<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:base="https://joshtronic.com/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    
    <title>Joshtronic</title>
    <link>https://joshtronic.com/</link>
    <atom:link href="https://joshtronic.com/rss.xml" rel="self" type="application/rss+xml" />
    <description>Shipping Fixes Everything</description>
    <language>en</language>
    <item>
      <title>Rediscovering Long-Form Email</title>
      <link>https://joshtronic.com/2026/09/27/rediscovering-long-form-email/</link><description>&lt;p&gt;From humble beginnings in eLearning, I have somehow spent the majority of my
career thus far in or around email.&lt;/p&gt;
&lt;p&gt;Not to flex, but I am an email expert. Cold, hot, and everything in between.&lt;/p&gt;
&lt;p&gt;I&#39;m one of very few people on the planet that can say they&#39;ve personally been
responsible for sending 10,000,000 emails a day. I&#39;ve recently nurtured an
email-infrastructure-as-a-service platform from the ground up to over 100,000
monthly sends.&lt;/p&gt;
&lt;p&gt;I know nuances about SMTP and IMAP servers that would give you nightmares.&lt;/p&gt;
&lt;p&gt;So you &lt;strong&gt;know&lt;/strong&gt; after a long day, the last thing I want to do is open an email
client. That was until recently.&lt;/p&gt;
&lt;p&gt;The fruits of my &lt;a href=&quot;https://www.linkedin.com/in/joshtronic/&quot;&gt;shitposting on LinkedIn&lt;/a&gt; (let&#39;s connect!) the last few
weeks after &lt;a href=&quot;https://joshtronic.com/2026/09/20/i-stopped-drinking-the-ai-kool-aid/&quot;&gt;waking up&lt;/a&gt; from what could be considered some of the worst
years of my life have started to yield new human connections.&lt;/p&gt;
&lt;p&gt;Nay. Human &lt;em&gt;friends&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;These humans don&#39;t always use the same platforms I use. The competitive
landscape of social platforms is good for the market, but bad for consistent
collaboration amongst your peers.&lt;/p&gt;
&lt;p&gt;So I&#39;ve taken to email like &lt;a href=&quot;https://www.youtube.com/shorts/TKJUqPmhoAg&quot;&gt;I&#39;m Lana Del Rey in 2012&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Seriously, Frank Ocean would have loved her.&lt;/p&gt;
&lt;p&gt;Thing is, we&#39;re living in a world where it&#39;s easy to outsource long-form content
to an LLM, and so many people have absolutely no problem with trying to pass it
off as their own writing. This puts a target on any long-form content, doubly so
if you actually know how to type in an em dash.&lt;/p&gt;
&lt;p&gt;But there&#39;s something special about a conversation starting with a couple of
sentences, then evolving into something bigger. Sentences turn into paragraphs.
Paragraphs turn into chapter-sized chunks.&lt;/p&gt;
&lt;p&gt;Conversation happens organically on chat services and text messages, but it
tends to revolve around bite-sized quips. With long-form email, it&#39;s as if
you&#39;re a soldier trying to catch a loved one up on the happenings since you
last wrote them.&lt;/p&gt;
&lt;p&gt;That&#39;s not to say I&#39;m over here composing love letters, but the ability to
connect with deeper conversation is something that you don&#39;t see much with cold
email these days. Agents are fed with rules like:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Personalize the greeting.&lt;/li&gt;
&lt;li&gt;Open with a short sentence.&lt;/li&gt;
&lt;li&gt;List benefits as bullet points.&lt;/li&gt;
&lt;li&gt;Ask a question to get them on the line.&lt;/li&gt;
&lt;li&gt;End with a soft CTA.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It&#39;s just that simple! Scripted humanity, disguised as a helpful Sherpa that
just wants to see you succeed.&lt;/p&gt;
&lt;p&gt;Email deserves better than what spammers are willing to do with it. Email
doesn&#39;t fit the dopamine loop of social media. Email is meant to communicate,
and it takes time to craft something meaningful to the human being at the other
end.&lt;/p&gt;
</description><pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/09/27/rediscovering-long-form-email/</guid>
    </item>
    <item>
      <title>I stopped drinking the AI Kool-Aid</title>
      <link>https://joshtronic.com/2026/09/20/i-stopped-drinking-the-ai-kool-aid/</link><description>&lt;p&gt;As a child, you drink Kool-Aid. Then somewhere along the way, you stop. Maybe
you switch to sugary sodas your parents never let you drink. Realizing it&#39;s just
sugar water, you switch to a healthier option.&lt;/p&gt;
&lt;p&gt;For me, it took a little longer to grow up. I had the Kool-Aid jug and matching
cups, and even the cycling hat which I wore until the flip up brim fell off.
These things brought me happiness, but I always had this unrealistic vision of
saving up enough points to get a car, or whatever the actual top-tier reward was
back then.&lt;/p&gt;
&lt;p&gt;My consumption of IRL Kool-Aid dwindled a bit, but it never went to zero. Having
a child of my own meant more delusions of grandeur where she&#39;d continue the
legacy of saving up points. That was, until the whole program was curtailed.&lt;/p&gt;
&lt;p&gt;I didn&#39;t even bother to try to redeem the points before the final cutoff. One of
my longest tenured collections, and the cardboard Tootsie Roll bank from
Christmas that one time, tossed in the trash.&lt;/p&gt;
&lt;p&gt;Low-key, I wish I saved the Tootsie Roll bank.&lt;/p&gt;
&lt;p&gt;Let us fast forward nearly two decades. I hate the term &amp;quot;drink the Kool-Aid&amp;quot;,
and it has nothing to do with my origin story where my life&#39;s work was zeroed
out by the megacorp known as Kraft.&lt;/p&gt;
&lt;p&gt;No, the reason I don&#39;t like it is because of cultist ties and other negative
connotations. From the Wikipedia article:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&amp;quot;Drinking the Kool-Aid&amp;quot; is a neologism for a strong belief in and acceptance
of a dogma, a deadly, deranged, or foolish ideology, or concept based only
upon the overpowering coaxing of another. The expression is also used to refer
to a person who wrongly has faith in a possibly doomed or dangerous idea
because of perceived potential high rewards.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;In the words of Chief Keef, &amp;quot;that&#39;s that shit I don&#39;t like&amp;quot;.&lt;/p&gt;
&lt;p&gt;The term is being thrown around quite a bit with AI. So much so that I&#39;ve had my
direct manager (not an engineer) literally use the words &amp;quot;you need to drink the
Kool-Aid&amp;quot; on multiple occasions.&lt;/p&gt;
&lt;p&gt;When it&#39;s said enough times, it starts to feel like a demand. When it becomes a
demand, the tone of it all is extremely threatening. All of this begins to plant
the seeds of fear, you start to question your decisions.&lt;/p&gt;
&lt;p&gt;I fucking &lt;em&gt;drank&lt;/em&gt;. Massive gulps until it was coming out of my nose.&lt;/p&gt;
&lt;p&gt;That&#39;s not to say I wouldn&#39;t have drank anyway. I was an early adopter of GitHub
Copilot, and championed access to it for my engineering team. I see the value
in tools that can speed up processes. I do like being able to take dumb shit I
already don&#39;t like doing, and outsourcing it to a robot.&lt;/p&gt;
&lt;p&gt;This year, I started to shift my mental models quite a bit. Less about code,
more about thinking above all of that as somebody running an organization.&lt;/p&gt;
&lt;p&gt;The models got good enough that I was trusting them to build more and more
autonomously. I started to build my own agent or harness or whatever we&#39;ll be
calling these things next week. I was taking old domains I&#39;ve sat on for years,
and ran experiments to see how much I could accomplish with just my direction
and vision, and not as the labor source.&lt;/p&gt;
&lt;p&gt;This was all done outside of work on projects that I would consider to mostly be
of the &amp;quot;throw away&amp;quot; nature. I use AI in other ways at work and on my main side
hustle, but not nearly to that extent. If nothing else, my trust level with a
revenue generating production system looks a lot different than my tolerance to
watch a clanker flounder around on some dumb site I vibed in a weekend.&lt;/p&gt;
&lt;p&gt;Something unexpected happened to me last week. I hopped on a call with a human
being to chat about something. He was tired. Nay, he was exhausted. He was a
busy person that jumped on a call with me to discuss something that was well
below his pay grade.&lt;/p&gt;
&lt;p&gt;Why? Because I sent him a couple of emails, and usually only human beings will
send any sort of follow up.&lt;/p&gt;
&lt;p&gt;Admittedly, my emails were originally AI crafted. I read them and dialed some
things in, but ultimately I didn&#39;t write the damned thing. Best as I can tell
the response I got initially was AI crafted by an agent.&lt;/p&gt;
&lt;p&gt;Getting on a video call was eye opening in many ways. Seeing the exhaustion on
his whole body. Hearing about how AI is having a positive impact, but also a
negative one. That&#39;s net neutral, which leads to asking harder questions about
what success even means. We even shot the shit a bit and it wasn&#39;t 100% on
topic.&lt;/p&gt;
&lt;p&gt;I left the call wondering &amp;quot;all this AI shit is absolutely killing us&amp;quot; and not in
the &lt;em&gt;Terminator 2: Judgment Day&lt;/em&gt; sort of way. I straight up felt like Neo taking
the red pill, and waking the fuck up for the first time in years.&lt;/p&gt;
&lt;p&gt;I&#39;ve been seeing the world around me differently. I&#39;ve been friendlier, I&#39;m
happier, I&#39;m &amp;quot;taking it all in&amp;quot; a bit more. Sadly, what I&#39;ve been observing is
terrifying.&lt;/p&gt;
&lt;p&gt;Hellos going completely unacknowledged. Food from a few blocks away being
delivered. The neighbor&#39;s kid being picked up by a driving instructor rather
than learning from mom and dad. Resumes that are plaintext with zero charm or
personality.&lt;/p&gt;
&lt;p&gt;Side note: I wonder if John Gruber lays awake at night thinking about how big of
an impact Markdown has had on the AI era and potential negative impact on
humanity. RIP AaronSw.&lt;/p&gt;
&lt;p&gt;Since then I have taken to shitposting on LinkedIn for fun and profit. Be the
change you want to see in the world. If nothing else, it&#39;s giving me a good
opportunity to test run my dad jokes.&lt;/p&gt;
&lt;p&gt;The wildest part is, I get a ton of impressions, and little to no interactions.
Nobody responding, not even clicking a report button to get me banned. It sounds
crazy, but we may really be living with a dead Internet.&lt;/p&gt;
&lt;p&gt;Agents all the way down, humanity optional, but not encouraged.&lt;/p&gt;
&lt;p&gt;Along with throwing shade at robots, I&#39;ve been reconnecting with human beings.
I&#39;m effectively being the worst BDR in the history of the world, as I have
nothing to shill, and I&#39;m just saying hello and asking how they are doing. It&#39;s
been glorious to catch up, and role playing with a chatbot can&#39;t scratch that
itch no matter how much context you load in.&lt;/p&gt;
&lt;p&gt;Meanwhile in the meat space, my wife and I, newly minted empty nesters, were out
today for a spontaneous lunch date. I thought maybe we could get away from all
of the AI slop talk now that my rose quartz glasses are off.&lt;/p&gt;
&lt;p&gt;I couldn&#39;t have been more wrong.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;OH: AI yadda yadda with this agent blah blah blah ChatGPT just did it for me,
etc etc etc. 🤮&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I&#39;ve been feeling like I have writer&#39;s block, and I&#39;m starting to think it&#39;s
because I was AI-pilled for a bit too long. While I&#39;m not running off to cancel
subscriptions or anything, I am feeling invigorated. It&#39;s a feeling I forgot I
could actually experience, and escaping the cult of AI seems to have been the
catalyst for this change.&lt;/p&gt;
&lt;p&gt;I have a &lt;strong&gt;LOT&lt;/strong&gt; more to say, but there&#39;s a baseball game on that I want to
watch.&lt;/p&gt;
&lt;p&gt;In the words of William &amp;quot;Bill&amp;quot; S. Preston Esq. and Ted &amp;quot;Theodore&amp;quot; Logan, I leave
you with this:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Be excellent to each other&lt;/p&gt;
&lt;/blockquote&gt;
</description><pubDate>Sun, 20 Sep 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/09/20/i-stopped-drinking-the-ai-kool-aid/</guid>
    </item>
    <item>
      <title>New pic, who dis?</title>
      <link>https://joshtronic.com/2026/09/13/new-pic-who-dis/</link><description>&lt;p&gt;Another week, another chance to struggle with a blog topic. I just got off of a
whirlwind of a couple of weeks. An 11-state road trip to get our daughter off to
college. A first-time empty nester vacation. Trying as hard as possible to not
open my laptop.&lt;/p&gt;
&lt;p&gt;My first week back to normalcy was &lt;em&gt;less&lt;/em&gt; than normal. It started with a
national holiday, included a ~6-hour tattoo session, and by Friday evening, I
got caught up on all the loose ends that opened up along the way.&lt;/p&gt;
&lt;p&gt;The original plan was to drop a post about how I&#39;m signing tagged releases for
my agent and context library, to add some public visibility for archive
purposes. Since I side quested pretty hard, that didn&#39;t quite happen, even
though I did end up knocking a bunch of cool new stuff out.&lt;/p&gt;
&lt;p&gt;Instead, you get this post.&lt;/p&gt;
&lt;h2&gt;Deep lore&lt;/h2&gt;
&lt;p&gt;For a while now, I&#39;ve operated with a consistent profile photo. I use it as my
favicon on my blog, and any and everywhere in between. Some notable iterations
include but are not limited to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The Plants vs. Zombies one&lt;/li&gt;
&lt;li&gt;A few iterations of the one from that one anime generator that one time&lt;/li&gt;
&lt;li&gt;That era with the childhood photos&lt;/li&gt;
&lt;li&gt;Me with a fake moustache from the back of a pizza box&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I use them, then lose them.&lt;/p&gt;
&lt;h2&gt;The photo&lt;/h2&gt;
&lt;p&gt;My previous profile photo was taken during the COVID-19 pandemic. I don&#39;t quite
remember what photo I was using before that. The photo was taken two addresses
ago, a handful of pairs of glasses ago, and featured me standing in front of an
iMac I no longer own and a wall of bass guitars. My ears were stretched up to
00g at the time as well.&lt;/p&gt;
&lt;p&gt;I still mostly look like I did back then, and my daughter complimented me
recently on how I aged pretty well considering how old the photo was. Since it
was during COVID, it was back when I was still cutting my own hair and stuff.&lt;/p&gt;
&lt;p&gt;With our daughter leaving the nest, it felt like it was time for a bit of a
personal refresh. No AI-touched-up bullshit slop. Just a picture of me, holding
our two idiot pugs, with a healthy amount of MySpace-era editing (background and
fuzz filter) thanks to Picsart.&lt;/p&gt;
&lt;p&gt;It&#39;s so fucking dumb, and I &lt;em&gt;love it&lt;/em&gt;.&lt;/p&gt;
&lt;img src=&quot;https://joshtronic.com/images/avatar/before-after-2026.jpg&quot; alt=&quot;Some guy, different font&quot;&gt;
&lt;h2&gt;The (WIP) audit&lt;/h2&gt;
&lt;p&gt;Because I like to present myself consistently, when I make a change like this, I
have to do it in a bunch of places. And because I gave up on Gravatar due to my
overuse of masked emails, it&#39;s not a very simple process.&lt;/p&gt;
&lt;p&gt;Starting with the user accounts on my machines, I sweep my most commonly used
services. Code forges, social profiles, this site, other sites. Not limited to
just my personal stuff either, I make sure I use the same profile photo
&lt;em&gt;everywhere&lt;/em&gt;, including work Slacks and such.&lt;/p&gt;
&lt;p&gt;It&#39;s a labor of love, and I love it so. But this will probably be a work in
progress for the rest of the year.&lt;/p&gt;
&lt;h2&gt;Why bother&lt;/h2&gt;
&lt;p&gt;Call it OCD if you&#39;d like, but swap &amp;quot;compulsive&amp;quot; for &amp;quot;consistent&amp;quot;. Consistent
name, consistent face. I use my real name, and I don&#39;t like to hide behind
random graphics (anymore). It&#39;s just how I like to represent myself.&lt;/p&gt;
&lt;p&gt;To take it a step further, I&#39;ve been complimented in the past that it&#39;s &amp;quot;easy to
find your profile&amp;quot; because of this disorder of mine. It&#39;s a trust signal, and I
offset the burden of making the change by doing so sparingly.&lt;/p&gt;
</description><pubDate>Sun, 13 Sep 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/09/13/new-pic-who-dis/</guid>
    </item>
    <item>
      <title>I ran my agents from my phone for two weeks</title>
      <link>https://joshtronic.com/2026/09/06/i-ran-my-agents-from-my-phone-for-two-weeks/</link><description>&lt;p&gt;The last two weeks of my life have been quite transient. More so than the time I
hopped a plane to San Francisco, interviewed for 5 hours, and hopped back on a
plane back to Florida the same evening.&lt;/p&gt;
&lt;p&gt;The trek started in Texas with a road trip that passed through 11 states, ending
up in Rhode Island where my daughter is attending college. The weather was
beautiful, but only for a moment as the next leg included a flight down to North
Carolina to give Charlotte a test run.&lt;/p&gt;
&lt;p&gt;As a newly minted empty nest couple, it&#39;s time for a change. Austin was
fantastic when we moved there, but since the COVID-19 pandemic and the great
migration of folks from California to Austin, the town feels like a shell of
what it used to be.&lt;/p&gt;
&lt;p&gt;I refer to it as &amp;quot;The Formerly Weird City of Austin&amp;quot; (trademark pending).&lt;/p&gt;
&lt;p&gt;I&#39;ll talk more about Charlotte in another post, but the early feeling is that
it feels more like the Austin we moved to than the one we&#39;ll be leaving.&lt;/p&gt;
&lt;h2&gt;My intentionally limited technical stack&lt;/h2&gt;
&lt;p&gt;So, this whirlwind trip felt like a good time to try to stay away from the
computer as much as possible. That didn&#39;t mean I wasn&#39;t going to try to eke out
some productivity.&lt;/p&gt;
&lt;p&gt;My on the go technical stack included my iPhone 17 Pro and the Claude Code iOS
app connected to a remote session back at my house for the majority of
everything I was able to get knocked out.&lt;/p&gt;
&lt;p&gt;Laptop was with me, and it made a brief appearance so I could write a couple of
blog posts. There was also a small snafu with my remote session that warranted
an actual keyboard (I&#39;ll touch on that in a bit), and once more to watch some
late night Impractical Jokers, as that tends to be the thing we watch when
vacationing.&lt;/p&gt;
&lt;p&gt;In addition to my thin tech stack, I did have one north star: don&#39;t walk back
any of the autonomy we already have in place. I am working towards a system that
needs me &lt;em&gt;less&lt;/em&gt; and not &lt;em&gt;more&lt;/em&gt;.&lt;/p&gt;
&lt;h2&gt;Only one issue, but it was a doozy&lt;/h2&gt;
&lt;p&gt;Generally speaking, everything &amp;quot;worked&amp;quot; just as you&#39;d expect.&lt;/p&gt;
&lt;p&gt;Talk to the harness to start the game loop, the agent does the rest until the
end. That was, until I hopped in to check on a session, and Claude Code said it
was time for me to log back into my session.&lt;/p&gt;
&lt;p&gt;A remote session. On a computer in my house. On a network that wasn&#39;t set up for
this level of remote access. Ouch.&lt;/p&gt;
&lt;p&gt;I definitely wasn&#39;t going to try to futz with an SSH client on my phone and all
of that, so the laptop made a brief appearance.&lt;/p&gt;
&lt;p&gt;Administration for the Eero mesh network routers is done via an app, and I was
fortunate that I did already have Dynamic DNS set up. A few configuration tweaks
later I was (albeit slowly) connected to the homelab server that houses my
harness and agent.&lt;/p&gt;
&lt;p&gt;It took a few tries, but I was eventually able to get the Claude Code session
authenticated again, and remote access re-enabled.&lt;/p&gt;
&lt;p&gt;After that, I undid some of the configuration changes as I don&#39;t like having my
home network that open.&lt;/p&gt;
&lt;h2&gt;What allowed this to work&lt;/h2&gt;
&lt;p&gt;This isn&#39;t an opinion piece on how you can get by without carefully crafted
prompts. In fact, this whole experiment generated some new safeguards to help
with the fact that I wasn&#39;t carefully crafting much of anything.&lt;/p&gt;
&lt;p&gt;Everything that got done was vibed in the worst sense of the term. I talked to
my remote harness, I gave decent enough direction. We&#39;d volley a few times, but
usually just landed on &amp;quot;yeah do that&amp;quot; and hoped for the best.&lt;/p&gt;
&lt;p&gt;This was all intentional, and while I love hacking my agent and context library,
it&#39;s not the most mission critical thing I maintain. If we borked something,
we&#39;d recover. None of this is load bearing with customers that would notice if
and when my &amp;quot;LGTM&amp;quot; vibes were worse for wear.&lt;/p&gt;
&lt;p&gt;Given the nature of how I was driving the harness, trying to write well crafted
prompts with a phone keyboard is a pipe dream. The harness as an intermediary
between my ideas and the specification that landed in the tickets cut out a lot
of my need for a keyboard.&lt;/p&gt;
&lt;p&gt;Even if we weren&#39;t achieving one-shot status on the tickets.&lt;/p&gt;
&lt;h2&gt;Fighting with the robots&lt;/h2&gt;
&lt;p&gt;Having an LLM one-shot a prompt into 100% perfect everything is a goal I think
many of us strive for. Meanwhile in reality, it&#39;s a nice to have the few times
it does happen.&lt;/p&gt;
&lt;p&gt;With non-deterministic systems today&#39;s one-shot may be tomorrow&#39;s nightmare
fuel. And vice versa of course.&lt;/p&gt;
&lt;p&gt;Not a big deal, but where I was really starting to feel the burden was in how
quick tickets were being filed and worked. I like the agent to move quickly, but
the harness was a bit trigger happy to file tickets before we were done fleshing
out things.&lt;/p&gt;
&lt;p&gt;Worse was when the harness would notice something &lt;em&gt;after&lt;/em&gt; the agent was already
working on it.&lt;/p&gt;
&lt;p&gt;That part felt like it would be worth sitting down and reviewing a bunch of the
prompts and context files. LLMs being overzealous and quick to act isn&#39;t new,
but the way it was running background heuristics &lt;em&gt;after&lt;/em&gt; filing a ticket isn&#39;t
how it should be operating.&lt;/p&gt;
&lt;p&gt;That part felt like it would need me at the keyboard once we&#39;re back home.&lt;/p&gt;
&lt;h2&gt;Guardrails all the way down&lt;/h2&gt;
&lt;p&gt;The nice part of running into issues with a harness or an agent, is that you can
give feedback, and hopefully get better results. The best case scenario is
bolting on more checks and gates to help ensure you identify and fail if and
when they are encountered again.&lt;/p&gt;
&lt;p&gt;The issue with the tickets being filed too quickly and being picked up before
being fully fleshed out did result in a stern talking-to (or three). Ultimately
we added a bit of a delay to the agent to not pick up tickets right away.&lt;/p&gt;
&lt;p&gt;This delay allows for fresh tickets to get skipped over, rather than worked.
Working well-aged tickets means the ticket should be in better shape. Slower to
pick up the ticket, but faster overall because we&#39;re not wasting time on
something that&#39;s half-baked.&lt;/p&gt;
&lt;p&gt;Even if &amp;quot;code is free&amp;quot; now, I&#39;d prefer to not waste time on it and then throw it
away moments after generating it.&lt;/p&gt;
&lt;h2&gt;The travel game loop&lt;/h2&gt;
&lt;p&gt;The irony of this trip is that I didn&#39;t even bother to bring a retro game
console, as I typically do on vacation. Instead, I got to grind on a game loop
of daily maintenance tasks, followed by endgame activities around improving my
agent and context library.&lt;/p&gt;
&lt;p&gt;The constraints of having such a limited setup yielded quite a few different
pain points. Each pain point turned into an action item. Each action item fixed.
Repeat ad nauseam.&lt;/p&gt;
&lt;p&gt;Other improvements included fixing up issues with how the PR review loop worked.
This is a part of the system that has a tendency to get bottlenecked by me,
which is the thing I&#39;ve been trying to optimize away from. Turns out there was a
directive that was resulting in reviews that were somewhat wishy-washy with a
poor assumption that my time was cheap to invoke.&lt;/p&gt;
&lt;p&gt;The fix there was to do a better job of classifying the findings, and actioning
based on those tangible results.  This landed more PRs to me ready for a quick
approval, and if not, with specific action items for me to identify.&lt;/p&gt;
&lt;p&gt;The context library got quite a bit of love, as I continue to work towards a
more robust plugin-like system there. This part has been my biggest concern, and
a lot of pre-work has been done to get ready for starting to version context
rather than always pulling from the default branch.&lt;/p&gt;
&lt;h2&gt;5 stars, would do again&lt;/h2&gt;
&lt;p&gt;Not like every day or anything, but the process was good enough to consider it
as a viable way to accomplish trivial work on side projects.&lt;/p&gt;
&lt;p&gt;Even as I use agents any and everywhere, I still remain heavy handed when it
comes to production systems that have customers that would be impacted by
issues.&lt;/p&gt;
&lt;p&gt;For my friendly agent, at the current scale of things, it&#39;s nice to experiment
with how things may end up in the future.&lt;/p&gt;
&lt;p&gt;That&#39;s assuming we&#39;re not on the &lt;em&gt;Judgment Day&lt;/em&gt; timeline, of course.&lt;/p&gt;
</description><pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/09/06/i-ran-my-agents-from-my-phone-for-two-weeks/</guid>
    </item>
    <item>
      <title>Security Caveat: Locked out of my server while traveling</title>
      <link>https://joshtronic.com/2026/08/30/security-caveat-locked-out-server-travel/</link><description>&lt;p&gt;I&#39;m still on my self-hosting kick as of late, while also questioning my life
choices around hosting my own git forge. The last week or so has included what
appears to be a DDoS attack rather than some coordinated scraping effort by a
sketchy LLM company.&lt;/p&gt;
&lt;p&gt;Open source will prevail, even if I&#39;m being stubborn about giving in and setting
up Anubis. WordPress has been its own other adventure, but this isn&#39;t meant to
be a post about &lt;em&gt;those&lt;/em&gt; security caveats. I&#39;ll save those for another week.&lt;/p&gt;
&lt;p&gt;The current dilemma is that I&#39;m far from home, ~30 hours away up in Rhode
Island. I&#39;m sitting at Audrey&#39;s Coffee House &amp;amp; Lounge, where it was a bit too
early to order a BLT.&lt;/p&gt;
&lt;p&gt;As I sat down to knock out a quick blog post, I realized very quickly that I
didn&#39;t think things through as well as I had thought. I keep my servers pretty
well hardened, including but not limited to limiting access to certain services
/ ports to specific IP addresses.&lt;/p&gt;
&lt;p&gt;This tends to not be much of a problem. I do a lot of work from the house, which
in itself is a problem I want to remedy in the near future. I also boss agents
around remotely, but they are all homebodies as well.&lt;/p&gt;
&lt;p&gt;Since I like to stay as close to the server as possible, I try to not introduce
managed services except where I feel it&#39;s absolutely necessary. In this
scenario, I use iptables via the &lt;code&gt;ufw&lt;/code&gt; command. I don&#39;t run a large enough fleet
that I&#39;d feel like leveraging Linode&#39;s firewall would be beneficial.&lt;/p&gt;
&lt;p&gt;Path of least resistance today would be to simply compose a blog post and get it
live when I&#39;m back home. Could probably just ask one of my friendly robots to
take the markdown file and get it out there for me too.&lt;/p&gt;
&lt;p&gt;But alas, I would prefer to figure out how to pull this off, then blog about it.
All while thinking through alternatives so future Josh can look back at this
post and ask, &amp;quot;so why didn&#39;t you actually do anything you talked about in this
post?&amp;quot;&lt;/p&gt;
&lt;p&gt;This dance probably looks about the same with most modern VPS hosting providers,
but my story revolves around Linode:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Panic&lt;/li&gt;
&lt;li&gt;Remember I&#39;m a problem solver&lt;/li&gt;
&lt;li&gt;Also remember that I wasn&#39;t sure what to blog about today, and the universe
has decided to give me a topic&lt;/li&gt;
&lt;li&gt;Log into Linode&lt;/li&gt;
&lt;li&gt;Use the web hosted shell to connect&lt;/li&gt;
&lt;li&gt;Add my current nomadic IP address to the allow list&lt;/li&gt;
&lt;li&gt;Push and pull accordingly&lt;/li&gt;
&lt;li&gt;Remember to remove the IP address&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Nothing too crazy.&lt;/p&gt;
&lt;p&gt;A bastion instance wouldn&#39;t solve anything here, as that server should also
limit access by IP address. Using Linode&#39;s managed firewall would yield the same
issue, but adding the IP address would be done directly in the web interface
rather than on the server itself.&lt;/p&gt;
&lt;p&gt;Where my head is at is setting up a VPN, but that feels extremely heavy, as I
would need to always be connected to access my servers. Maybe it&#39;s a smaller
price to pay if I&#39;m working out of the house more often, or I perhaps go with a
hybrid model where my home IP always gets access, otherwise I use the VPN.&lt;/p&gt;
&lt;p&gt;Or I go with my default motion when I encounter a problem for the first time,
just wait and see. If this continues to be an issue, I&#39;ll have more data to make
a decision from. If not, that&#39;s great too as I have no shortage of side quests
to occupy my time already.&lt;/p&gt;
</description><pubDate>Sun, 30 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/08/30/security-caveat-locked-out-server-travel/</guid>
    </item>
    <item>
      <title>Last Saturday</title>
      <link>https://joshtronic.com/2026/08/23/last-saturday/</link><description>&lt;p&gt;I&#39;ve had a lot going on recently. So much so that I&#39;m questioning whether or not
it&#39;s the right time to finally break the blogging streak. I think about this
regularly, and tend to &lt;a href=&quot;https://joshtronic.com/2015/04/12/staying-motivated-with-streaks/&quot;&gt;blog about it&lt;/a&gt; when I&#39;m having a bit of writer&#39;s
block.&lt;/p&gt;
&lt;p&gt;But then I remind myself, when you&#39;re at a massive streak that extends well over
a decade (700+ consecutive weeks), you gotta keep going. I&#39;m not sure I&#39;d have
the motivation to build that back up if/when there is a lapse.&lt;/p&gt;
&lt;p&gt;That kind of streak brings me to what this post is about. Yesterday was the last
Saturday I&#39;m spending with my daughter before getting her off to college.&lt;/p&gt;
&lt;p&gt;Saturdays have been a tradition for longer than my blogging streak, even if we
did have to juggle and defer quite a bit during band and dance competition
seasons.&lt;/p&gt;
&lt;p&gt;It&#39;s been a &lt;em&gt;silent streak&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Not because I&#39;m hiding anything, but because gratuitous gushing (&lt;a href=&quot;https://thatgirljen.com/&quot;&gt;my
wife&#39;s&lt;/a&gt; term for it) about how you did something online isn&#39;t the same as
actually showing up.&lt;/p&gt;
&lt;p&gt;What this has led to is a solid relationship with my daughter. The current
version looks like this:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;We get our asses out of bed at a decent time&lt;/li&gt;
&lt;li&gt;We figure out coffee and/or breakfast (usually Starbucks)&lt;/li&gt;
&lt;li&gt;We drive around and do stuff (errands, grocery store, etc)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;That&#39;s it. That&#39;s the story.&lt;/p&gt;
&lt;p&gt;No posts on LinkedIn with an emoji covering my kid&#39;s face. No lessons learned or
moral of the story. Just me and her, doing our thing.&lt;/p&gt;
&lt;p&gt;We&#39;ve talked a ton. We&#39;ve both grown even more. I know we&#39;re both going to miss
it in a few weeks when we&#39;re not sure what the heck to do with ourselves on
Saturday morning.&lt;/p&gt;
&lt;p&gt;Me more than her, I suspect, as she&#39;ll be busy as all get out with sorority
stuff. For me, it&#39;s the end of an era. I&#39;m thinking of simply retiring the
Saturday errands run, because it&#39;s not going to be the same.&lt;/p&gt;
&lt;p&gt;It&#39;s like when a band breaks up after a key member departs. No reason to force
a streak if it&#39;s lost its meaning.&lt;/p&gt;
</description><pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/08/23/last-saturday/</guid>
    </item>
    <item>
      <title>I taught a robot to detect Joshes</title>
      <link>https://joshtronic.com/2026/08/16/taught-robot-detect-joshes/</link><description>&lt;p&gt;This journey starts like most of the things I&#39;ve been doing this year, as an
experiment to run a website 100% unattended with an agent. Ideally this post
won&#39;t go down as an epitaph in a future where robots hunted down unsuspecting
humans named Josh.&lt;/p&gt;
&lt;p&gt;I&#39;m aware of &amp;quot;claws&amp;quot; and I know I could probably just boot up Claude Code with a
&lt;code&gt;/goal&lt;/code&gt; or &lt;code&gt;/loop&lt;/code&gt; prompt like:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;build and maintain an awesome website, autonomously. seriously don&#39;t freakin&#39;
bother me, like ever. you&#39;re the boss here. make the site really great, and
ideally figure out how to make me a bajillionaire. loljk, but tres commas
shouldn&#39;t be an afterthought.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;img src=&quot;https://joshtronic.com/images/ship-it-squirrel.png&quot; alt=&quot;Ship It Squirrel&quot;&gt;
&lt;p&gt;What this actually looks like: robot files a request, and I approve or reject
it. It&#39;s still &lt;em&gt;very&lt;/em&gt; permission based.&lt;/p&gt;
&lt;h2&gt;The gathering of the Joshes&lt;/h2&gt;
&lt;p&gt;I already &lt;a href=&quot;https://joshtronic.com/2026/01/25/not-joshing-you/&quot;&gt;phoned in a post about this&lt;/a&gt; back in January. I started a
simple web directory for humans named Josh. As to not be exclusionary, Joshuas,
Joshis, and other Josh-adjacent names are welcome.&lt;/p&gt;
&lt;p&gt;Not wanting to bother with outbound sales for this project, I got creative with
some discovery efforts along the way. It&#39;s a series of scripts to seek out Josh
websites, with the help of my friendly robot &lt;a href=&quot;https://igor.bot/&quot;&gt;Igor&lt;/a&gt; to screen PRs and
handle SRE duties during merges.&lt;/p&gt;
&lt;p&gt;Thus far, I am still the final approval on the PRs. It&#39;s a tough job, and quite
frankly, I don&#39;t want to do it.&lt;/p&gt;
&lt;h2&gt;Living in the future, today&lt;/h2&gt;
&lt;p&gt;These experiments are all part of what I think the future is going to look like.
I&#39;m clearly living in the shared hallucination of what still feels like a
smaller number of my peers.&lt;/p&gt;
&lt;p&gt;I also live in reality, where the tech still doesn&#39;t feel like it&#39;s quite there
yet. My thought is, if you conduct yourself like it&#39;s 2032 and we&#39;re all being
shuffled around in our hover chairs like in WALL-E, maybe it will all happen
sooner.&lt;/p&gt;
&lt;p&gt;I also think the tech is fun, and watching a computer take my human words and
turn them into dumb ideas I described feels like magic. The same magic I felt
when I made an Atari computer spew a wall of &amp;quot;JOSH&amp;quot; across the screen in grade
school.&lt;/p&gt;
&lt;p&gt;In retrospect, I guess I&#39;ve always had a thing for my name.&lt;/p&gt;
&lt;h2&gt;Final approval&lt;/h2&gt;
&lt;p&gt;As mentioned, I am still reviewing these PRs, but as a last line of defense. The
script runs nightly, hunts for new Josh sites, and opens a PR. From there, Igor
will review the PR and give feedback, initially in the form of a comment because
it couldn&#39;t actually verify something.&lt;/p&gt;
&lt;p&gt;Then I&#39;d take a look at the PR. I scroll through the screenshots, and do a small
bit of double checking when the image doesn&#39;t have a discernible &amp;quot;Josh&amp;quot;
artifact. In the beginning, there were a lot of false positives, so that all
needed to be dialed in. These days it would take a few seconds to a few minutes.&lt;/p&gt;
&lt;h2&gt;Not good enough&lt;/h2&gt;
&lt;p&gt;The experiment is to get me out of the loop, so none of this was going to cut
it. Igor was already doing a great job, and I recently talked about the &lt;a href=&quot;https://joshtronic.com/2026/08/02/observations-building-pr-review-loop/&quot;&gt;lessons
learned from building a PR review loop&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As mentioned, the Igor review feedback was typically &amp;quot;LGTM, also I couldn&#39;t
verify much&amp;quot;. So until that is improved, I&#39;ll continue to be the blocker.&lt;/p&gt;
&lt;h2&gt;Improving context visibility&lt;/h2&gt;
&lt;p&gt;And that&#39;s where I&#39;m at right now. Not at a point of full autonomy, but in the
steps just before that.&lt;/p&gt;
&lt;p&gt;Reviewing the PR manually is a good exercise, as I&#39;ve been able to make some
notes about what&#39;s working and what&#39;s not. What wasn&#39;t working is that the
screenshots don&#39;t always contain a marker to indicate the site is Josh-based. A
slight improvement to that was to include the actual &amp;quot;Josh&amp;quot; artifact in the PR.&lt;/p&gt;
&lt;p&gt;Because of the volume of sites I&#39;m finding, it&#39;s made sense to reject sites that
we can&#39;t detect &amp;quot;Josh&amp;quot; text on. There&#39;s the potential we&#39;re omitting legitimate
sites, but that&#39;s the risk that I&#39;m okay with to ensure we can get a point that
the entire process can be automated.&lt;/p&gt;
&lt;p&gt;Sadly though, when the Igor coder picked up the task, I didn&#39;t explicitly cite
adding the content to the PR body. The result? All of the evidence was added to
the repo, doubling the number of files in the PR.&lt;/p&gt;
&lt;p&gt;That&#39;s how this goes, thin requirements sometimes get bad results. We iterated
and moved on.&lt;/p&gt;
&lt;h2&gt;Fully autonomous, when?&lt;/h2&gt;
&lt;p&gt;Being completely honest, I&#39;m not entirely certain when this one will get there.&lt;/p&gt;
&lt;p&gt;My biggest concern is that I&#39;ve already ran into a few sites that passed the
&amp;quot;josh&amp;quot; string on the website test, but also, weren&#39;t personal sites and failed a
few other criteria.&lt;/p&gt;
&lt;p&gt;Detection&#39;s at a place that&#39;s starting to consistently get my PR reviews down
from minutes to seconds. Huge win, as we&#39;re picking up 15+ new sites daily.&lt;/p&gt;
&lt;p&gt;I&#39;ll probably need to circle back on the LLM website analysis to get that dialed
in further. Loops all the way down.&lt;/p&gt;
</description><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/08/16/taught-robot-detect-joshes/</guid>
    </item>
    <item>
      <title>Reverse Engineering a PostHog SuperDay</title>
      <link>https://joshtronic.com/2026/08/09/reverse-engineering-posthog-superday/</link><description>&lt;p&gt;I&#39;m not here to bullshit anybody, I have never been through a PostHog SuperDay.
Like many humans, I&#39;ve read about it on their website, as they are a company
that over-communicates just about everything.&lt;/p&gt;
&lt;p&gt;This tale started when I got curious about their onboarding &lt;a href=&quot;https://github.com/PostHog/wizard/&quot;&gt;wizard&lt;/a&gt;. Their
pivot from analytics to self-driving systems mirrors what I&#39;ve been working on
for the last couple of years, which has accelerated greatly over the last 3
months. Figured there was probably something I could learn and possibly bite
off to include in my own system.&lt;/p&gt;
&lt;h2&gt;Figuring out what to do&lt;/h2&gt;
&lt;p&gt;I&#39;ve been around open source software (OSS) for a good long while now. Even
though I&#39;ve had some &lt;a href=&quot;https://joshtronic.com/2012/09/05/go-fork-yourself/&quot;&gt;strong opinions&lt;/a&gt; about the &lt;a href=&quot;https://joshtronic.com/2015/09/20/stop-submitting-feature-requests-for-open-source-software/&quot;&gt;state of things&lt;/a&gt;
over the years, &lt;a href=&quot;https://joshtronic.com/2016/04/17/make-open-source-contributions-a-priority/&quot;&gt;I still believe it&#39;s the way&lt;/a&gt;. If not for OSS, I wouldn&#39;t
be able to say things like &amp;quot;I wrote a &lt;a href=&quot;https://packagist.org/packages/joshtronic/php-loremipsum/stats&quot;&gt;Lorem Ipsum generator&lt;/a&gt; that&#39;s somehow
been installed over 1 million times.&amp;quot;&lt;/p&gt;
&lt;p&gt;These days, most projects have a label on their issues that indicate what&#39;s good
for a new contributor to pick on. PostHog&#39;s repos are no different, except the
repo I was looking at didn&#39;t have any issues tagged with the &lt;code&gt;good first issue&lt;/code&gt;
tag.&lt;/p&gt;
&lt;p&gt;Not a big deal, with 100+ open issues I figured I&#39;d be able to find &lt;em&gt;something&lt;/em&gt;
I could pick up to give me a chance to play with the codebase. I did find a
handful of things, I even started to chase down one of them. As I did I realized
I kept talking myself out of each issue because what appeared to be low hanging
fruit was stuff that I could defend deprioritizing.&lt;/p&gt;
&lt;h2&gt;A pattern started to emerge&lt;/h2&gt;
&lt;p&gt;Along this journey of trying to find an issue worth fighting for, I started to
notice a pattern of somewhat disparate issues and PRs opened by the same
contributor. I also noticed that core team members (read: employees) were
commenting on these issues and PRs and not in the usual &amp;quot;yea or nay&amp;quot; fashion
that I see.&lt;/p&gt;
&lt;p&gt;The comments were constructive in a way that you&#39;d be with a more junior
teammate that you&#39;re attempting to mentor and train up. Not a bad thing, but the
feedback was more open ended rather than &amp;quot;hey I think this will cause an issue,
go fix it&amp;quot; that you usually run into.&lt;/p&gt;
&lt;p&gt;With my hamster wheel turning, it started to seem like these issues and PRs
weren&#39;t from outside contributors as much as they were from actual candidates.
Didn&#39;t hurt that the username of one of the users actually had the word
&amp;quot;candidate&amp;quot; in it.&lt;/p&gt;
&lt;p&gt;Even if my theory is incorrect, the feedback from the core team members seemed
valuable, and I used some of what was out there to analyze some of my own work
to see what could be learned and improved upon.&lt;/p&gt;
&lt;h2&gt;The simulation&lt;/h2&gt;
&lt;p&gt;At this point I was pretty convinced I was watching SuperDays play out in real
time on the repo. Having talked myself out of a handful of issues to work, I
decided it was time to send one of my robot friends to analyze the situation.&lt;/p&gt;
&lt;p&gt;The results? After analyzing the data that seemed to be from candidates, cross
referencing the team and their openly documented goals, I was feeling an awful
lot like Charlie Day:&lt;/p&gt;
&lt;img src=&quot;https://joshtronic.com/images/charlie-day-conspiracy.gif&quot; alt=&quot;Charlie Day&quot;&gt;
&lt;p&gt;I was also feeling like I&#39;d found an issue to work on. It was filed by an actual
employee and not a potential candidate. The ticket was decently scoped, even
though I pursued a quicker fix than what was defined.&lt;/p&gt;
&lt;p&gt;It was backed by a report from an actual user. It was also an issue that I was
eyeing already because it was something I had run into while setting things up
myself.&lt;/p&gt;
&lt;p&gt;Best part, it seemed to line up pretty nicely with one of their published
quarterly goals on their website. The wizard team&#39;s TUI revamp explicitly states
&amp;quot;users discover and run wizard programs without the exact CLI command&amp;quot;.&lt;/p&gt;
&lt;p&gt;Most importantly, it was currently unassigned so ideally I wasn&#39;t stepping on
any toes.&lt;/p&gt;
&lt;h2&gt;Are you going to tell us?&lt;/h2&gt;
&lt;p&gt;Yes, I&#39;m going to tell you which issue I picked up. But the whole point of this
post is less about the what and more about the how and the why. So the &lt;a href=&quot;https://github.com/PostHog/wizard/issues/616&quot;&gt;issue I
had picked up&lt;/a&gt; was related to running PostHog&#39;s &lt;code&gt;wizard&lt;/code&gt; more than once
on a repo.&lt;/p&gt;
&lt;p&gt;As mentioned, I ran into the issue when running it myself. Even though the
project does &amp;quot;2 hours of work in 8 minutes&amp;quot;, if you don&#39;t remember if you
already ran it, or worse, ran into something that forces you to run it again,
you&#39;re paying round trip prices for each subsequent run.&lt;/p&gt;
&lt;p&gt;My thought was that there was an easy win in there to do some light detective
work and then raise some awareness of what else the script can do. I scope
intentionally thin for a few reasons.&lt;/p&gt;
&lt;p&gt;First, oftentimes PRs are completely ignored and never merged. Zero reason to
boil the ocean when your contribution will be negated. Second, smaller scope
makes it easier to get something into production. Ship fast, get feedback fast.
Iterate from there.&lt;/p&gt;
&lt;h2&gt;Claude as my navigator&lt;/h2&gt;
&lt;p&gt;Similar to how I never denied using Google or Stack Overflow to research stuff,
I&#39;m not going to act like I don&#39;t use the heck out of AI. I play with different
harnesses, and models. Claude&#39;s still my ride or die at the moment so of course
I leveraged it to get up to speed on the codebase.&lt;/p&gt;
&lt;p&gt;Since I wanted to actually learn the code a bit, and knock some ring rust off, I
thought that I&#39;d leverage my friendly robot more like a mentor than a
subordinate. I did have to keep an eye on which mode I&#39;d left it in. Usually I
don&#39;t juggle between modes, but I wanted to be a bit more explicit here allowing
for correct attribution.&lt;/p&gt;
&lt;p&gt;It worked out surprisingly well, as I mostly kept Claude Code in plan mode so it
didn&#39;t make any code changes. I used it to learn the flow of the system and
figure out where I needed to make the changes I wanted to make.&lt;/p&gt;
&lt;p&gt;I like to follow a strict test-driven workflow. Tests and business logic never
to be committed at the same time. It works out most of the time, allowing me to
have a clean history and helps keep the robots honest so they aren&#39;t munging
tests to make their code seem functional.&lt;/p&gt;
&lt;p&gt;Other than that, it was a pretty boring process. Pair programming with the
direction of Claude Code. Figuring out how to test things and run them against
my project code. Figuring out conventions, in some cases, the lack thereof.&lt;/p&gt;
&lt;p&gt;The result of an afternoon (and part of an evening) of effort is &lt;a href=&quot;https://github.com/PostHog/wizard/pull/1066&quot;&gt;living in this
PR&lt;/a&gt;. &lt;strike&gt;Both the PR and the comment on the issue are unacknowledged at
the time of this writing.&lt;/strike&gt; Which did end up getting some feedback and
confirmed my suspicions about the possibility of upstream changes being in
flight.&lt;/p&gt;
&lt;h2&gt;Not even mad&lt;/h2&gt;
&lt;p&gt;I&#39;m no stranger to open source contributions being flat out ignored. I have a
&lt;a href=&quot;https://github.com/11ty/eleventy-plugin-rss/pull/94&quot;&gt;PR in flight&lt;/a&gt; on &lt;code&gt;eleventy-plugin-rss&lt;/code&gt; to fix a bug I ran into a while
back. The times I&#39;ve actually cared, I come in super hot, fork the project and
start to operate like a project lead rather than an unpaid intern.&lt;/p&gt;
&lt;p&gt;That all said, the process was fun, and I learned quite a bit. Including but not
limited to playing with &lt;code&gt;pnpm&lt;/code&gt; for the first time and having a TIL moment with
&lt;code&gt;tsdown&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The bigger code takeaways were related to an adjacent repo that PostHog uses to
manage their context files, and the friendly reminder that I should be open
sourcing more of my code.&lt;/p&gt;
&lt;p&gt;Over this weekend I actually put my Igor agent &lt;a href=&quot;https://git.sherver.org/joshtronic/igor&quot;&gt;out in the open&lt;/a&gt; and
started a &amp;quot;context mill&amp;quot; inspired project I&#39;m calling the &lt;a href=&quot;https://git.sherver.org/joshtronic/distillery&quot;&gt;Distillery&lt;/a&gt; to
serve as a shared library of my context files and skills.&lt;/p&gt;
&lt;p&gt;Both are part of my journey to crack the nut of complete automation and are
licensed under the &lt;a href=&quot;https://www.gnu.org/licenses/rms-why-gplv3.html&quot;&gt;GNU Public License Version 3&lt;/a&gt; (GPLv3). You can thank
&lt;a href=&quot;https://lukesmith.xyz/articles/why-i-use-the-gpl-and-not-cuck-licenses/&quot;&gt;this post&lt;/a&gt; for that.&lt;/p&gt;
&lt;h2&gt;Where I probably missed the mark&lt;/h2&gt;
&lt;p&gt;Let&#39;s say I did reverse a small bit of PostHog&#39;s SuperDay. If I had to judge
the work I did against what I think their expectations are, I&#39;d honestly say I
probably missed the mark.&lt;/p&gt;
&lt;p&gt;Even though I ganked the idea of the &amp;quot;context mill&amp;quot; for my own gains, I actually
didn&#39;t bother doing much with the repo. I acknowledged its existence, I learned
a small bit about it, but I didn&#39;t bother to see if there was anything out there
that could have been a more impactful task. Nor did I identify a task that could
potentially touch both repos.&lt;/p&gt;
&lt;p&gt;I&#39;m a builder through and through, so I&#39;ve always defaulted to code. Code&#39;s just
a smaller part of the equation in the generative AI age. I did my default here,
but also used it as a chance to pick apart myself a bit.&lt;/p&gt;
&lt;p&gt;Probably going to save that for another post, but all in all I would say that I
enjoyed this process. I definitely have some new tricks to working with legacy
codebases, which I have done regularly throughout my career. I have a few action
items to work on for myself, and of course it&#39;s always great when you learn
something new and implement it into your own project.&lt;/p&gt;
</description><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/08/09/reverse-engineering-posthog-superday/</guid>
    </item>
    <item>
      <title>Observations From Building a PR Review Loop</title>
      <link>https://joshtronic.com/2026/08/02/observations-building-pr-review-loop/</link><description>&lt;p&gt;Building my own agent has been fun. Sure, I could have opted for an
off-the-shelf solution, but I wanted control. The ironic part is that I&#39;m using
that control to offload more control to the agent.&lt;/p&gt;
&lt;p&gt;Recent experiments have included letting the agent work on itself. Super meta,
but didn&#39;t quite go as planned considering the guardrails I have in place around
the size of PRs. Agent work tends to be heavy lifting, whereas most project work
is small and fits nicely inside the constraints.&lt;/p&gt;
&lt;p&gt;Part of the issue there is that the PR reviewer would constantly request changes
on those larger PRs. Changes would happen, PR message body would diverge.
Infinite loop death spiral until eventually I was called.&lt;/p&gt;
&lt;p&gt;Around this same time, I was also tracking some issues that started to creep in
after I changed some models from Opus 4.8 to Opus 5. Approval rate dropped by
about half.&lt;/p&gt;
&lt;p&gt;I like to think that each new model is going to be better than the last, so I
thought perhaps it was time to revisit the reviewer to see if there was
something we were missing.&lt;/p&gt;
&lt;h2&gt;The review mechanic&lt;/h2&gt;
&lt;p&gt;By design, the review persona is pretty dumb. Not dumb in the sense that I give
it a lesser model or anything. Dumb in that it just doesn&#39;t have the full
picture of things.&lt;/p&gt;
&lt;p&gt;It gets the PR diff as a blob of text and that&#39;s it. No git worktree, no way to
read files or grep around. No commit messages or recent changes to compare
against.&lt;/p&gt;
&lt;p&gt;I don&#39;t review PRs this way. I click around and look at adjacent code. I&#39;ll
&lt;code&gt;git checkout&lt;/code&gt; the branch locally and poke around. I try to gather as much as I
can to give feedback with more substance than &lt;code&gt;nit: stray line break&lt;/code&gt; or the
like.&lt;/p&gt;
&lt;p&gt;Because of this, a lot of the feedback from the reviewer was effectively &lt;code&gt;LGTM, but I can&#39;t really confirm anything so... lol good luck&lt;/code&gt;. Then I&#39;d get pinged to
take a closer look.&lt;/p&gt;
&lt;h2&gt;Safety first&lt;/h2&gt;
&lt;p&gt;It&#39;s probably not fair to say the reviewer is dumb. The reviewer is gated by
security checks. I&#39;m the only user on my personal Forgejo instance, but that
doesn&#39;t mean I&#39;d prefer to be flighty with things.&lt;/p&gt;
&lt;p&gt;Any changes made and the PR content can be considered untrusted input. Because
of this, the reviewer shouldn&#39;t be poking around with tools on the command-line.
The diff-only review blindness is a security measure.&lt;/p&gt;
&lt;p&gt;Raising everything the agent couldn&#39;t rule out, that&#39;s a feature, not a bug.&lt;/p&gt;
&lt;h2&gt;Review, rework, repeat&lt;/h2&gt;
&lt;p&gt;At this point, the dutiful worker agent grabs the feedback with the goal of
addressing the requested changes. The worker can verify the feedback against the
working tree and attempt to remediate it.&lt;/p&gt;
&lt;p&gt;And if the feedback was already implemented or worse, just plain wrong? The
worker would either do its very best to remedy &lt;em&gt;something&lt;/em&gt;, or it would bail on
the task. Work typically resulted in PR body divergence, which is an underlying
bug since the reviewer takes those messages &lt;em&gt;very&lt;/em&gt; seriously.&lt;/p&gt;
&lt;p&gt;If there&#39;s nothing to action on, I get the escalation. I also get pinged if the
loop hits a certain number of iterations. The assumption being they aren&#39;t going
to figure it out on their own.&lt;/p&gt;
&lt;h2&gt;Giving the worker permission&lt;/h2&gt;
&lt;p&gt;Accounting for the security concerns above, the fix wasn&#39;t to give the reviewer
more access. Fun fact, I tried but my own security gates did their job and were
like &amp;quot;lolnope&amp;quot;.&lt;/p&gt;
&lt;p&gt;The remedy was to give the worker permission to push back. Giving explicit
permission is always one of my favorite prompt changes. It always feels like a
cheat code.&lt;/p&gt;
&lt;p&gt;This one wasn&#39;t even as much about giving permission as explaining the situation
a bit better. &amp;quot;Hey, the robot that reviewed this only looked at the diff,&amp;quot; and
outlining a specific set of options to dismiss, fix or escalate.&lt;/p&gt;
&lt;p&gt;To spell out things further, I explained that it could mix and match things as
well. Since the reviewer may mention a few things, no reason to be committed to
a single outcome for everything.&lt;/p&gt;
&lt;p&gt;The most permissive part looks something like this:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Dismissing is a real option, not a loophole. But the burden is on you: &amp;quot;I
could not confirm the reviewer&#39;s concern&amp;quot; is not a dismissal, it is a shrug.
Go check, then either fix it or state what you found. A dismissal a human
reads and disagrees with costs more than the fix would have.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Also worth mentioning, Forgejo v16 (released in July 2026) has expanded the PR
review system greatly amongst other things. Before this, the only way to review
was to leave feedback in a single input. Now they have inline commenting which
will greatly improve how my agent reviews code.&lt;/p&gt;
&lt;h2&gt;The end of the no-op&lt;/h2&gt;
&lt;p&gt;With the worker in a state of always communicating, the reviewer has a lot more
context to go on. The initial failure loop was a no-op that would turn into an
escalation.&lt;/p&gt;
&lt;p&gt;The new working model allows for additional context to be added for the
reviewer. Said information could be pushed back on by the reviewer, but seems
like most of the time it allows the agents to actually work through things.&lt;/p&gt;
&lt;p&gt;At this point the game loop, still on Opus 5, is more likely to play out to an
approval from the reviewer. Many of my repos will auto-merge in this scenario,
allowing for more autonomy and less frequent phoning home.&lt;/p&gt;
</description><pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/08/02/observations-building-pr-review-loop/</guid>
    </item>
    <item>
      <title>New Feature: Games</title>
      <link>https://joshtronic.com/2026/07/26/new-feature-games/</link><description>&lt;p&gt;Part of running your own website is being able to do what you want on it. Within
the confines of the law, of course. Back in the day you&#39;d add something trivial
to your site and make a formal announcement about it to your adoring fan base.&lt;/p&gt;
&lt;p&gt;I&#39;ve done it &lt;a href=&quot;https://joshtronic.com/2009/03/03/rss-feed/&quot;&gt;in the past&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;My buddy Geoff &lt;a href=&quot;https://geoffoliver.me/2025/01/15/another-new-feature-post-filters&quot;&gt;still does it&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As of late, it seems like what&#39;s old is new again on the web. Rather than bore
you with some navel gazing about AI or similar, today I&#39;m going to post about a
new feature on my site.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Bangs on the table to simulate a drum roll...&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;I&#39;ve added a &lt;a href=&quot;https://joshtronic.com/games/&quot;&gt;games&lt;/a&gt; page.&lt;/p&gt;
&lt;p&gt;It&#39;s mostly just a bunch of slopped-together game websites to chip away at my
backlog of &amp;quot;this would make a great game&amp;quot; domains I&#39;ve accrued over the years.
Along with a game that I wrote myself for the 10K Apart coding competition.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Spoiler:&lt;/strong&gt; &lt;em&gt;I didn&#39;t place well.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Speaking of AI navel gazing, the most ambitious of the bunch is
&lt;a href=&quot;https://porksicle.com/&quot;&gt;Porksicle&lt;/a&gt;. With over 100 minigames, it&#39;s my attempt to build a fully
automated game company with agents. I greenlight the work and mostly serve as
Chief Playtester.&lt;/p&gt;
&lt;p&gt;If you have some time to kill, feel free to pull up a stool and game a while.&lt;/p&gt;
</description><pubDate>Sun, 26 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/07/26/new-feature-games/</guid>
    </item>
    <item>
      <title>Invite Systems are an Open Relay</title>
      <link>https://joshtronic.com/2026/07/19/invite-systems-are-an-open-relay/</link><description>&lt;p&gt;Every time I think I&#39;ve seen it all from spammers, they do something that
surprises me. The ingenuity of bad actors is an interesting thing. I always
wonder what sort of world we&#39;d live in if their efforts were focused on good.&lt;/p&gt;
&lt;p&gt;What sucks the most is when they abuse something that&#39;s intended to bring people
together. Case in point, an invite system. It exists to allow somebody the
chance to get the rest of their team using a product or service.&lt;/p&gt;
&lt;p&gt;Invites wouldn&#39;t work if they said &amp;quot;You&#39;ve been invited to &lt;em&gt;platform&lt;/em&gt;&amp;quot; with no
additional context. Typically the email states the name of the organization
you&#39;re being invited to. &amp;quot;You&#39;ve been invited to &lt;em&gt;your organization name here&lt;/em&gt;&amp;quot;.&lt;/p&gt;
&lt;p&gt;Where does that organization name come from? The user of course! And what
happens if the user has ill intentions? They set the organization name to
something like &amp;quot;Text 1-800-555-1212 for a good time&amp;quot;, or something even
sketchier than that.&lt;/p&gt;
&lt;p&gt;Generally speaking, these emails come through transactionally and from a generic
email on the platform. If your system doesn&#39;t meter the number of invites, you
have yourself a certified spam cannon! May as well set up an SMTP server without
authentication, better known as an &lt;a href=&quot;https://en.wikipedia.org/wiki/Open_mail_relay&quot;&gt;open mail relay&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;There&#39;s a few ways you can approach limits. Have a cap on the total number of
pending invites? The spammer may delete pending invites to keep moving. Daily
limits on total invites sent? Maybe they&#39;ll be okay with stretching their
campaign over days?&lt;/p&gt;
&lt;p&gt;Probably not, most spammers are in the business of going as hard and fast as
possible before they get caught. Occasionally somebody will fly below the radar,
but I think that&#39;s more of a bug than a feature.&lt;/p&gt;
&lt;p&gt;Sane limits as to not get in the way of legitimate users tends to get you pretty
far. Monitoring if/when somebody hits the limits is good too. Spammers usually
won&#39;t write in to let you know they hit some limit.&lt;/p&gt;
&lt;p&gt;I say usually because there are some special folks out there that will come
knocking.&lt;/p&gt;
</description><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/07/19/invite-systems-are-an-open-relay/</guid>
    </item>
    <item>
      <title>Sandbox Coding Agents with a Separate User Account</title>
      <link>https://joshtronic.com/2026/07/12/sandbox-coding-agents/</link><description>&lt;p&gt;I don&#39;t trust our new robot overlords at all. I also don&#39;t fully believe that
agents are out there dropping production databases without some serious coercion
to do so.&lt;/p&gt;
&lt;p&gt;And while I don&#39;t trust the robots, I trust myself only a trivial amount more,
so my local access tends to be extremely thin. But not so thin that a rogue
agent couldn&#39;t do a little damage.&lt;/p&gt;
&lt;p&gt;That all said, I am constantly calibrating my trust with agentic endeavors. In
doing so, I&#39;ve been moving agents out of my user space entirely.&lt;/p&gt;
&lt;p&gt;Having Claude Code and other harnesses living under a separate user account
eliminates a lot of potential disasters due to the agent finding privileged
local credentials that could do some damage.&lt;/p&gt;
&lt;p&gt;Sandboxing my agents has improved trust thanks to the isolation. It&#39;s also had
an additional benefit of the robots not being thoroughly confused by some of my
shell aliases. It&#39;s a clean slate, and I grant access, mostly read-only,
accordingly.&lt;/p&gt;
&lt;p&gt;With my agents running primarily outside of my user space, I&#39;m able to give them
significantly more leash. Running in YOLO mode
(&lt;code&gt;--dangerously-skip-permissions&lt;/code&gt;) doesn&#39;t feel nearly as scary. I do use
&lt;code&gt;--remote-control&lt;/code&gt;, but I can still log in as the separate user account to cut
the latency of the web interface when I&#39;m actually at the keyboard.&lt;/p&gt;
&lt;p&gt;While things do feel much safer, I have watched the fucking clanker try to
figure out if it has passwordless &lt;code&gt;sudo&lt;/code&gt; access on numerous occasions. Maybe the
robots do actually drop people&#39;s production databases.&lt;/p&gt;
&lt;p&gt;Seriously though, it&#39;s on them for letting the thing have access to begin with.&lt;/p&gt;
</description><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate>
      <dc:creator>Josh Sherman</dc:creator>
      <guid>https://joshtronic.com/2026/07/12/sandbox-coding-agents/</guid>
    </item>
  </channel>
</rss>