Working Code

Adam Tuttle, Ben Nadel, Carol Hamilton, Tim Cunningham

Water-cooler conversation about web-development. We want to entertain, inspire, and motivate you -- or to put it another way, make your coding career more enjoyable.

  1. 247: Trust Me Bro - LLM Security

    1D AGO

    247: Trust Me Bro - LLM Security

    Adam built a Claude Code skill for his Taffy REST framework and wanted to share it with the CFML community. Simple enough—create a GitHub repo, add some markdown files, done. But somewhere between "this is cool" and "anyone can install this," a familiar chill crept in. These skills are just text files. No checksums. No digital signatures. No verification that the thing you're installing won't quietly exfiltrate your code to some server in Eastern Europe. Sound familiar? It should. We've been here before—back when passwords lived in plain text and "security" meant hoping nobody looked too hard. The hosts dig into the unsettling parallels between today's LLM plugin ecosystem and the wild west of early internet security. LinksAdam's Dotfiles Blog Post - Getting his shit together with dotfiles, Brewfile, and 1Password SSH agentCF Community LLM Marketplace - Adam's community marketplace for CFML-related Claude skillsSteve Yegge's Google Platforms Rant - The infamous accidentally-public Google+ postVibe Coding by Gene Kim & Steve Yegge - The audiobook Ben's been enjoyingSocket.dev - Supply chain security for npm dependenciesFollow the show and be sure to join the discussion on Discord! Our website is workingcode.dev and we're @workingcode.dev on Bluesky. New episodes drop weekly on Thursday. And, if you're feeling the love, support us on Patreon. With audio editing and engineering by ZCross Media. Full show notes and transcript here.

    1h 2m
  2. 246: Ben's Feeling the Vibe

    JAN 29

    246: Ben's Feeling the Vibe

    Ben's been circling vibe coding for months, kept at bay by a simple fear: what if he spends more time fighting the AI over formatting than actually building anything? What if he has to bolt on linters and test runners just to babysit the output? Then his work handed him a Claude plan, and he decided it was finally time to take the plunge. And then something unsettling happened—the code looked like his code. Same line lengths. Same method ordering. Same obsessive formatting. Nobody told it to do that. It just... knew. Meanwhile, Adam has gone full mad scientist. His "Ralph" workflow runs Claude in a loop, feeding it tasks from a JSON file while he walks away to eat dinner. When he comes back, features are done. Tests pass. The machine just keeps building. It's the kind of setup that makes you wonder why you're still manually typing commands into a terminal. LinksAdam's Ralph Workflow for Claude Code - Adam's blog post with his implementationMatt Pocock's Ralph Primer Video - The workflow Adam adapted for automated iterative developmentAlgorithm Maze Race - Tim's vibe-coded game on itch.ioPro tip: Use /resume in Claude Code to return to prior sessionsFollow the show and be sure to join the discussion on Discord! Our website is workingcode.dev and we're @workingcode.dev on Bluesky. New episodes drop weekly on Thursday. And, if you're feeling the love, support us on Patreon. With audio editing and engineering by ZCross Media. Full show notes and transcript here.

    1h 19m
5
out of 5
26 Ratings

About

Water-cooler conversation about web-development. We want to entertain, inspire, and motivate you -- or to put it another way, make your coding career more enjoyable.

You Might Also Like