love to see it in action
edf13··on 1-Bit Bonsai Image 4B Image Generation for Local Devices
Odd… UK visitor and I get:

Website Not Allowed “⁦‪prismml.com‬⁩” is a restricted website.

edf13··on AI Makes Adding Features Faster – So Why Not Add Just One More?
Exactly - the flow of AI assistance makes it so much easier to get caught in the one more feature trap!
edf13··on Vibe Coding Still Needs a Senior Engineer (For Now)
Most of the AI-security discourse (and most of my posts) right now is about prompt injection and agent hijacking. But there are still the move-fast-break-things issues that are exacerbated with agentic coding/vibe coding...

I reviewed a colleague's vibe-coded internal tool last week, found 28 security issues, and none of them were that kind of bug - they were the same classic stuff juniors have always shipped, just produced at much higher throughput.

Wrote it up because the "senior engineer review" step quietly disappeared from a lot of AI-assisted workflows, and the bugs that step used to catch are still there (We are still needed!).

edf13··on Before GitHub
Ha ha... yes... that brings back memories!
edf13··on Before GitHub
My first was this monster:

https://en.wikipedia.org/wiki/Microsoft_Visual_SourceSafe

edf13··on Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
Manually review the package and override the setting
edf13··on Parallel agents in Zed
Anyone know of a similar tool to conductor for Linux?
edf13··on CrabTrap: An LLM-as-a-judge HTTP proxy to secure agents in production
Hand written I’m afraid… regular comments on this topic is true - it’s an area I’m very interested in.
edf13··on CrabTrap: An LLM-as-a-judge HTTP proxy to secure agents in production
Yes, true ;)
edf13··on CrabTrap: An LLM-as-a-judge HTTP proxy to secure agents in production
We are Open Source… code will be published soon (before launch)
edf13··on The Vercel Breach Needed Malware. The Next One Needs a Bad Readme
Yes, fair point.

Feedback accepted, thanks!

edf13··on Claude Opus 4.7
Related: https://news.ycombinator.com/item?id=47803847
edf13··on Elevated errors on Claude.ai, API, Claude Code
Seems to be a very regular occurrence starting around this time of day (14:30 UTC)...

Claude Code returning: API Error: 500 {"type":"error","error":{"type":"api_error","message":"Internal server error"},"request_id":"---"}

Over and over again!

edf13··on Ask HN: What Are You Working On? (April 2026)
Building grith (grith.ai) - a security proxy for AI coding agents enforced at the OS syscall level.

The problem: agents like Claude Code, Codex, and Aider execute file reads, shell commands, and network requests with your full system privileges.

For example, when a malicious README tells the agent to read ~/.ssh/id_rsa and POST it somewhere, nothing in the agent's own trust model catches it. Auto Mode makes this worse - it asks the model to audit its own actions, so a prompt injection that corrupts the reasoning also corrupts the permission layer.

grith wraps any CLI agent with `grith exec -- <agent>`. Every syscall passes through a multi-filter scoring engine before it executes. Deterministic, ~15ms overhead, no LLM reasoning in the permission path. Linux now, macOS/Windows coming. AGPL, open-core.

Two weeks ago a DPRK-linked attacker backdoored axios on npm (400M monthly downloads). The RAT executed 1.1 seconds into npm install. AI agents run npm install autonomously, without human review. If yours ran it during the 3-hour window, you're compromised and nobody told you.

That's the threat model grith is built for.

edf13··on Who is Satoshi Nakamoto? My quest to unmask Bitcoin's creator
> And really, for what?

Readership, clicks and views

edf13··on Agent-to-agent pair programming
I’m going to take a look today!
edf13··on Schedule tasks on the web
Or perhaps we end up where all software is self evolving via agents… adjusting dynamically to meet the users needs.
edf13··on Agent-to-agent pair programming
Nice - I do something similar in a semi manual way.

I do find Codex very good at reviewing work marked as completed by Claude, especially when I get Claude to write up its work with a why,where & how doc.

It’s very rare Claude has fully completed the task successfully and Codex doesn’t find issues.

edf13··on My minute-by-minute response to the LiteLLM malware attack
Good write up…

I’ve found Claude in particular to be very good at this sort of thing. As for whether it’s a good thing, I’d say it’s a net positive - your own reporting of this probably saved a bigger issue!

We wrote up the why/what happened on our blog twice… the second based on the LiteLLM issue:

https://grith.ai/blog/litellm-compromised-trivy-attack-chain

edf13··on My astrophotography in the movie Project Hail Mary
Congrats on the film use!

It’s really interesting to read how you’ve captured and created these images… will follow your work!

Page 1 of 17Next →