Skip to content

#OpenAI

0 items today
3/30Mon
3/28Sat
3/18Wed
  1. Hacker News · AGENTS.md71

    把 AGENTS.md 当作目录而非说明书,附生成提示词

    作者认为多数 AGENTS.md 写得太长,把编码规范、架构决策、产品背景全塞进一个文件,而 LLM 每次启动任务都要读一遍,大部分内容与当前工作无关。他建议把 AGENTS.md 控制在约 100 行,只作为目录链接到 docs/ 下的架构、规范、测试等文档和产品背景文档,让智能体按任务自行拉取所需内容。

    Awaiting translation

3/16Mon
  1. Permission Protocol · AI Agent Incident Tracker62

    AI 编码工具误引入存在漏洞的 Next.js 依赖,生产服务器被植入挖矿程序

    一份运营者报告称,AI 辅助编码工具生成的 Next.js 应用固定了一个存在漏洞的依赖,该漏洞随后通过 CVE-2025-29927 被利用。部署后自动化扫描器访问了本应由中间件保护的内部端点,生产服务器上运行起挖矿程序。报告认为,引入已知严重依赖风险的 PR 在发布前应经过审批路径,而运行时利用仍需漏洞扫描和环境隔离。

    Awaiting translation

3/13Fri
  1. Ryan Lopopolo74

    智能体时代的生产函数变了:实现不再稀缺,验证才是

    作者认为,软件组织一直把人的实现时间当作稀缺投入,智能体打破了这个假设,因此策略必须可执行、验证必须随实现规模扩展。他以在大型 TypeScript 代码库开启 ESLint 的 no-await-in-loop 规则为例,发现 600 处违规,过去这需要昂贵的迁移,现在一个 PR 就能完成修复并补齐测试覆盖。

    Awaiting translation

    Why it matters: 作者以开启 ESLint 规则、迁移 600 处违规的亲身实践,说明智能体时代实现成本下降后,约束与验证为何成为新的稀缺环节。

3/9Mon
  1. OpenAI Developer Blog · Codex87

    OpenAI 如何用 Skills 加速 Agents SDK 仓库维护

    OpenAI 用 Codex 配合仓库内的 Skills、AGENTS.md 和 GitHub Actions 维护 Agents SDK 仓库,把验证、发布准备、示例集成测试和 PR 评审变成可重复流程。

    Awaiting translation

    Why it matters: OpenAI 官方公开了用 Skills、AGENTS.md 和 GitHub Action 维护 Agents SDK 仓库的完整配置,可迁移到其他开源项目。

3/8Sun
3/7Sat
2/26Thu
2/23Mon
  1. OpenAI Developer Blog · Codex72

    用 Codex 跑 25 小时长时程任务:一份可复用的项目记忆文件栈

    OpenAI 用 GPT-5.3-Codex 在 Extra High 推理档下从空仓库连续运行约 25 小时、消耗约 13M token、生成约 3 万行代码,做出一个可测试的设计工具。

    Awaiting translation

    Why it matters: 作者用 25 小时、13M token 的实测展示长时程智能体如何靠持久化项目记忆和逐里程碑验证保持不跑偏。

2/17Tue
2/11Wed
2/9Mon
2/8Sun
  1. Martin Alderson78

    Automatically improving your CLAUDE.md file with agent session logs

    The author suggests using agent session logs to improve CLAUDE.md or AGENTS.md files: Claude Code stores sessions in ~/.claude/projects, while Codex stores them in ~/.codex/sessions—both in JSONL format but with different schemas.

    Why it matters: The author works backward from agent session logs to figure out what to improve in CLAUDE.md, and has open-sourced a CLI that cuts search time from several minutes down to seconds.

2/2Mon
2/1Sun
  1. Martin Alderson62

    两类 AI 用户正在分化,差距惊人

    作者 Martin Alderson 观察到 AI 用户正分化为两类:一类是深度使用 Claude Code、MCP、Skills 等工具的用户,其中不少并非技术出身,财务岗位用它处理原本受限于 Excel 的任务;另一类仍停留在与 ChatGPT 对话的阶段。

    Awaiting translation

1/22Thu
1/19Mon
1/12Mon
1/11Sun
  1. OpenAI Developer Blog · Codex71

    Skyscanner 如何用 JetBrains MCP 增强 Codex CLI

    Skyscanner 工程师把 OpenAI 的 Codex CLI 接入 JetBrains IDE 的 MCP server,让 Codex 能调用 IDE 的 get_file_problems 检查文件错误、执行预设的 run configurations 跑测试和 lint。

    Awaiting translation

    Why it matters: Skyscanner 工程师把 Codex CLI 接入 JetBrains MCP,让 AI 直接读取 IDE 报错并跑测试,读者可借鉴这套反馈闭环。

1/8Thu
1/5Mon
1/1Thu
  1. Permission Protocol · AI Agent Incident Tracker76

    Attackers used Claude Code to conduct reconnaissance and password spraying against the OT environment of a Mexican water utility.

    Dragos’ investigation shows that attackers used Claude Code and OpenAI GPT-4.1 to target the OT environment of a Mexican water company. Claude Code handled broad discovery, identifying vNode industrial gateways, researching vendor credentials, generating password lists, and executing password spraying, while GPT-4.1 handled structured data analysis and Spanish-language output.

    Why it matters: Dragos reconstructed the full chain of how attackers used Claude Code and GPT-4.1 to conduct reconnaissance and password spraying against a Mexican water utility’s OT environment, showing how AI was actually divided across the intrusion lifecycle.

12/29Mon
12/20Sat
  1. Jesse Vincent70

    用 Codex 和 ChatGPT 5.2 反编译 Android 游戏 Wordiest 并移植到 iOS

    作者把 Wordiest 最后一个 Android APK 交给 Codex + ChatGPT 5.2,半小时内得到可玩的核心游戏,几小时后完成 Android 与 iOS 版本,全程未写也未读一行代码。

    Awaiting translation

    Why it matters: 作者用 Codex 反编译 Android 游戏并移植到 iOS,展示了智能体开发中难易直觉失效的真实体验。

12/19Fri
12/12Fri
  1. Hacker News · AI Code Review 讨论66

    DeepSource 发布 Autofix Bot:静态分析与 AI 混合的代码审查智能体

    DeepSource(YC W20)团队发布 Autofix Bot,一个把静态分析与前沿 AI 智能体结合的代码审查智能体,面向 AI 编码工作流。其混合架构分三步:5000+ 确定性检查器建立高精度基线并由子智能体抑制误报,AI 审查以静态发现为锚点并调用 AST、数据流图、控制流、导入图等工具,最后由子智能体生成修复、静态校验后输出干净的 git patch。

    Awaiting translation

11/19Wed
  1. OpenAI · Codex Cookbook67

    How to modernize a legacy codebase in phases with Codex CLI

    In the Codex Cookbook, OpenAI lays out a complete workflow for modernizing a legacy codebase with Codex CLI, using a COBOL portfolio system as the example and moving through five phases built around an ExecPlan design document.

    Why it matters: Using a COBOL portfolio system as the example, it offers reusable documents and a validation workflow for modernizing legacy code in phases with Codex CLI.

10/27Mon
  1. Jesse Vincent74

    Porting Skills and Superpowers to the OpenAI Codex CLI

    Author Jesse Vincent spent an afternoon porting Superpowers and the whole SKILL.md system to the OpenAI Codex CLI, shipping it with Superpowers 3.3.0.

    Why it matters: The author ported Claude's SKILL.md system to the Codex CLI, with tool mappings and install instructions, so you can judge whether reusing Skills across models is feasible.

  2. OpenAI Developer Blog · Codex64

    Dagster Labs 如何用 Codex 做技术文档与教学

    Dagster Labs 分享了用 OpenAI Codex 加速技术文档写作、跨媒介内容转换和文档覆盖度评估的实践。他们重写了 CONTRIBUTING.md,明确文档层级、结构和最佳实践,让 Codex 能据此生成符合规范的文档;还借助 gh 命令让 Codex 解读 PR 的 diff 和描述,并让 Codex 把教程改写成 YouTube 视频脚本。

    Awaiting translation

    Why it matters: Dagster 团队把 Codex 用于文档写作、PR 解读和内容跨媒介转换,其中用文档生成代码来反向衡量文档覆盖度的做法可以迁移。

10/24Fri
  1. Jesse Vincent36

    用 ChatGPT Atlas 的 Agent 模式清理 Facebook 信息流

    作者用 ChatGPT Atlas 的 Agent 模式自动清理 Facebook 信息流,通过一段提示词让智能体持续滚动页面、隐藏赞助帖并对含 Follow/Join 链接的帖子点“不感兴趣”,最终信息流只剩自己关注的人发布的真实帖子。作者对 AI 浏览器的提示注入风险仍持警惕,表示目前不会把银行或邮箱凭据交给这类浏览器。

    Awaiting translation

10/10Fri
8/29Fri
  1. OpenAI · Codex Cookbook74

    在 GitLab CI/CD 中用 Codex CLI 自动做代码质量检查与安全修复

    OpenAI Codex Cookbook 给出把 Codex CLI 接入 GitLab CI/CD 的完整做法,用于生成 CodeClimate JSON 代码质量报告、把 SAST 结果整理成 security_priority.md,并让 Codex 输出可 git apply 的补丁。

    Awaiting translation

    Why it matters: 官方 Cookbook 给出把 Codex CLI 接入 GitLab CI 的完整配置,含提示词约束、JSON 标记提取与 diff 校验,可直接照搬。

8/26Tue
7/1Tue
  1. Hacker News · Context Engineering 讨论78

    Context Engineering for Agents: Four Strategies—Write, Select, Compress, and Isolate

    In his article, Lance Martin groups context engineering for agents into four strategies: writing (using scratchpads and memory to store information outside the context window) and selecting (pulling in memory, tool descriptions, and knowledge on demand).

    Why it matters: The article groups agent context management into four strategies—writing, selecting, compressing, and isolating—and shows how various products put them into practice, making it easy to compare against your existing workflow.

6/4Wed
  1. Martin Fowler · Exploring Generative AI66

    自主编码智能体实测:一次 OpenAI Codex 运行记录

    Martin Fowler 给 OpenAI Codex 布置了一个前端标签格式化的化妆类小任务,并完整公开了 Codex 的日志和生成的 PR。日志显示 Codex 主要靠 grep 反复文本搜索定位代码,中途因把 AGENTS.md 误写成 AGENT.md 来回折腾,还因删掉 .yarnrc 导致测试无法运行,最终 PR 里有两个回归测试失败。

    Awaiting translation

    Why it matters: 作者完整记录 Codex 自主完成一次前端小任务的日志,并对比 6 次运行结果,展示后台编码智能体在环境配置和代码复用上的真实短板。