@StErMi

#web3 dev + auditor | @SpearbitDAO LSR, @immunefi bug hunter, sage of AAVE codebase :D

ethereum L1/L2
Joined April 2008
During the next few days, I will share some of my private security research work that I have done in the last year. ​ All those projects are @aave related, and I feel very proud to have been chosen as one of the security partners to review them. I'm pretty sure that the dedication and knowledge that I have demonstrated on their codebase has been a pretty good investment 😁 ​ Those projects were very challenging, but at the same time it was fun and a pleasure because you always feel motivated and engaged when the quality of documentation, specifications and code is high quality. ​ When @avara or @bgdlabs contacts you, you know that you are going to enjoy it. They are both a top-notch team to work with. ​ The first one that I want to share is a.DI (Aave Delivery Infrastructure) It's a cross-chain communication abstraction layer for decentralised systems like the Aave DAO to communicate across networks, minimising the risk of underlying individual bridge provider failures, via consensus rules.
8
7
2
118
16,686
I was looking at the Codex Security GitHub repo to see if it could have been a good source of inspiration for an agentic security workflow but tbh it's more confusing than helpful. It seems to merge the CLI, SDK, and plugin (set of skills available in Codex) al togheter and it's a mix of python and TypeScript without a clear delineation (at least to me). I feel like they started with the Plugin and then tried to move to the CLI/SDK, but the code is really hard to follow, not structured and documented and it seems the outcome of a vibecoded codebase that compounds on the initial caos. I would honestly would love to see a full refactor that start sfroms scratch without caring about backward compatiblity.
5
491
I'm the bottleneck. My mind is spinning with tasks that I want to delegate to Codex but I know that I need to focus otherwise those tasks would end up in a poorly implemented outcome. But if I don't offload those thoughts into a task I can end up forgetting about the details or the intuition that I would like to experiment with. I would need something paired with my brain that reads my thoughts and automatically orchestrates Codex to create new projects, creates tickets in GitHub, manages those tasks and then reports back the outcome and keeps going with the flywheel. I would be the main orchestrator that gets pings when a decision needs to be made or a task provides a report/result and I can then re-offload to the agent orchestrator of my mind. Typing or speaking is not enough, it can't keep up with everything that goes into my mind. @sama can you build something like that?
5
7
931
learning to prompt models is like Horse Whispering
4
245
If Jev works like it seems (I still haven't had enough time to look at the docs), I would really love to be hooked into Codex to steer a part of the reasoning. I feel like it would vastly improve the result.
1
3
321
Ehi @grok what will come first in Europe, FSD 15 or Siri AI and all the other Apple related features not available yet?
1
272
Ehi @Steam am I crazy or you don't have a macOS silicon version of the app? 🧐
157
After using Codex so much during the past months I got used to its jargon. Sometimes I still need to nudge him to ELI5 things but I'm getting used to most of the terms.
2
340
At this point I think that I don't know how to talk or explain things to GPT6-Astra. It makes dumb mistakes and makes assumptions that even a "normal" person would not do. I try to be patient, provide all the context needed, provide guidance and so on. But you just need to miss one tiny obvious thing in the prompt and you will not get what you would expect.
4
4
519
in this case I provided a very detailed prompt and told Astra (high reasoning) that I want it to provide a description to the zod schema attributes for those that do not already have a proper explanation in the prompt we have defined for the agents. It performs the tasks but some fields have been skipped. They were only mentioned in the agent's prompt without an explanation and those fields were not self-explanatory. Now I have to reprompt the request hoping that it won't just add the description for the sake of satisfying my second request where I have reprimanded it
55
No invite for the GPT-6 Community Night for me 😭
1
1
417
Well at least I’ve tried 😁
46
With the new iOS 27 + macOS 27 airdropping links to my Mac always works and instantly. I can't belive it!
270
StErMi retweeted
Steam Frame is here! Our wireless VR headset + controllers, available now in the following models: Steam Frame 256GB Steam Frame 1TB Sign up now and learn more on @Steam store.steampowered.com/hardw…
1,070
3,821
1,237
30,620
7,609,773
Has someone vibecoded a tracker that lists all the features across all the Apple devices that are not available in Europe because of the DMA? Like: iPhone Mirroring on macOS, iOS Call Screening, Siri AI, and so on.
268
Apple please can you make a good revision of the Apple AirPods Max? I hate my current Sony but the existing max really need to be improved in plenty of places.
225
I see plenty of people complaining that GPT-6 Astra is "bad at coding". It seems to be a widespread acknowledgment. What went wrong? Why did it happen? Doesn't OpenAI have benchmarks on the "quality" of the code produced for a sucessful task?
3
4
806
Ok @mitsuhiko I just had the first instance of more or less your same experience with GPT6 Astra medium reasoning. It was terrible. I wanted to just throw everything away and start from scratch even if it meant wasting everything.
1
61
Does @OpenAIDevs still use the "Plan mode" in the Codex app? Previous versions had a "suggestion" UI to enable plan mode when you mentioned "plan" (or similar) in the prompt. Now you can only manually enable it via the `/plan` command.
2
394
Would we get a special version of your skill just for Astra @mattpocockuk ?
Get more out of GPT-6 Astra by revisiting your skills, AGENTS.md, and task prompts. Make skill triggers specific, load guidance when it's relevant, and define what done looks like. developers.openai.com/blog/r…
1
310
Get more out of GPT-6 Astra by revisiting your skills, AGENTS.md, and task prompts. Make skill triggers specific, load guidance when it's relevant, and define what done looks like. developers.openai.com/blog/r…
293
1,679
402
15,635
6,042,623