Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ThailandJohn
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
ThailandJohn
6mo ago
lol... thats bit embarrassing I copy paste my memo note too... ohh well. It doesnt change much lol, it was supposed to end up here anyhow and now it did xD <3
2.
▲
Show HN: A benchmark for SAST exploit chain and evasion detection
(github.com)
2 points
by
ThailandJohn
6mo ago
|
1 comments
3.
▲
by
ThailandJohn
10mo ago
Not exactly how it works but I do understand the concern. The other option is to "just give it away" by not having it and being sherlocked... Now? You have to ask permission first, commercial licensing is a thing.
4.
▲
by
ThailandJohn
10mo ago
Happy to inform Ive just created my first pip package to make it bit easier to install :D https://pypi.org/project/theauditor/
5.
▲
by
ThailandJohn
10mo ago
Why not?
6.
▲
by
ThailandJohn
10mo ago
Would be really cool to compare notes :D Sent from a "non tech" company email so it doesn't get filtered lol. My speed really depends on language and what needs indexing. On pure Python projects I get around 220k loc/min
7.
▲
by
ThailandJohn
10mo ago
Hey! Yes I did. I started with treesitter tbh. And for go, rust, bash and hcl? I still do. In my naive beginnings, i really had no idea how complex things "were supposed to be", so i was never really deterred for it and kept build
8.
▲
by
ThailandJohn
10mo ago
Hi! Limitations of tree sitter, its insanely fast, easy to use but hits a limit on syntax/nodes only. Typescript compiler provides semantic with full type checking and cross module resolution. Its a small nightmare as I have to write e
9.
▲
Show HN: TheAuditor v2.0 – A “Flight Computer” for AI Coding Agents
(github.com)
40 points
by
ThailandJohn
10mo ago
|
12 comments
10.
▲
by
ThailandJohn
10mo ago
Hi HN, OP here. I’m a former Enterprise Systems Architect (Cisco/VMware) turned "vibe coder." I realized quickly that AI coding is dangerous because LLMs lack *context* and *verification*. They hallucinate because they are gu
11.
▲
Show HN: TheAuditor – I indexed my code into SQLite to stop AI hallucinations
(github.com)
7 points
by
ThailandJohn
10mo ago
|
1 comments
12.
▲
by
ThailandJohn
1y ago
Yeh, i dont dont use nix so when asked to follow the link? It didnt work as it should. And because i dont use nix? Hard to catch it until my friend did... That said? Did you the hash fail? Yes it did, security working as intended... Anythin
13.
▲
by
ThailandJohn
1y ago
No? At least read couple lines in the readme before joining the discussion please.
14.
▲
by
ThailandJohn
1y ago
Yes, i cant code but i can build systems, more news at eleven... That's why I built this. The 204 SQL injections it found in production? Those were real. Those are produced by industry standard tools.... The nightmare isn't that
15.
▲
by
ThailandJohn
1y ago
AST parsing fails primarily due to installation issues, not syntax errors in your code. TheAuditor uses a sandboxed environment (.auditor_venv/) to avoid polluting your system. When Tree-sitter isn't properly installed in that san
16.
▲
by
ThailandJohn
1y ago
You're absolutely wrong. - lol.
17.
▲
by
ThailandJohn
1y ago
Why does it matter? Just because you know how to code doesnt mean you know how to build systems, architecture or infrastructure? I do, professional background in it.
18.
▲
by
ThailandJohn
1y ago
The glaring thing most people seem to miss that llm generated code is like TOS and unless you work in a more enterprise team setting? You are not going to catch 90% of the issues... If this was used before releasing the tea spill fiasco, on
19.
▲
by
ThailandJohn
1y ago
"Using SonarQube is probably the way to go" "We don't need specialized tools" Pick one. SonarQube IS a specialized tool. It just specializes in different things than TheAuditor. SonarQube: "This file has issues
20.
▲
by
ThailandJohn
1y ago
You're absolutely right to be skeptical! You do ignore that vibe coding isnt going away... That's exactly why I built TheAuditor - because I DON'T trust the code I had AI write. When you can't verify code yourself, you n
21.
▲
by
ThailandJohn
1y ago
Do you care about the messenger or the message? I use AI to communicate because I have dyslexia and ADHD. It helps me articulate technical concepts clearly. The irony isn't lost on me - I built a tool to audit AI-generated code, using
22.
▲
by
ThailandJohn
1y ago
After reviewing my own code. Thanks for digging into the code! You're reviewing the regex fallback patterns that only trigger when AST parsing fails. The primary detection uses Tree-sitter for structural analysis and taint flow trackin
23.
▲
by
ThailandJohn
1y ago
@quibono: Great questions! The "don't create venv" warning is because TheAuditor creates its own sandboxed environment (.auditor_venv/) for analyzing YOUR project. If you install TheAuditor inside your project's ven
24.
▲
by
ThailandJohn
1y ago
You're absolutely right about that TOCTOU pattern - it's terrible! That regex would flag every if cache.has(key) then cache.add(key, value) as a race condition. Thank you for the specific example. This perfectly illustrates why I
25.
▲
Show HN: TheAuditor – Offline security scanner for AI-generated code
(github.com)
13 points
by
ThailandJohn
1y ago
|
32 comments