
Keyclasp Keeps Tokens Out of Prompts
Keyclasp is a local secret-injection project for coding agents. Learn what it solves, where it helps, and where it stops.
Practical Cursor guides for subagents, rules, MCP setup, code review, and team use in production repositories.
Start with Cursor subagents, MCP training, and team conventions.
Have you tried these? Run the change on one branch. The methodology puts that in Review: an engineer still owns the merge. Training is the team version of that step.
If one article names a change you have not tried, run it on a branch. If the team needs the same Review habit, book a 15-minute sync or open training.
Book a 15-minute sync
Keyclasp is a local secret-injection project for coding agents. Learn what it solves, where it helps, and where it stops.

Manifold Security’s Git hijack post shows how untrusted repos can trigger code through agent-run Git commands.

Continue is archived, but not useless. Learn what changed and how to test a safer Cursor replacement path.

desktop-vibe-fly turns AI-coding marker files into desktop scent; learn why it landed and how to try the idea safely.

Proliferate is an open-source AI IDE for parallel coding agents, with a safe Cursor-first way to try it.

If you typed curs or into a search box you probably meant Cursor. Here is what it is and how teams use it.

Who Rogier Muller is, what he teaches engineering teams about AI coding agents, and how the training sessions are actually run.

Gabriel Blessed’s claw-coder post shows why local agent autonomy is really a runtime safety problem.

Evaluate Kastra authorization for Cursor tool calls with a disposable test service, denial evidence, and checks for alternate execution paths.

Cursor rules help teams keep scoped .cursor/rules files, subagents, and reviews aligned in Cursor.

A Jira handoff should expose scope, subagent responsibilities, connector access and the checks a reviewer still needs to inspect.

Review a Cursor subagent handoff with an independent caller search, actual connector permissions and a check of the combined diff.

A migration memo for Cursor 3.2 teams deciding how to use subagents, worktrees, and multi-root workspaces without losing review ownership.

Local checks before CI, argued for agent work: replay sandwiches, connector cards, and child receipts created where the work happens.

A field guide to specs for coding agents: five-line scope ledgers, decision stubs, and connector cards that a tired reviewer can check.

Parallel coding agents clog merge trains when scopes overlap. Scope ledgers, CLAUDE.md precedence, and replay receipts keep streams out of each other.

Coding agent loops survive messy code when scope ledgers, CLAUDE.md precedence, replay receipts, and connector cards keep every iteration reviewable.

Browser checks for coding agents: turn UI claims into replayable receipts with intent lines, command transcripts, connector cards, and decision stubs.

Reviewing AI generated code defensively: decision stubs, scope ledgers, and replay receipts that let reviewers defend a merge without replaying the chat.

Coding agent browser automation moves faster but widens blast radius fast. Give every connector a named owner before you trust it.

Why subagent prompts need their own scope, paths, and verification: four named fixes that keep forked agent work explainable in review.

Async subagents speed up AI coding workflows when every fork returns receipts: paths touched, commands run, and tests that prove regression guards.

When AI coding tools regress, the teams that recover fastest are the ones whose receipts survive the update: connector cards, child receipts, decision stubs.