Blog
Notes from building a tool that sits next to Claude Code and Codex all day.
- Codex and AGENTS.md: every file from root down, and a 32 KiB cutoff Codex does not pick the nearest AGENTS.md. It concatenates every file from your repo root down to the current directory, lets later files win conflicts, and stops at 32 KiB, which means the most specific instructions are the first to be cut. How discovery works, what AGENTS.override.md is for, and how to check what actually loaded. 2026-09-21 · 5 min read
- Codex code review: the local command, @codex review, and the Action Codex has three ways to review code, plus a fourth thing named auto-review that is not code review at all. What codex review and codex exec review actually take, what the bundled review-agent skill defines as a finding, why GitHub reviews only post P0 and P1, how AGENTS.md review rules work, and the Action's prompt injection warning. 2026-09-17 · 6 min read
- Codex skills: the 8,000-character budget that decides which ones load A Codex skill is a folder with a SKILL.md in it, and its description is the only part Codex reads until the skill is selected. We read all 581 skills shipped with Codex to see what authors actually put in them. What matters, what is decoration, and where skills are discovered. 2026-09-16 · 5 min read
- Codex plugins: what the 180 in the marketplace actually contain We opened every plugin in Codex's curated marketplace. Most are thin wrappers around an app connector, a minority bundle skills or MCP servers, and two ship hooks that run scripts after your edits and commands. How codex plugin works, what to check before installing, and how to override a plugin's MCP servers in config.toml. 2026-09-15 · 6 min read
- Codex MCP servers: config.toml, the add command, and what the docs skip How to add MCP servers to Codex CLI with codex mcp add and config.toml, every key worth knowing, where tokens should live instead of the file, per-tool approval modes, and the version gaps between the docs and the CLI you actually have installed. 2026-09-14 · 5 min read
- Codex hooks and config.toml: notify is no longer the whole story Codex CLI now ships twelve lifecycle hooks, on by default, with JSON on stdin and the power to block. What changed from notify, how config.toml layers and trust decide what runs, the notify sharp edges that still apply, and what sandbox_mode, approval_policy, --full-auto and --yolo actually set. 2026-09-13 · 7 min read
- Claude Code models: how to change it, and the dial that matters more Five places can set the model and they resolve in a fixed order. What the default actually is on your plan, why opusplan is the setting most people want and never find, why MAX_THINKING_TOKENS does nothing on newer models, and the honest answer about local models. 2026-09-12 · 6 min read
- Claude Code SDK vs Claude Agent SDK: the rename, and whether you need either The Claude Code SDK was renamed to the Claude Agent SDK, with two breaking changes that make migrated code behave differently. What actually changed, why claude -p is the third option nobody frames as one, and the CI security gap in a non-interactive run that has not trusted the folder. 2026-09-11 · 5 min read
- Claude Code settings: which file actually wins Five settings layers, and your personal file is the bottom one. Why your team's committed settings beat your own, which keys a repository file can never set, which ones wait for workspace trust, and the security keys where the strictest value wins no matter who set it. 2026-09-10 · 6 min read
- AGENTS.md vs CLAUDE.md: does Claude Code read AGENTS.md? No. Claude Code reads CLAUDE.md and ignores AGENTS.md entirely. Three ways to bridge them so one file drives both, and the design difference that breaks a naive port: AGENTS.md lets the nearest file win, while CLAUDE.md concatenates every file it finds. 2026-09-09 · 5 min read
- Claude Code git worktrees, and what /rewind will not save you from Running several Claude Code sessions on one repo without them colliding, using worktrees. How isolation is actually enforced, the base-branch default that surprises people, why your hooks do not follow the worktree, and the four categories of change checkpoints silently cannot undo. 2026-09-08 · 6 min read
- Claude Code auto mode: what the classifier actually blocks Auto mode replaces you with a second model that reviews every action. What it blocks by default, why it flags routine internal work, the order deny and ask rules run in, how to fix a denial properly, and the settings footgun that silently deletes the built-in exfiltration rule. 2026-09-07 · 7 min read
- You've hit your session limit: which Claude Code limit you hit, and what actually works Claude Code has four different usage limit messages and they call for opposite responses. Switching models fixes two of them and does nothing for the other two. Plus the wait-and-continue machinery most people never discover, when it refuses to offer it, and the things that silently cancel it. 2026-09-06 · 6 min read
- Claude Code on the web vs desktop vs terminal: what actually changes The same agent has four front doors and they are not equivalent. Cloud sessions clone GitHub rather than your disk, silently ignore two permission modes from your settings files, and drop half a dozen commands. What each surface adds, what each one quietly takes away, and how to pick per task. 2026-09-05 · 6 min read
- --dangerously-skip-permissions: what it turns off, and what to use instead The flag people reach for when Claude Code will not stop asking. What bypassPermissions actually disables, the four rules that still apply, why it refuses to start under sudo, the plan mode trap that comes with merely enabling it, and the three newer options that solve the real problem without it. 2026-09-04 · 6 min read
- Claude Code code review: three different things with the same name Searching for Claude Code code review returns three separate products blended together. The local /code-review skill, the managed Code Review that comments on your PRs, and the GitHub Action you write yourself. What each one actually does, the gotchas that make each silently produce nothing, and how to pick. 2026-09-03 · 7 min read
- Claude Code cost: why it climbs when you are not typing The honest answer to what Claude Code costs is not a price. Cost scales with context times requests, which is why a session you left open all day bills for a one-line question. How to read /usage, the six ways tokens leave while you are idle, and the levers ranked by what actually moved our number. 2026-09-02 · 7 min read
- What does "/rc active" mean in Claude Code? The /rc active badge in your Claude Code footer means Remote Control is connected, so the session running on your machine can be driven from claude.ai or the Claude app. What turned it on, what it does with your data, what to do when it turns red, and how to switch it off. 2026-08-30 · 5 min read
- Claude Code status line: what actually earns a row The statusline script receives about forty fields and most setups display the four least useful ones. What to show instead (rate limit burn, context percentage, session identity), the performance trap that makes it go stale, and the gotchas that leave it blank. 2026-08-29 · 6 min read
- Claude Code and MCP, past the install command Adding an MCP server takes one command. Deciding which servers earn their place, what they cost your context window, and which of their features you are not using is the harder part. Scopes, auth without hardcoded tokens, the cost model, the four underused capabilities, and when a hook is the better answer. 2026-08-28 · 8 min read
- Claude Code security, with the right threat model The risk is not that the model turns on you. It is that an agent reads attacker-controlled text all day and runs commands you approved in a hurry. The permission layers that actually hold, how to configure the sandbox, why only hooks enforce anything, and the attack surface in the tooling you build around the agent. 2026-08-27 · 8 min read
- Claude Code plugins, and when you actually need one A plugin is not a new capability. It is packaging for the skills, subagents, hooks, and MCP servers you can already write, plus a way to version and share them. What plugins contain, which prebuilt ones are worth installing, how to convert a .claude directory into one, and the context cost nobody mentions. 2026-08-26 · 7 min read
- Claude Code memory: CLAUDE.md, rules, and the notes Claude keeps on you Most people know CLAUDE.md and stop there. The memory system has three layers, and the two you are probably ignoring are the ones that fix a bloated CLAUDE.md and explain why your instructions get followed only sometimes. Load order, path-scoped rules, auto memory, and what actually enforces anything. 2026-08-25 · 8 min read
- Claude Code plan mode, past the two-keystroke version Most people know plan mode as Shift+Tab twice. The mechanics matter more than the shortcut: what actually gets blocked, why commands still run while planning, why the approval prompt is a permission decision you make in a hurry, and how to keep a good plan from evaporating in the next compaction. 2026-08-24 · 5 min read
- Claude Code agent teams vs subagents: which one you actually need Claude Code now has three ways to run more than one agent, and they are not interchangeable. Subagents return a summary; agent teams are independent sessions that message each other; worktrees are you doing it by hand. What each is for, what an eight-agent pipeline taught us about making multi-agent work reliable, and the enable-flag trap that silently breaks orchestration. 2026-08-23 · 7 min read
- Claude Code Remote Control: what it replaces, and what it does not Remote Control lets you drive a Claude Code session on your machine from your phone or a browser. It is not a cloud session, and it does not make tmux obsolete. How to start it in the three modes, the requirements that trip people up, the "local process must keep running" rule that decides how to combine it with SSH, and how to pick between Remote Control, the web, and tmux. 2026-08-22 · 6 min read
- Claude Code skills: the missing manual Skills are the most misunderstood extension point in Claude Code, partly because they quietly absorbed slash commands. What a skill actually is, when a procedure deserves one instead of bloating CLAUDE.md, the four frontmatter features that do the real work, and the pitfalls the reference docs will not warn you about. 2026-08-21 · 5 min read
- Cursor vs Claude Code: the shape of the tool decides This is not a benchmark repost. Cursor and Claude Code are different shapes of tool (an editor you steer keystroke by keystroke versus an agent you delegate to), and that difference decides which one fits, what your day feels like, and what tooling you can build around it. How to pick, and why many developers keep both. 2026-08-20 · 5 min read
- Which spaced repetition app should you actually use? An honest map of the spaced repetition app landscape from someone who ships one. Anki is still the default answer, but the right app depends on where your cards come from and when you review. Picks by use case, the failure mode each app has, and who should skip each one. 2026-08-19 · 5 min read
- A Claude Code workflow you can run all day Not principles, a routine. The exact loop I run Claude Code in for a full workday: how a task starts, what happens during the turn, what happens when it ends, how parallel lanes work, and the fifteen minutes of maintenance that keep the whole thing from decaying. 2026-08-18 · 5 min read
- Claude Code best practices from a year of daily use Not a feature tour. These are the practices that survived a year of running Claude Code every day and building a product on top of its hook system: instruction files that stay small, permission rules that scale, hooks as gates, multi-session discipline, and verifying everything the agent claims. 2026-08-17 · 6 min read
- Claude Code and tmux: surviving SSH disconnects Claude Code dies with your SSH connection because it is a foreground process on a doomed terminal. tmux fixes that in one command. Here is the exact setup, plus the three things that quietly break inside tmux and how to fix each one. 2026-08-16 · 5 min read
- Codex vs Claude Code, from someone who wired into both I run both agents daily and built integrations against both of their extension systems. This comparison skips the benchmark reposts and covers what actually differs when you live in them: automation surface, session signals, workflow shape, and how to pick. 2026-08-15 · 6 min read
- Your DMG is notarized. The app inside it might not be. Signing, notarization, and stapling are three different things, and a ticket can be missing from four different places. How our release pipeline shipped a DMG whose inner app had no ticket, why that failure is invisible in your metrics, and the order of operations that fixed it. 2026-08-14 · 4 min read
- Your download count is lying to you Our first week showed 9 downloads and 1 install, which reads as a broken product. It was actually crawlers from OVH and AWS inflating the top of the funnel. How we classify bot traffic without an analytics SDK, and why the real fix was changing the denominator. 2026-08-13 · 5 min read
- Claude Code hook recipes: six configs worth stealing Beyond the finish notification: a permission-prompt alert, a turn journal, a guardrail for dangerous commands, auto-formatting after edits, a tests-must-pass gate, and forwarding to a local daemon. Complete configs, with the caveats that keep them from backfiring. 2026-08-12 · 4 min read
- localhost is not a security boundary Any web page your users visit can POST to their 127.0.0.1, no CORS preflight required. How we authenticate a local daemon with a token file, why denied requests still return 200, and two bugs we shipped anyway. 2026-08-11 · 5 min read
- Spaced repetition for programmers who quit Anki Developers are the ideal audience for spaced repetition and the worst audience for Anki. The problem is the contract, not the algorithm. Here is a guilt-free SRS design, with the actual scheduler we ship. 2026-08-11 · 5 min read
- Selling a desktop app with no accounts Unwait has no signup, no login, and no user database in the usual sense. Payment email is the identity, a license key is the credential, and lapsed users get a smaller app instead of a locked one. The design, and what real payments taught us that test mode did not. 2026-08-10 · 5 min read
- The invisible tar entries that broke our auto-updater macOS tar quietly stores extended attributes as ._ files, bsdtar hides them again on the way out, and a Rust tar parser turns them into real files that break your code signature. How our 0.1.6 update failed and the check that would have caught it. 2026-08-09 · 3 min read
- What Claude Code actually passes to your hooks Every Claude Code hook receives a JSON payload on stdin, and most example hooks throw it away. Here is the data contract for the events people actually wire up, and the things the payload cannot tell you. 2026-08-08 · 5 min read
- Building a macOS overlay that never steals focus Our overlay appears while you type in a terminal, so stealing a single keystroke kills the product. Here is the NSPanel setup that makes a window float without ever taking focus, in Tauri, with the traps we hit. 2026-08-07 · 4 min read
- How to get notified when Codex finishes Codex's notify key in config.toml runs a command when a turn ends, and it is still the simplest way to get a notification. The minimal setup, the JSON it passes as an argument, its sharp edges, and when to use Codex's newer lifecycle hooks instead. 2026-08-06 · 5 min read
- Why your Claude Code hooks do nothing over SSH If you run Claude Code on a remote box, your hooks live on the wrong machine and anything they talk to is on the wrong localhost. Here is what actually breaks and the SSH config that fixes it. 2026-08-05 · 3 min read
- Claude Code notifications: when it finishes, and when it is waiting on you The Stop hook fires when a turn ends and the Notification hook fires when Claude is blocked on you. Working configs for macOS, Linux, and Windows, per-project labels, the mobile push option, and why no notification is arriving when you swear the hook is right. 2026-08-04 · 7 min read