[ Blog_Posts ]

Codex ships 43,591 lines of sandboxing across four platform backends, and treats enforcement and approval as two separate axes. Pi ships none and says so in its README. Both are defensible. What is not defensible is the assumption in between, where a dialog box gets mistaken for a boundary. A source-level look at what your coding agent can actually do to your machine.

Read More

Claude Code's agent loop is 1,729 lines. Codex's is 983. Pi's is 794. Three teams, three languages, no shared code, and the loop lands in the same place every time. What does not converge is where each one puts its boundary, and that turns out to be the whole design. A source-level read of two harnesses that are now open, against one that leaked.

Read More

Sixty-five bytes are enough to kill llama.cpp. Not by corrupting memory, by handing the GGUF loader a tensor dimension of zero and letting a bounds check divide by it. The check was already there and looked correct. Zero is a legal dimension the format is supposed to support, which is why rejecting it was never the fix. A note on two crashes I fuzzed out of the loader, what the review changed, and why a downloaded model deserves the suspicion you give a downloaded executable.

Read More