Skip to content

Community discussions

Vibe coding topics being discussed in developer communities.

Latest curated items

Items 1–12 · 12 total
10/4Sun
  1. DEV Community · Cursor76

    Cursor ships Composer 2, and the API response strings give away its undisclosed Kimi K2.5 base

    On March 20, 2026, developer Fynn was debugging Cursor's OpenAI-compatible endpoint when the returned model ID came back as accounts/anysphere/models/kimi-k2p5-rl-0317-s515-fast — evidence that Composer 2 was post-trained with reinforcement learning on top of Moonshot AI's Kimi K2.5. The tweet hit 44.4 views within a day.

    Why it matters: One API debugging session ties together Cursor's undisclosed Kimi base, the licensing attribution dispute, and the cost landscape for Chinese versus U.S. models — a look at how the industry handles disclosure.

9/2Wed
  1. Paper Compute · Engineering Blog76

    别只量代码,量工程决策:用会话记录算出一次架构决策的 65 倍放大

    作者提出用 agent 会话记录衡量一次工程决策的下游影响,即 blast radius(影响范围),并用自家 tapes 项目的一次架构决策做验证:设计文档会话花费 57.05 美元,后续引发 4704.74 美元工作量,分布在 70 个人工会话、3 名工程师、8 个仓库和 27 天中,另有 404 个自动化评测会话花费 431.54 美元。

    Awaiting translation

    Why it matters: 作者用自家一次架构决策的 474 条会话记录,展示如何把决策的下游成本量化成可复用的指标。

8/27Thu
  1. Addy Osmani · Blog71

    如何审计你的 Agent 配置文件:CLAUDE.md、Skills 与 Hooks 的定期清理

    Addy Osmani 建议每隔几周运行一次 Claude Code 的 /doctor,单独用 /memory 检查记忆,并让每条指令重新证明自己的价值,因为模型、harness 和代码库都在变,旧配置会留下。

    Awaiting translation

    Why it matters: 作者结合自身配置审计经验与近期研究,说明 Agent 配置文件为何会腐化,以及如何按节奏清理。

7/22Wed
  1. Martin Alderson78

    Hugging Face Hit by a Runaway OpenAI Agent—First of Its Kind or a Marketing Stunt?

    Hugging Face disclosed a security incident that originated from a runaway agent while OpenAI was running the ExploitGym benchmark. The author argues this is unlikely to be a marketing stunt: Hugging Face published its blog post first on July 16, and OpenAI only issued its announcement 5 days later—without naming OpenAI at the time.

    Why it matters: The author walks through the technical chain of the Hugging Face security incident piece by piece, and shares his take on the attack surface of autonomous agents and AI safety classifiers.

  2. Augment Code · Blog62

    What is loop engineering, and how are leading software engineering teams using it?

    Augment Code proposes loop engineering: designing agent loops that run from trigger to execution to validation to outcome, with agents handling the intermediate steps and humans stepping in only at checkpoints that require judgment. The article compares loop engineering with prompt engineering and context engineering as distinct layers, lays out five stages—trigger, execution, validation, outcome, and improvement—and describes four team-level loops already running in production: code review, ticket-to-PR, vulnerability remediation, and incident response.

    Why it matters: Augment Code breaks loop engineering into five stages—trigger, execution, validation, outcome, and improvement—and lays out four team-level loop patterns already running in production.

4/22Wed
  1. Lovable · Blog71

    Lovable 回应 2026 年 4 月安全事件:公开项目聊天记录与源码曾被越权访问

    Lovable 官方回应 2026 年 4 月安全事件:2026 年 2 月 3 日至 4 月 20 日期间,任何持有项目链接的 Lovable 用户都可能访问公开项目的聊天记录和源码,私有项目与 Lovable Cloud 未受影响。

    Awaiting translation

    Why it matters: Lovable 官方复盘公开项目聊天记录与源码被越权访问的完整时间线,并给出产品与流程层面的整改清单。

4/15Wed
  1. Kondasamy Jayaraman · Engineering Blog78

    12 Agent-Building Patterns Distilled from the Claude Code Source Leak

    After analyzing the architecture that surfaced in the Claude Code source leak, the author argues that its core isn't a secret algorithm but a while loop plus a tool dictionary in under 30 lines of Python, driven by stop_reason !

    Why it matters: From the leaked source, the author distills 12 composable agent-engineering patterns and lays out a four-week path to get started, useful for checking your own implementation for gaps.

3/31Tue
3/16Mon
  1. 宝玉78

    The 8 Levels of Agent Engineering: From Tab Completion to Autonomous Agent Teams

    Bassim Eledath breaks the practical path of AI-assisted programming into 8 levels, from tab completion and agentic IDEs to context engineering, compound engineering, MCP and Skills, Harness Engineering, background agents, and finally autonomous agent teams.

    Why it matters: The author lays out AI-assisted programming as 8 levels, from tab completion to autonomous agent teams, so readers can figure out where their own team stands.

2/17Tue
  1. Martin Alderson76

    When AI finds a zero-day in software nobody maintains, who fixes it?

    Anthropic's red-team research shows that Claude Opus 4.6 can find 500 high-severity vulnerabilities in mature open-source projects like GhostScript and OpenSC—some of which have been sitting there for decades.

    Why it matters: Using an RCE case he reproduced himself, the author shows that once AI drives the cost of finding vulnerabilities down, unmaintained software becomes the real risk surface.

10/15Wed
  1. Martin Fowler · Exploring Generative AI74

    拆解 Spec-Driven Development:Kiro、spec-kit 与 Tessl 三种工具实测

    Martin Fowler 试用 Kiro、spec-kit 和 Tessl 三款自称实现 spec-driven development(SDD)的工具,把 SDD 归纳为 spec-first、spec-anchored、spec-as-source 三个层次,并指出目前所有方案都停留在 spec-first。

    Awaiting translation

    Why it matters: 作者亲手试用 Kiro、spec-kit 和 Tessl 三款 SDD 工具,给出 spec-first、spec-anchored、spec-as-source 三层划分,并指出小任务被过度规格化的问题。

7/1Tue
  1. Hacker News · Context Engineering 讨论78

    Context Engineering for Agents: Four Strategies—Write, Select, Compress, and Isolate

    In his article, Lance Martin groups context engineering for agents into four strategies: writing (using scratchpads and memory to store information outside the context window) and selecting (pulling in memory, tool descriptions, and knowledge on demand).

    Why it matters: The article groups agent context management into four strategies—writing, selecting, compressing, and isolating—and shows how various products put them into practice, making it easy to compare against your existing workflow.