<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Taimoor khan</title>
    <description>The latest articles on DEV Community by Taimoor khan (@taimoorkhan).</description>
    <link>https://dev.to/taimoorkhan</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F489332%2Feb07113f-d501-4a27-b162-ea6b68130932.png</url>
      <title>DEV Community: Taimoor khan</title>
      <link>https://dev.to/taimoorkhan</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/taimoorkhan"/>
    <language>en</language>
    <item>
      <title>LLM vs Agent vs Harness, Explained by a Caveman</title>
      <dc:creator>Taimoor khan</dc:creator>
      <pubDate>Fri, 25 Sep 2026 14:04:23 +0000</pubDate>
      <link>https://dev.to/taimoorkhan/llm-vs-agent-vs-harness-explained-by-a-caveman-29oe</link>
      <guid>https://dev.to/taimoorkhan/llm-vs-agent-vs-harness-explained-by-a-caveman-29oe</guid>
      <description>&lt;h1&gt;
  
  
  LLM vs Agent vs Harness, Explained by a Caveman
&lt;/h1&gt;

&lt;p&gt;Everyone argues about AI agents. Half the people arguing can't say where the LLM ends and the agent begins.&lt;/p&gt;

&lt;p&gt;So here's the whole thing, explained by a caveman.&lt;/p&gt;

&lt;h2&gt;
  
  
  The LLM: a big brain in a jar
&lt;/h2&gt;

&lt;p&gt;The LLM is a brain. A very big, very well-read brain. It knows many words. It can finish your sentences, write your emails, and explain recursion five different ways.&lt;/p&gt;

&lt;p&gt;It has no hands.&lt;/p&gt;

&lt;p&gt;You give it a question, it gives you an answer. That's the entire product: text in, text out. It doesn't remember yesterday unless you hand it the notes. It can't open a browser, run your tests, or move your money.&lt;/p&gt;

&lt;h2&gt;
  
  
  The agent: a brain with hands
&lt;/h2&gt;

&lt;p&gt;Give that brain hands, a goal, and permission to keep going.&lt;/p&gt;

&lt;p&gt;An agent takes "book me the cheapest flight to Dubai next month," breaks it into steps, searches flights, compares prices, hits a dead end, tries different dates, and comes back with a booking. Nobody held its hand between steps. The loop did that: think, act, look at what happened, think again.&lt;/p&gt;

&lt;p&gt;The LLM is the part that reasons. The agent is the loop around it: tools it can call, memory of what it already tried, and the stubbornness to keep going until the job is done.&lt;/p&gt;

&lt;h2&gt;
  
  
  The harness: the leash
&lt;/h2&gt;

&lt;p&gt;The harness is everything around the agent that keeps it from running off a cliff. Which tools it's allowed to touch. How many times it may retry. What it must never do. Where it writes logs. How you score its work.&lt;/p&gt;

&lt;p&gt;Skip the harness and your agent is a toddler with a credit card. It will do something. It won't be what you wanted.&lt;/p&gt;

&lt;p&gt;Building agents for production taught me this split: the model is maybe 10% of the work. The harness is the other 90%. Anyone can call an API. The work is guardrails, evals, retry budgets, and permissions.&lt;/p&gt;

&lt;h2&gt;
  
  
  The mammoth stew test
&lt;/h2&gt;

&lt;p&gt;The village wants mammoth stew.&lt;/p&gt;

&lt;p&gt;The LLM hands you five recipes and wishes you luck.&lt;/p&gt;

&lt;p&gt;The agent goes out, hunts the mammoth, and brings back meat.&lt;/p&gt;

&lt;p&gt;The harness says no baby mammoths, home before dark, max three spears.&lt;/p&gt;

&lt;p&gt;Same goal. Three very different cavemen.&lt;/p&gt;

&lt;h2&gt;
  
  
  When to use which
&lt;/h2&gt;

&lt;p&gt;Need text, a summary, or an answer? A single LLM call is enough. Don't build an agent because it's fashionable.&lt;/p&gt;

&lt;p&gt;Need a multi-step job done with tools? That's an agent.&lt;/p&gt;

&lt;p&gt;Letting it touch anything real? Build the harness first. Permissions before autonomy.&lt;/p&gt;

&lt;h2&gt;
  
  
  The short version
&lt;/h2&gt;

&lt;p&gt;LLM = brain. Agent = brain + hands. Harness = leash.&lt;/p&gt;

&lt;p&gt;Next time someone says "we built an AI agent," ask what the harness looks like. The answer tells you whether it's a demo or a product.&lt;/p&gt;

&lt;p&gt;Which one are you building right now?&lt;/p&gt;

</description>
      <category>ai</category>
      <category>llm</category>
      <category>agents</category>
      <category>deepseek</category>
    </item>
    <item>
      <title>I Built a Claude Code Plugin That Audits Vibe-Coded Apps for Production Readiness</title>
      <dc:creator>Taimoor khan</dc:creator>
      <pubDate>Thu, 24 Sep 2026 10:16:13 +0000</pubDate>
      <link>https://dev.to/taimoorkhan/i-built-a-claude-code-plugin-that-audits-vibe-coded-apps-for-production-readiness-3797</link>
      <guid>https://dev.to/taimoorkhan/i-built-a-claude-code-plugin-that-audits-vibe-coded-apps-for-production-readiness-3797</guid>
      <description>&lt;h1&gt;
  
  
  I Built a Claude Code Plugin That Audits Vibe-Coded Apps for Production Readiness
&lt;/h1&gt;

&lt;p&gt;Vibe coding got us shipping in hours. Then the launches started breaking.&lt;/p&gt;

&lt;p&gt;AI coding assistants are incredible at getting a working prototype on screen. What they're terrible at is the part that comes after: the quiet, boring, unglamorous work of making sure the thing is safe to put in front of real users. I've watched the same failure patterns repeat across AI-generated apps — broken Supabase RLS policies that leak one tenant's data to another, API keys committed straight into the repo, Stripe integrations that handle the happy path and fall over on webhooks and refunds, auth that lives in the frontend while the API trusts everyone, and public endpoints with no rate limiting at all.&lt;/p&gt;

&lt;p&gt;The prototype works. Nobody checked whether it's safe to launch. That's the gap I built &lt;strong&gt;prod-readiness&lt;/strong&gt; to fill.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it is
&lt;/h2&gt;

&lt;p&gt;prod-readiness is a Claude Code plugin that runs a read-only, whole-repository production-readiness audit. It answers one question: &lt;strong&gt;is this app safe to launch?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It works in three stages:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;One shared evidence pass&lt;/strong&gt; over the repo, so every finding is grounded in actual code, not vibes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Eight specialist lenses&lt;/strong&gt; — security, backend, database, DevOps, QA, frontend, AI security, and runtime — each writing evidence-tagged findings from that shared pass.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A verdict: SHIP, FIX THEN SHIP, or HOLD.&lt;/strong&gt; CTO-readable, backed by an absence ledger that distinguishes controls that are &lt;em&gt;confirmed&lt;/em&gt;, &lt;em&gt;not found&lt;/em&gt;, or &lt;em&gt;unverified&lt;/em&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;It's deliberately read-only. It never touches your code — it produces the audit trail under &lt;code&gt;.readiness-audit/&lt;/code&gt; and tells you what's wrong and where. There's also an optional local dashboard if you want to watch the audit run in your browser.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why a plugin, not another scanner
&lt;/h2&gt;

&lt;p&gt;Keyword scanners catch secrets in code. They don't catch the structural stuff that actually kills launches: missing recovery paths, unsafe trust boundaries, untested webhook handlers, operational blind spots. The eight-lens design exists because production readiness is a systems question, not a grep question. Each lens looks at the same evidence from a different angle, the way a real review team would.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it on your own app
&lt;/h2&gt;

&lt;p&gt;You only need Claude Code installed. Three commands:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;/plugin marketplace add Taimoorkhan1122/prod-readiness
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;/plugin install prod-readiness@prod-readiness-marketplace
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;/reload-plugins
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then point it at any repo and run:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;/prod-readiness:production-readiness-audit
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If the idea of running a full multi-agent audit makes your laptop fans spin up, there's a sequential mode too:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;/prod-readiness:production-readiness-audit sequential
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  What I'm looking for
&lt;/h2&gt;

&lt;p&gt;This is early and I'm actively improving it. If you vibe-code apps — especially ones heading toward real users and real payments — run it and tell me what it missed. The findings that matter most are the ones I haven't thought of yet.&lt;/p&gt;

&lt;p&gt;Repo: &lt;strong&gt;&lt;a href="https://github.com/Taimoorkhan1122/prod-readiness" rel="noopener noreferrer"&gt;https://github.com/Taimoorkhan1122/prod-readiness&lt;/a&gt;&lt;/strong&gt; — stars and issues both welcome.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>opensource</category>
      <category>vibecoding</category>
    </item>
    <item>
      <title>Navigate Github repos as in VS code</title>
      <dc:creator>Taimoor khan</dc:creator>
      <pubDate>Thu, 11 Feb 2021 18:49:39 +0000</pubDate>
      <link>https://dev.to/taimoorkhan/navigate-github-repos-as-in-vs-code-92m</link>
      <guid>https://dev.to/taimoorkhan/navigate-github-repos-as-in-vs-code-92m</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fi%2Fj1e2yb1c01313xo7c3t7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fi%2Fj1e2yb1c01313xo7c3t7.png" alt="Alt Text" width="800" height="450"&gt;&lt;/a&gt;&lt;br&gt;
you can navigate  github repos just like in VS Code by adding &lt;em&gt;1s&lt;/em&gt; in githubs domain name like &lt;a href="http://www.github.com/some-repo" rel="noopener noreferrer"&gt;www.github.com/some-repo&lt;/a&gt; will become &lt;a href="http://www.github1s.com/some-repo" rel="noopener noreferrer"&gt;www.github1s.com/some-repo&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=""&gt;Source&lt;/a&gt;&lt;/p&gt;

</description>
      <category>github</category>
      <category>vscode</category>
      <category>javascript</category>
      <category>react</category>
    </item>
    <item>
      <title>How to add dynamic colors in Chartjs</title>
      <dc:creator>Taimoor khan</dc:creator>
      <pubDate>Wed, 23 Dec 2020 08:40:45 +0000</pubDate>
      <link>https://dev.to/taimoorkhan/how-to-add-dynamic-colors-in-chartjs-3mlk</link>
      <guid>https://dev.to/taimoorkhan/how-to-add-dynamic-colors-in-chartjs-3mlk</guid>
      <description>&lt;p&gt;If you are stuck in hardcoding color values for each dataset and whenever there is new entry in a dataset your code broke, if yes this article is for you...&lt;/p&gt;

&lt;p&gt;Recently I was working with chartjs in React. Every time a new data was populated I had to add new color values for that label and data manually, after spending about 1.5 hours on the internet, I finally found  a solution to dynamically add colors in chartJS.&lt;/p&gt;

&lt;h2&gt;
  
  
  Setting up project
&lt;/h2&gt;

&lt;p&gt;You can use this &lt;a href="https://replit.com/@Taimoorkhan1122/React-Dashboard" rel="noopener noreferrer"&gt;replit&lt;/a&gt; for your reference, just start the project and start playing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Explanation
&lt;/h2&gt;

&lt;p&gt;Following this amazing &lt;a href="https://bit.ly/3haW2lg" rel="noopener noreferrer"&gt;article&lt;/a&gt;, using D3's Chromatic color scale, we will be creating dynamic color ranges for our charts, D3's Scale Chromatic library provides many color scales, we have used their interpolate color scales. All of the interpolate color scales have a domain of [0, 1]. If you want to get deeper check out this amazing &lt;a href="https://bit.ly/3haW2lg" rel="noopener noreferrer"&gt;article&lt;/a&gt;. To simplify, I have created a function &lt;code&gt;chartData()&lt;/code&gt; &lt;/p&gt;

&lt;p&gt;&lt;code&gt;chartData()&lt;/code&gt; returns data object which we can then pass to any Chart component. This function accepts a data object which contains &lt;code&gt;labels&lt;/code&gt;, &lt;code&gt;colorRangeInfo&lt;/code&gt;, &lt;code&gt;scale&lt;/code&gt; and &lt;code&gt;dataLabel&lt;/code&gt;&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;chartData({
    labels: ["China", "UAE", "Yemen", "Pakistan", "Saudia"],
    colorRangeInfo: {
    colorStart: 0,
    colorEnd: 1,
    useEndAsStart: false,
    },
    scale: d3.interpolateBlues,
    dataLabel: "data for doughnut chart",
})
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;Labels : accepts list of data labels which will be displayed as labels.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;colorRangeInfo()&lt;/code&gt; : accepts object containing d3 chromatic color range (0,1) useEndAsStart : true will reverse the color range.&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;const colorRangeInfo = {
    colorStart: 0,
    colorEnd: 1,
    useEndAsStart: false,
};
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;The scale property accepts &lt;code&gt;d3.interpolate&lt;/code&gt; which gives you various combinations such:&lt;br&gt;
&lt;strong&gt;interpolateIferno&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fraw.githubusercontent.com%2Fd3%2Fd3-scale-chromatic%2Fmaster%2Fimg%2Finferno.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fraw.githubusercontent.com%2Fd3%2Fd3-scale-chromatic%2Fmaster%2Fimg%2Finferno.png" width="800" height="94"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;interpolateCool&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fraw.githubusercontent.com%2Fd3%2Fd3-scale-chromatic%2Fmaster%2Fimg%2Fcool.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fraw.githubusercontent.com%2Fd3%2Fd3-scale-chromatic%2Fmaster%2Fimg%2Fcool.png" width="800" height="94"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;You can play around with different variation by using different interpolate color scales.&lt;/p&gt;

&lt;p&gt;Please share your thoughts if this article was useful for you. I would love hear back from you guys if you have any better solution for this. &lt;/p&gt;

</description>
      <category>react</category>
      <category>javascript</category>
      <category>chartjs</category>
      <category>dashboard</category>
    </item>
    <item>
      <title>The Rust</title>
      <dc:creator>Taimoor khan</dc:creator>
      <pubDate>Fri, 04 Dec 2020 07:26:36 +0000</pubDate>
      <link>https://dev.to/taimoorkhan/the-rust-50lo</link>
      <guid>https://dev.to/taimoorkhan/the-rust-50lo</guid>
      <description>&lt;p&gt;According to StackOverflow's Developer Survey Rust is most loved programming language for developers for past consecutive 5 years.&lt;/p&gt;

&lt;p&gt;Rust is a statically typed programming language that promises Safety and Performance. It has modern yet hard to digest syntax and provides low level control (such as memory usage, pointers etc).&lt;br&gt;
Rust is statically typed compiled language without anything like Garbage Collectors. &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Question:&lt;/strong&gt; How does Rust guarantee memory memory safety? &lt;br&gt;
&lt;strong&gt;Answer:&lt;/strong&gt; Rust manages memory through a system of Ownership with a set of rules that the compiler checks at compile time.&lt;/p&gt;

&lt;h1&gt;
  
  
  Hello World
&lt;/h1&gt;

&lt;p&gt;Let's write our first program in Rust.&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;fn main(){
  println!("Hello World");
}
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;
&lt;h1&gt;
  
  
  User Input In Rust
&lt;/h1&gt;

&lt;p&gt;Some types are not included in prelude so we need to explicitly call them into the scope by using &lt;code&gt;use&lt;/code&gt; keyword. The &lt;code&gt;std::io&lt;/code&gt; library provides number of useful features, including the ability to accept user input.&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;use std::io;

fn main(){
  println!("Your good name?:");

  let mut user_in = String::new();
  io::stdin()
      .readline(&amp;amp;mut user_in)
      .expect("something happened!");

  println!("Happy coding {}", user_in); 


}
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;Do you think rust will dominate other statically typed languages?&lt;/p&gt;

</description>
      <category>rust</category>
      <category>programming</category>
      <category>helloworld</category>
    </item>
  </channel>
</rss>
