Writing
Blog
How we build Sentinel, and what we have learned about permissions, cost, models and measurement while building it. Written for engineers who intend to run an agent on code they care about.
Courses
All writing
- Part 1212 min read
The cautious tech lead asks three questions. Answer those.
How to answer a sceptical tech lead about running a terminal coding agent on a production repo, the questions they actually ask, and what you can honestly offer instead of a demo.
- Adoption
- Architecture
- Engineering Management
- Part 1111 min read
Quiz: can you spot the three agents that would leak?
Twelve questions on building a terminal coding agent, with answers, because the wrong options are more instructive than the right ones.
- Quiz
- Tutorial
- Security
- Part 1012 min read
The gate that asks for a rollback before the write lands
How to make an AI agent justify writes to sensitive paths: detect blast centres from path patterns, block once per path per turn, and demand a file:line plus an exact rollback.
- Tutorial
- Security
- Guardrails
- Part 913 min read
Approve one git command, not every git command
How to build an agent risk ledger that grades command shapes rather than tool names, so approving a git commit never silently authorises a force push.
- Tutorial
- Security
- Guardrails
- Part 814 min read
Permission modes: saying no in code, not in the prompt
How to build permission modes for a coding agent: named tool allowlists enforced in the loop rather than the prompt, why FIX mode withholds the shell, and what happens when the model argues.
- Tutorial
- Security
- Guardrails
- Part 712 min read
One agent, three front ends: async generators as the interface
Why an agent loop should yield events instead of printing: async generators let a terminal UI, a JSON pipeline and an MCP server share one implementation, and make cancellation free.
- Tutorial
- Node.js
- Architecture
- Part 613 min read
Watch every move: recording the agent loop as JSONL
How to make an agent loop inspectable: record every event to JSONL as it happens, wrap the generator so logging can never break the turn, and turn past runs into a regression suite.
- Tutorial
- Observability
- Evals
- Part 514 min read
Your first agent turn, streamed over raw fetch
Build a streamed agent turn over raw fetch: parse SSE, normalise three provider wire formats into one event shape, and feed tool results back until the model stops asking.
- Tutorial
- Agents
- Streaming
- LLM
- Part 412 min read
Writing the doctor command your users will actually run
How to write a doctor command for an AI CLI: check the runtime, prove the data directory is writable, confirm credentials without printing them, and exit non-zero on real failures only.
- Tutorial
- Developer Experience
- Diagnostics
- Part 310 min read
Terminal output that survives being piped into a file
Using Chalk and Figlet to make a CLI look finished, and the TTY, NO_COLOR and buffering rules that stop your banner from ending up inside someone else's data file.
- Tutorial
- CLI
- Chalk
- Terminal
- Part 211 min read
Building the command surface with Node.js and Commander
How to build a real CLI command surface with Commander: subcommands, variadic arguments, flag descriptions, exit codes, and the small conventions that make a CLI worth typing twice.
- Tutorial
- Node.js
- CLI
- Part 19 min read
What a Cursor-style terminal agent actually has to do
The shortest honest brief for building a terminal coding agent: find the command, stream the turn, gate the writes, print the cost, and fail in a way a human can read.
- Tutorial
- Architecture
- Agent
- 13 min read
Guardrails for AI coding agents: a design that survives week two
How to design AI coding agent guardrails engineers keep switched on: layered controls, once-per-path gating, and the friction traps that get them disabled.
- Security
- Architecture
- Guardrails
- 12 min readupdated 30 Sept 2026
Designing file permissions for an AI coding agent
A threat model and eight-layer defence for coding agent file access: path sandboxing, symlink escapes, secret refusal, risk grading and the blast-radius gate.
- Security
- Architecture
- Sandboxing
- 10 min readupdated 30 Sept 2026
How to evaluate a coding agent you are building
Capability gates, FAIL_TO_PASS fixtures, deterministic graders and reproducible task evals, how to measure an agent without fooling yourself.
- Evaluation
- Testing
- SWE
- 8 min read
Looking for a Cursor alternative that runs in your terminal?
An honest look at switching from an AI IDE to a local, multi-model CLI coding agent, what you gain, what you lose, and who should not make the move.
- Comparison
- Workflow
- 10 min read
Cut your LLM bill in half: cost control for coding agents
Where coding agent spend actually goes, and the seven changes that reduce it most: free-tier defaults, hard context caps, persisted budgets, and a verifier.
- Cost
- Performance
- Operations
- 9 min read
Run a coding agent on local models with Ollama or LM Studio
A practical guide to running an AI coding agent on local models: which model sizes work for which jobs, how to route between local and hosted, and what still breaks.
- Local models
- Privacy
- Ollama
- 8 min read
Turn any CLI coding agent into an MCP server
Why command line coding agents are ideal Model Context Protocol servers, how stdio transport works, and the three mistakes that break a JSON-RPC stream.
- MCP
- Integration
- Protocol
- 9 min readupdated 24 Sept 2026
The 7 best open source AI coding agents for the terminal
Seven open source AI coding agents that run in your terminal, compared on model choice, sandboxing, cost control and data handling. Updated for 2026.
- Comparison
- Open source
- CLI