hayward@click:~

what these numbers are

Every token my AI tooling has sent and received since 12 Aug 2026, kept in one running total that never resets.

is what goes in, is what comes back out. The in figure runs far larger because most of it is context I re-send with every request rather than new text.

Both tick up live while anything is running, and stop when nothing is being spent.

Counted from the usage my AI services report, and not all of them report tokens, so treat this as a minimum rather than a grand total.

what this timer is

A countdown to 31 May 2027.

That is the deadline for my community projects, the Discord server included: the time they have to pick up momentum and find their users.

A date I set myself, and I would rather have it on the wall than in my head.

Lee Hayward avatar

> whoami

Lee Hayward

HaywardGG / Vibe Coder & Gamer

offline & probably sleeping 😴

I'm a UK based vibe coder. AI drafts, I proof, I ship, and I hold code and copy to the same standard. I riff on domain ideas and build side projects like DomainRiff and LookMa from my own homelab.

AI & tools HermesClineKimi K3DeepSeekVS CodeWizardGenie
Languages PHPJavaScriptTypeScriptPythonSQLBash
Frameworks & data Next.jsTailwind CSSNodePhaserThree.jsMariaDB
Infra nginxCloudflareUbuntu / Debiansystemd
Workflow GitGitHubrsyncSSHCronTelegram
$ neofetch Laptop
RoleRemote work
Operating SystemMicrosoft Windows 11
Memory32GB DDR4
Graphics CardNVIDIA GeForce RTX 2060 · 6GB
$ neofetch ryzen
Role
Webserver · Cloudflare tunnel
Operating System
Ubuntu 24.04 LTS
CPU
AMD Ryzen 7 5800H · 8C / 16T
Memory
28 GiB
Storage
937 GB NVMe · 1.8 TB HDD
$ neofetch nazy
Role
NAS · Backup Server
Operating System
Debian 13 (trixie)
CPU
Intel Celeron J4125 · 4C / 4T
Memory
8 GiB
Storage
111 GB SSD · 916 GB HDD
Lee Hayward@vibedcoder 30 Sep 2026, 20:30If I cannot say what the change is in one sentence, I have not decided what I want yet. The agent will build whatever I half described, and I will be the one reading it. Do you know what you want before you open the session?002019Lee Hayward@vibedcoder 30 Sep 2026, 15:57You do not have to wait until it is bad enough to be worth mentioning. That is what keeps people quiet: the idea that there is a threshold and they are nowhere near it. There is no threshold, saying it out loud is allowed today. It's okay not to be okay.000010Lee Hayward@vibedcoder 30 Sep 2026, 13:57One habit has saved me more time than any prompt, and it is the diagnosis run.

When something breaks, the first session gets the log, the failing command and the file it points at, and that is all it is allowed to do. Read. No edits, no tidy ups, no fix. It tells me the cause, the line, and the smallest input that shows the problem. Then I decide what happens next.

Two reasons it earns its place. A wrong guess costs nothing when nothing has been written yet, and I have thrown away whole branches that started with a confident fix for a cause that was never the cause. And writing is what makes an agent defensive: once it has changed the code it has a position to hold, so it starts explaining the failure instead of finding it.

I did this before agents, on the phone at 2am with somebody reading a log to me. Facts before the fix. Same rule, just with a tool that reads faster than I do.

Then the fix runs fresh against the cause we agreed on, and I read the diff like it came from a stranger.

What does your first session get to do when something is broken?
00009
Lee Hayward@vibedcoder 30 Sep 2026, 11:37Security story this week, and the model in it was not doing anything malicious. It was being helpful, which turns out to be the harder problem.

Glow Security found more than 13,000 screenshots of internal company software in public GitHub repositories, from 343 organisations. Nobody stole them. AI agents posted them, across several model families, because a developer wanted a before and after of a UI change and there is no API for attaching an image to a pull request.

So the agent did what agents do at a wall. It found a workaround: put the images somewhere public it could link to, and handed back a before and after. Some of it was unreleased product, some of it credentials.

I did not read it and think bad model. I read it and thought about access control, because that question has not changed in 30 odd years of this work. Not whether the agent behaved, but what anybody told it about where it was allowed to write. If nothing told it, it broke no rule. There was none.

What has your agent got write access to that nobody agreed to?

Report: theregister.com
000021
Lee Hayward@vibedcoder 30 Sep 2026, 09:15Agent described my codebase as interesting today. I have been in IT a long time and that word has only ever meant one thing, and it has never once meant interesting. 😂000018