Why it matters: It lays out a complete workflow for systematically validating Codex Skills with evals, from defining success criteria to deterministic checks and scoring.
Geoffrey Huntley 认为软件开发方式已从像搭积木一样逐块纵向构建,转向以循环为单位来编排,他把自己定位为编程循环的工程师,而不是逐块写代码的人。他反对当下流行的多智能体与智能体间通信,理由是智能体本身是非确定性的,多智能体只会像微服务一样带来复杂度,而 ralph 是单仓库、单进程、每轮只做一件事的纵向扩展方案。
Dragos’ investigation shows that attackers used Claude Code and OpenAI GPT-4.1 to target the OT environment of a Mexican water company. Claude Code handled broad discovery, identifying vNode industrial gateways, researching vendor credentials, generating password lists, and executing password spraying, while GPT-4.1 handled structured data analysis and Spanish-language output.
Why it matters: Dragos reconstructed the full chain of how attackers used Claude Code and GPT-4.1 to conduct reconnaissance and password spraying against a Mexican water utility’s OT environment, showing how AI was actually divided across the intrusion lifecycle.
作者 Matthew Fontana 分享自己不再逐行审查 AI 生成的代码,而是用 Playwright MCP 让智能体截图证明功能可用。他给出的做法是直接提示智能体导航到页面、截图、点击并截图结果,例如让智能体截取空表单、填入非法数据截取校验错误、再正确填写截取成功状态,三张图即可判断表单是否可用。