Skip to content

#Tutorials/practice

0 items today
10/6Tue
  1. DEV Community · MCP71

    用 100 行 Python 检查器识别链式 Skill 审批劫持

    作者用标准库 Python 写了一个约 100 行的 chain_check.py,用两条规则检测链式 Skill 审批劫持:单 Skill 规则标记同一文本中同时出现状态变更动作(upload、send、delete、transfer)和审批声明的 Skill,链式规则在已安装 Skill 间构建写读图,标记 A 写入含审批声明的文件、B 读取后执行状态变更动作的路径。

    Awaiting translation

  2. Reddit · ClaudeCode / Codex / VibeCoding17

    如何让 Codex 预先授权自动登录邮箱和软件账号

    有开发者想为小企业搭建 BI hub,部分数据源 API 端点有限,只能用定时邮件附带数据集的方式绕过。但 Codex 等工具风险规避严格,每次访问邮箱或软件都要求授权,即便单独创建了邮箱和账号也一样。他询问能否给 Codex 预先授权,使其无需每次显式许可即可登录这些账号。

    Awaiting translation

  3. Reddit · ClaudeCode / Codex / VibeCoding22

    Codex 任务跑了几小时,怎么查清时间花在哪?

    有用户反映 Codex 任务运行数小时仍未完成,事后难以判断时间究竟耗在等待响应、重试失败步骤还是反复读取同一批文件上。该用户向社区征集排查经验,询问大家用日志、终端历史还是实时观察,以及是否找到了答案。他尤其关注那些查清原因后改变了下次任务运行方式的案例。

    Awaiting translation

  4. DEV Community · MCP78

    FP8 pitfall: GPU bill dropped 47%, but the model outputs “!!!!!!”

    The author ran Qwen2.5 7B/32B/72B on a single AMD MI300X with vLLM ROCm, priced at $2.99/GPU-hr. The BF16 baseline was 7B at $0.227/M, 32B at $0.77/M, and 72B at $1.67/M output tokens.

    Why it matters: The author benchmarked FP8 quantization on the MI300X and found that per-token billing can hide the model's output degrading into gibberish, then gave a reusable way to verify it.

  5. Reddit · ClaudeCode / Codex / VibeCoding22

    Codex 能否像 Claude Code 一样跨设备续接会话?用户求助

    一名同时使用 Claude Code 和 Codex 的用户反映,Claude Code 可通过 VPS 的 screen 加 /rc 命令或 Claude Desktop 的 Code 标签页启动会话,手机上能立即接续;而 Codex 会话似乎绑定 ChatGPT Windows 应用,部分会话在手机上可见、部分不可见,原因不明。

    Awaiting translation

  6. DEV Community · Claude Code78

    I tested ten Claude Code mods: when a guard crashes, the command still runs — only three held up

    I tested ten Claude Code mods on Claude Code 2.1.288 across 85 sessions, 882 prompts, and 5993 tool calls, and found that a guard Hook without a .catch gets skipped when it throws, so the command runs anyway. Only by adding a catch that returns deny does it fail closed.

    Why it matters: I tested ten Claude Code mods across 85 sessions and 5993 tool calls, and lay out transferable criteria for choosing between them, plus the open question of failing open.

10/5Mon
  1. Reddit · ClaudeCode / Codex / VibeCoding20

    Sol 6.1 keeps interrupting /goal targets, and users are questioning what it's even for

    Users report that Sol 6.1 interrupts /goal targets on any excuse, stopping and escalating in 99% of cases—with completely made-up reasons. This user says they've already adjusted things per OpenAI's prompt suggestions, but the model still can't autonomously complete goals the way it used to, and they have to watch it the whole time.

  2. DEV Community · Vibe Coding22

    What goes wrong with apps launched on Vibe Coding: continuevibe takes over maintenance

    The small Korean team continuevibe offers maintenance services for products launched on Vibe Coding, with a process of diagnosing the problem, scoping the fix, fixing the code, and testing. From their interviews, they found that the most common post-launch issues are severe bugs that drive users away, such as broken login and data loss, along with fixing one thing and breaking another—failures that non-developers find hard to describe.

9/29Tue
9/27Sun
9/23Wed
9/22Tue
8/25Tue
8/6Thu
7/3Fri
  1. Hacker News · AI 编程经验问答22

    AI 编程助手为何让人崩溃:重复造轮子、上下文窗口太短、越调越笨

    一位开发者吐槽 AI 编程助手的几大问题:同一功能在一个文件里写出三个重复函数,因为它怕撑爆上下文窗口,只读大文件的一小部分,错过已有实现;AI 偏爱新增代码而非修改,几乎不删代码,几轮迭代后代码库堆满死代码。它还缺乏全局意识,改坏原有逻辑后只当作新任务单独修,且上下文窗口太短,塞满必要上下文后很快触及 200k token 上限,再两轮就触发自动压缩,模型随即变笨。

    Awaiting translation

3/19Thu
3/12Thu
  1. Hacker News · Prompt Injection62

    Ask HN:生产环境如何缓解提示词注入

    作者在 Hacker News 分享生产环境中缓解提示词注入的多层做法。输入侧包括在系统提示词中强制角色边界、在 API 层用独立的 user 角色隔离用户内容与系统指令、对工具调用参数在执行前做 schema 校验;输出侧则用评估指标对模型输出打分,检查事实正确性、指令遵循与安全性,RAG 场景还要验证答案确实基于检索到的上下文。

    Awaiting translation

11/16Fri