A maintainer's account of low-effort, AI-generated pull requests submitted to pad contributor profiles, with a 117-comment Hacker News discussion in which other maintainers describe adopting new contribution rules in response.
In the News: August 28, 2026
A Nanjing University study and a live Claude Code demo both show automatic permission review approving actions it flags as risky.
A single technique defeats permission review on six coding-agent harnesses
The researchers name a new attack class, instruction privilege escalation, in which an agent harness reconstructs context, through subagent delegation, persistent goals, scheduled tasks or custom subagent installs, in a way that relabels…
Read story →A researcher reproduces the same failure live against Claude Code
Rehberger's chain starts with an ordinary request to summarize a webpage, moves Claude from its WebFetch tool to a direct curl download of a ZIP archive, and uses Python module shadowing to run remote code after Claude, having correctly…
Read story →Six months as the only coder, before scaling to a fleet
Ali has not hand-written code in six months, describing the practice as agentic engineering rather than vibe coding: read-mostly, write-restricted agent access, credential proxying instead of handing agents live secrets, and named subagents…
Read story →