AI agents
Working with AI coding agents that run real commands: context, permissions, review, safety rails, and where they should run.
69 posts · page 2 of 3
What Is a Context Window? Why AI Tools 'Forget' Things
An AI model can only consider so much text at once — its context window. What's in it, why long sessions get worse, what 'compacting' does, and practical habits for working with Claude Code and other tools so the right information is always in view.
What Are Tokens in AI? Why Your Usage Is Counted in Pieces of Words
AI models read and write in tokens, not words — and pricing, limits, and context windows are all measured in them. What a token is, roughly how many words it equals, input vs output tokens, why code uses more of them, and practical ways to use fewer.
Agent Hosting Is Becoming Free. Here's What Isn't.
Anthropic now ships ways to keep Claude Code running without your laptop — Remote Control, cloud sessions, scheduled Routines. That's good news, and it changes what's worth paying for. The session is becoming a commodity. The environment the work ships into is not.
A Security Checklist for Vibe-Coded Apps
AI-built apps fail security in predictable ways: open databases, keys in the browser, authorization checked only in the UI. A practical checklist for non-security people — what to check, how to test it yourself, and what to fix before real users arrive.
How to Undo Almost Anything in Git (Including an AI Agent's Mess)
An agent committed to the wrong branch, rewrote files you needed, or ran a reset it shouldn't have. Git can almost always get your work back. Which undo command fits which situation — restore, revert, reset, and the reflog that rescues 'deleted' commits — explained with the exact commands.
Why TypeScript Makes AI-Generated Code Safer
Types turn a whole class of AI mistakes — invented properties, wrong arguments, forgotten null checks — into errors caught before the code runs. How TypeScript acts as a feedback loop for agents, the settings that matter, and the escape hatches AI uses to switch it off.
Technical Debt in AI-Built Apps: What It Is and When to Pay It Down
AI tools let you build fast, and some of that speed is borrowed. What technical debt is, the specific kinds AI-generated code accumulates — duplication, dead code, inconsistent patterns, no tests — how to tell when it's hurting, and a practical way to pay it down without a rewrite.
Stuck in an AI Fix Loop? How to Break Out
You ask the AI to fix a bug. It says it's fixed. It isn't. Three rounds later, two other things are broken too. Why AI tools get stuck in loops, how to recognise one early, and a step-by-step way out that works far better than asking again.
How to Stop Bots From Running Up Your AI App's Bill
If your app calls an AI model on a user's behalf, every request costs you money — and a bot, a scraper, or one determined user can make thousands of them overnight. Rate limits, usage caps, provider spending limits, and the architecture that keeps a surprise bill from happening.
How to Stop an AI Agent From Deleting Your Production Database
In July 2025 an AI coding agent deleted a company's production database during a code freeze. It wasn't a freak event — it was the predictable result of giving an agent production credentials. Six controls that make it structurally impossible, not just unlikely.
Should You Still Learn to Code If AI Writes It?
AI can now build working apps from a description, so is learning to code still worth it? An honest answer: what AI has genuinely made unnecessary, the skills that matter more than ever, and a practical learning path for people who build with AI.
Securing MCP Servers: Threats and Controls for Tool-Connected Agents
An MCP server turns a model's text into real actions against real systems. The threat model — tool poisoning, prompt injection via tool output, confused deputies, token passthrough, DNS rebinding on local servers, over-broad scopes — and the controls for building and deploying MCP servers safely.
How to Run AI-Generated Code Safely
AI-generated code is usually well-intentioned and occasionally destructive, and the packages it installs are a supply-chain risk of their own. A practical, layered approach — what the code can see, reach, consume, and outlive — with a hardened Docker command you can use today.
How to Run Claude Code on a Remote Server (and Keep It Running)
Running Claude Code on a server instead of your laptop means sessions survive a closed lid, a dropped connection, and a flat battery. A practical setup guide — the server, the session, the security — and what you take on by doing it yourself.
How to Review a Pull Request Written by an AI Agent
AI-written pull requests are tidy, confident, and plausible — which makes them harder to review, not easier. The failure modes that differ from human code, the order to read a PR in, and a checklist that catches what skimming misses.
How to Resume a Claude Code Session (and What Resuming Can't Bring Back)
claude --continue and claude --resume reopen yesterday's conversation in seconds. But a resumed session restores the conversation, not the world it was working in. The commands, the habits that make resuming reliable, and the gap between conversation state and environment state.
Refactoring AI-Generated Code: Cleaning Up Without Breaking Things
Refactoring improves code's structure without changing what it does. When to refactor an AI-built app, how to do it safely with tests and small steps, the most valuable clean-ups, and prompts that stop the AI from rewriting everything.
Prompt Injection in Coding Agents: A Threat Model
A coding agent with a shell, credentials, and network access reads text written by strangers all day. A threat model — sources, capabilities, sinks — why detection-based defences fail, and the architectural controls that actually bound the damage.
Preview Environments for Every Branch: How They Work and What They Cost
A preview environment gives every branch or pull request its own live URL, so changes are reviewed running rather than read as diffs. How they work, the hard part (databases), the ways to get one, and why they matter more when an AI agent is writing the code.
How to Plan Your First App Before You Ask AI to Build It
Thirty minutes of planning saves days of AI going in circles. How to define the one problem your app solves, cut it down to a first version, describe your users' journeys and your data, and turn it all into a brief an AI tool can build from.
Running Claude Code Agents in Parallel With Git Worktrees
Two agents in one checkout will overwrite each other's work. Git worktrees give each Claude Code session its own files and branch on the same repository. How to set it up, and the parts nobody warns you about: ports, databases, and dependencies.
How to Keep Claude Code Costs Down (Without Making It Worse)
Claude Code usage is driven less by how much you ask and more by how much context every request carries. Where the tokens actually go, how to see them, and the habits that cut usage — clearing between tasks, picking the right model, trimming CLAUDE.md, and planning before building.
How to Write a CLAUDE.md That Actually Changes What Claude Does
Most CLAUDE.md files are either empty or a wall of generic advice Claude would have followed anyway. What to put in one, what to leave out, how the files load, and how to tell whether yours is working.
How to Read a Diff: Reviewing What Your AI Tool Changed
A diff shows exactly what changed in your code: red lines removed, green lines added. How to read unified and side-by-side diffs, what the @@ lines mean, where to look them up in Git, VS Code, and GitHub, and a quick review routine for AI-generated changes.