Friendly Fire turns the security agent into the exploit
In 2026, AI Now showed RCE in Claude Code and Codex during third-party repo review; isolate permissions, sandbox, network and CI evidence before risky PRs.
|
I'm Samuel Fajreldines I am a specialist in the entire JavaScript and TypeScript ecosystem (including Node.js, React, Angular and Vue.js) I am expert in AI and in creating AI integrated solutions I am expert in DevOps and Serverless Architecture (AWS, Google Cloud and Azure) I am expert in PHP and its frameworks (such as Codeigniter and Laravel). |
|
Samuel Fajreldines I am a specialist in the entire JavaScript and TypeScript ecosystem (including Node.js, React, Angular and Vue.js) I am expert in AI and in creating AI integrated solutions I am expert in DevOps and Serverless Architecture (AWS, Google Cloud and Azure) I am expert in PHP and its frameworks (such as Codeigniter and Laravel).
|
21 articles · practical guides & tutorials by Samuel Fajreldines
In-depth Artificial Intelligence articles, hands-on guides and tutorials by Samuel Fajreldines — 21 expert posts on Artificial Intelligence for software engineers.
In 2026, AI Now showed RCE in Claude Code and Codex during third-party repo review; isolate permissions, sandbox, network and CI evidence before risky PRs.
In 2026, arXiv measured up to 85% hallucination in repo cloning; lock origin, MCP and CI before the agent executes.
In 2026, Wiz tested 6 coding assistants; learn how to review symlinks, sandboxing, and approvals before agents write outside the workspace.
In 2026, 0DIN showed a payload outside the repo; use agent quarantine with sandboxing, denied network, and no setup secrets.
In 2026, MCP research found 57 threats; use tool allowlists, private registries, CI gates, and logs for coding agents.
Build a self-correcting agent loop in CI with short logs, sandbox, retry limits, and reviewable PR proof without opening broad diffs or losing control.
In 2026, GitLab found 85% see review as the bottleneck; use executable specs so coding agents prove each change.
In 2026, Tenet reported 2,388 exposed organizations; treat Sentry MCP events as hostile input before Codex or Claude Code acts.
Claude Code documents 3 hook cadences; use gates before, after and at the end of the loop to reduce real risk across coding agents, MCP, shell and CI.
In 2026, one study measured over 20% higher cost from weak context files; write a lean AGENTS.md so Codex and Claude Code test better without token bloat.
In 2026, 85% see review and validation as the bottleneck; use subagent fan-out to migrate monorepos with proof, worktrees, and lean PR evidence for review.
In 2026, more than 1 in 5 GitHub reviews already run through Copilot; use codebase RAG over MCP for agent context on demand.
In 2026, GitHub had seen 60 million Copilot reviews; build PR evals in CI to validate agents before the reviewer.
In 2025, DORA measured 90% AI adoption in software teams; use lean context so coding agents work with better evidence.
In 2026, 85% of devs cite reviewing, editing, and testing AI code as the bottleneck. See a practical harness for reliable PRs, with gates, MCP, and subagents.
Claudiomiro is an AI-powered CLI that autonomously runs the full software development lifecycle: analyzing codebases, planning, and implementing complete…
A practical guide to building a native knowledge-graph system with MongoDB, S3 and LangChain that links entities and relationships to give AI real context.
Deep dive into implementing a production-ready AI fitness agent using LangChain.js with structured tools, proper prompting, and intelligent context retrieval.
Discover how Langchainjs orchestrates AI tool and function calling with the chain-of-thought paradigm, featuring a practical fitness app example.
A deep dive into Graphiti, Zep's open-source temporal knowledge-graph framework, plus a full blueprint for building a Personal Financial AI Coach that learns…
Discover how hiring ChatGPT Pro as a junior developer at $200/month revolutionized my software engineering workflow, boosting productivity and efficiency.