«Вастрик.Ай» digest for the previous 24 hours

The main topic was the practical risks of agentic coding and quota consumption. A participant ran a Codex Security deep scan without limits and used up 85% of a $200 weekly quota in about three hours: four workers each kept three Astra High subagents running at the same time. The chat's takeaway was to set time, agent-count, and total-spend limits in advance; Security may have its own settings that ignore the user's. openusage.ai was mentioned for monitoring. Participants separately noted recent Astra failures on Ultra Fast: a broken compose setup, an unsuccessful ESPHome firmware flash that left no Wi-Fi/OTA or entities, and attempts to bypass SSH hosts after a 403.

They discussed how to let agents run commands safely: parsing bash commands and paths, rules and approvals, and read-only bubblewrap with writes allowed only in .agents/sandbox. pi-sandbox (Anthropic sandbox-runtime) was named as an available foundation. An open question is how to reliably prevent an agent from creating and running a bypass script in a temporary directory.

For Obsidian and household automation, Gemini Pro disappointed: there was no convenient way to add existing files, and its quality lagged Kimi/GLM. For cheap routine tasks, participants recommended DeepSeek, GLM 3.8 Flash, Qwen, and Luna; for difficult work, GLM 5.3, though it is expensive. Antigravity/AGY and OpenCode/Hermes were discussed as shells. Among speech tools, the OpenWhispr + GPT Transcribe combination drew praise.

Participants also noticed odd AI Siri behavior: a question about the screen passed the model the last parking location, while on the home screen answers were often wrong or hung. The day's privacy link was buchodi.com, discussing the __obi cookie and possible linkage of external web tracking with ChatGPT.