<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: steipete</title><link>https://news.ycombinator.com/user?id=steipete</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 22 Apr 2026 18:08:46 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=steipete" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by steipete in "Anthropic says OpenClaw-style Claude CLI usage is allowed again"]]></title><description><![CDATA[
<p>Peter here from OpenClaw. For context, here’s why our post reads the way it does:<p>Boris from Claude Code said publicly on Twitter that CLI-style usage is allowed. We took that seriously and invested time building around that guidance. I even changed the defaults, so when using the cli we're automatially disabling features that use excessive tokens like the heartbeat feature. But in practice, Anthropic still blocks parts of our system prompt, so the actual behavior today does not match what was communicated publicly.<p><a href="https://x.com/bcherny/status/2041035127430754686" rel="nofollow">https://x.com/bcherny/status/2041035127430754686</a><p>They since seemed to changed their classifier as people hack around it, as it is trivial to do so with a few renames. I'm not playing that game so it's in a weird limbo where it should work in theory but doesn't in practice.</p>
]]></description><pubDate>Tue, 21 Apr 2026 20:02:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47853799</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=47853799</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47853799</guid></item><item><title><![CDATA[New comment by steipete in "OpenClaw privilege escalation vulnerability"]]></title><description><![CDATA[
<p>ofc it's software engineers.</p>
]]></description><pubDate>Sat, 04 Apr 2026 18:03:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=47641573</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=47641573</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47641573</guid></item><item><title><![CDATA[New comment by steipete in "OpenClaw privilege escalation vulnerability"]]></title><description><![CDATA[
<p>Honestly that seems like total guesswork. There's a lot of FUD going around, or people running portscans and assuming just because they detect a gateway on a port, that they can connect to it. That’s not the case.</p>
]]></description><pubDate>Sat, 04 Apr 2026 13:55:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47639103</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=47639103</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47639103</guid></item><item><title><![CDATA[New comment by steipete in "OpenClaw privilege escalation vulnerability"]]></title><description><![CDATA[
<p>They both sponsor the OpenClaw Foundation and provide engineers to improve OpenClaw.</p>
]]></description><pubDate>Sat, 04 Apr 2026 13:54:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=47639098</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=47639098</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47639098</guid></item><item><title><![CDATA[New comment by steipete in "OpenClaw privilege escalation vulnerability"]]></title><description><![CDATA[
<p>OpenClaw creator here.<p>This was a privilege-escalation bug, but not "any random Telegram/Discord message can instantly own every OpenClaw instance."<p>The root issue was an incomplete fix. The earlier advisory hardened the gateway RPC path for device approvals by passing the caller's scopes into the core approval check. But the `/pair approve` plugin command path still called the same approval function without `callerScopes`, and the core logic failed open when that parameter was missing.<p>So the strongest confirmed exploit path was: a client that ALREADY HAD GATEWAY ACCESS and enough permission to send commands could use `chat.send` with `/pair approve latest` to approve a pending device request asking for broader scopes, including `operator.admin`. In other words: a scope-ceiling bypass from pairing/write-level access to admin.<p>This was not primarily a Telegram-specific or message-provider-specific bug. The bug lived in the shared plugin command handler, so any already-authorized command sender that could reach `/pair approve` could hit it. For Telegram specifically, the default DM policy blocks unknown outsiders before command execution, so this was not "message the bot once and get admin." But an already-authorized Telegram sender could still reach the vulnerable path.<p>The practical risk for this was very low, especially if OpenClaw is used as single-user personal assistant. We're working hard to harden the codebase with folks from Nvidia, ByteDance, Tencent and OpenAI.</p>
]]></description><pubDate>Fri, 03 Apr 2026 17:58:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=47629849</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=47629849</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47629849</guid></item><item><title><![CDATA[New comment by steipete in "I’m joining OpenAI"]]></title><description><![CDATA[
<p>Mario has a special place in the Clawtributor list.<p><a href="https://github.com/openclaw/openclaw#community" rel="nofollow">https://github.com/openclaw/openclaw#community</a></p>
]]></description><pubDate>Mon, 16 Feb 2026 01:05:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=47029630</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=47029630</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47029630</guid></item><item><title><![CDATA[New comment by steipete in "Cowork: Claude Code for the rest of your work"]]></title><description><![CDATA[
<p>Funny timing. Written in 10 days just when this took off. <a href="https://clawd.bot/" rel="nofollow">https://clawd.bot/</a></p>
]]></description><pubDate>Tue, 13 Jan 2026 01:49:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=46596500</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=46596500</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46596500</guid></item><item><title><![CDATA[New comment by steipete in "Just talk to it – A way of agentic engineering"]]></title><description><![CDATA[
<p>Marketing for what? I didn't even link to what I'm building because I wanna ship it when it's ready.</p>
]]></description><pubDate>Wed, 15 Oct 2025 22:09:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=45598895</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=45598895</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45598895</guid></item><item><title><![CDATA[New comment by steipete in "Just talk to it – A way of agentic engineering"]]></title><description><![CDATA[
<p>(OP) You know if I link to a half-finished project, people would take it apart as many don't understand the nuance between crap and simply not done yet. But if you follow me on twitter it'll take you a few minutes to figure out. I'm two months in, even with AI, shipping good stuff takes time.</p>
]]></description><pubDate>Wed, 15 Oct 2025 22:07:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=45598881</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=45598881</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45598881</guid></item><item><title><![CDATA[New comment by steipete in "Just talk to it – A way of agentic engineering"]]></title><description><![CDATA[
<p>(OP) 1/3rd of the code is tests.<p>There's an Expo app, two Tauri apps, a cli, a chrome extension.
The admin part to help debug and test features is EXTREMELY detailed and around 40k LOC alone.<p>To give some perspective to that number.</p>
]]></description><pubDate>Wed, 15 Oct 2025 22:02:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=45598848</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=45598848</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45598848</guid></item><item><title><![CDATA[New comment by steipete in "Just talk to it – A way of agentic engineering"]]></title><description><![CDATA[
<p>OP: If you give the llm examples like <a href="https://react.dev/learn/you-might-not-need-an-effect" rel="nofollow">https://react.dev/learn/you-might-not-need-an-effect</a>, it does a farily good job at refactoring useEffecs.<p>And yes refactoring sometimes re-introduces these, so it's not a perfect solution.</p>
]]></description><pubDate>Wed, 15 Oct 2025 22:00:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=45598822</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=45598822</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45598822</guid></item><item><title><![CDATA[New comment by steipete in "Just talk to it – A way of agentic engineering"]]></title><description><![CDATA[
<p>(OP) the current projec is closed source. If you look at my cli tools, that's pure slop, all I care is that it works, so reviewing that code for sure will show some weird stuff. Does it matter? It's a tool to fetch logs form a server. I run it locally. As long as is does that reliably, idk about the code.</p>
]]></description><pubDate>Wed, 15 Oct 2025 21:58:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=45598809</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=45598809</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45598809</guid></item><item><title><![CDATA[New comment by steipete in "Just talk to it – A way of agentic engineering"]]></title><description><![CDATA[
<p>tbh in the time where everyone uses AI to write articles, some typos and mistakes like that are helpful to show that it's human made.</p>
]]></description><pubDate>Wed, 15 Oct 2025 21:57:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=45598803</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=45598803</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45598803</guid></item><item><title><![CDATA[New comment by steipete in "Just talk to it – A way of agentic engineering"]]></title><description><![CDATA[
<p>(OP) I use atlas for database migrations, it works quite well with agents and has plenty guardrails around it.</p>
]]></description><pubDate>Wed, 15 Oct 2025 21:56:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=45598800</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=45598800</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45598800</guid></item><item><title><![CDATA[New comment by steipete in "GLM 4.5 with Claude Code"]]></title><description><![CDATA[
<p>Been using that for a while, first Chinese model that works REALLY well!<p>Also fascinating how they solved the issue that Claude expects a 200+k token model while GLM 4.5 has 128k.</p>
]]></description><pubDate>Sat, 06 Sep 2025 01:42:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=45145816</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=45145816</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45145816</guid></item><item><title><![CDATA[New comment by steipete in "Show HN: Conductor, a Mac app that lets you run a bunch of Claude Codes at once"]]></title><description><![CDATA[
<p>For that workflow, you might be happier with <a href="https://vibetunnel.sh" rel="nofollow">https://vibetunnel.sh</a>.</p>
]]></description><pubDate>Mon, 21 Jul 2025 00:33:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=44630728</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=44630728</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44630728</guid></item><item><title><![CDATA[New comment by steipete in "vibetunnel - turn any browser into a terminal and command your agents on the go"]]></title><description><![CDATA[
<p>Bind to localhost (default) and share securely via Tailscale.</p>
]]></description><pubDate>Tue, 17 Jun 2025 02:16:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=44295200</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=44295200</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44295200</guid></item><item><title><![CDATA[vibetunnel - turn any browser into a terminal and command your agents on the go]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/amantus-ai/vibetunnel">https://github.com/amantus-ai/vibetunnel</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44295042">https://news.ycombinator.com/item?id=44295042</a></p>
<p>Points: 15</p>
<p># Comments: 2</p>
]]></description><pubDate>Tue, 17 Jun 2025 01:49:01 +0000</pubDate><link>https://github.com/amantus-ai/vibetunnel</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=44295042</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44295042</guid></item><item><title><![CDATA[New comment by steipete in "Give Your AI Agents Supernatural Vision on macOS"]]></title><description><![CDATA[
<p>Peekaboo is a macOS-only MCP server that enables AI agents to capture screenshots of applications, or the entire system, with optional visual question answering through local or remote AI models.<p>Without screenshots, agents debug blind—Peekaboo gives them eyes.</p>
]]></description><pubDate>Sun, 08 Jun 2025 22:55:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=44219989</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=44219989</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44219989</guid></item><item><title><![CDATA[Give Your AI Agents Supernatural Vision on macOS]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.peekaboo.dev/">https://www.peekaboo.dev/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44219988">https://news.ycombinator.com/item?id=44219988</a></p>
<p>Points: 4</p>
<p># Comments: 2</p>
]]></description><pubDate>Sun, 08 Jun 2025 22:55:12 +0000</pubDate><link>https://www.peekaboo.dev/</link><dc:creator>steipete</dc:creator><comments>https://news.ycombinator.com/item?id=44219988</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44219988</guid></item></channel></rss>