Sign in

Clarkio

@clarkio.com
1.1K followers 187 following 232 posts

Web dev and app sec things. Here for community, fun and learning. Not here to accrue numbers or influence you.

PostsRepliesMedia
Clarkio @clarkio.com · 20/08/2026
Anyone else getting a sense for what generation someone is in by how often they use the word “literally”?
011
Clarkio @clarkio.com · 20/08/2026
Whenever bun has a new release I enjoy the videos that go with them😁 youtu.be/i38DgEuaJwM
youtu.be
Bun v1.4
YouTube video by Bun
000
Clarkio @clarkio.com · 28/05/2026
A fun test to see how well you do at checking agentic AI permissions: llmgame.scalex.dev
llmgame.scalex.dev
Continue? Y/N
A 30-second game about LLM permission fatigue. How carefully do you really read AI commands?
010
Clarkio @clarkio.com · 20/05/2026
Your first instinct after getting hit by the TanStack npm attack is to revoke your GitHub token. Don't. The malware polls GitHub every 60 seconds. Gets a 401? It runs rm -rf ~/ Here's the right remediation order before you touch a single credential. youtu.be/YrwM2EFYrUY
youtu.be
Mini Shai-Hulud: The Most Sophisticated NPM Supply Chain Attack of 2026
YouTube video by Snyk
020
Clarkio @clarkio.com · 08/05/2026
Companies are deploying AI-generated code into production. Much of that code contains vulnerabilities. Making traditional AppSec struggle to keep up Snyk + Anthropic's Claude = security at AI speed 👇 snyk.io/news/snyk-embeds-anthropics-claude-to-advance-ai-powered-security-for-software-development
snyk.io
Snyk Embeds Anthropic's Claude to Advance AI-Powered Security for Software Development | Snyk
Starting today, Snyk has integrated Claude into the Snyk AI Security Platform — powering automated vulnerability discovery, prioritization, and developer-ready fixes across code, dependencies, contain...
130
Clarkio @clarkio.com · 13/11/2025
Been getting messages asking how I use Codex in my projects. Finally made a video about it! I break down my entire workflow and share the tips and tricks that make the biggest difference in my daily coding. Hope it helps 👍 🎥👇 youtu.be/mP-GiOihhM0
A smiling Clarkio wearing a backward black Snyk cap against a purple background with binary code. To the right, there’s a screenshot of the OpenAI Codex interface displaying the text 'What should we code next?' with a red arrow pointing to the input box. Above, bold text reads 'TIPS & TRICKS' in purple and pink gradient letters.
030
Clarkio @clarkio.com · 06/11/2025
Can your AI code gen model/tools of choice generate a proper Content Security Policy that allows everything to still work properly?
100
Clarkio @clarkio.com · 15/10/2025
AI is transforming how we build, deploy & secure software. Learn how to empower innovation without compromising security at #DevSecCon, the Global Community Summit on AI Security. Details: 💻 Virtual 🗓️ Oct 22, 2025 🔗 snyk.io/events/devseccon
The DevSecCon 2025 logo above large white text on a purple gradient background that reads “Securing the Shift to AI Native.” Below, smaller white text says “October 22, 2025 - Virtual.”
010
Clarkio @clarkio.com · 13/10/2025
If you’re using Windsurf and not adding MCP servers you’re missing out on serious power. I’ll show you how to add them from the store and manually (including Snyk!) Full video 👇 youtu.be/exGudnPb9Bo
A smiling clarkio wearing a backward black Snyk cap and a black shirt with the Snyk logo, pointing to text on the right that says 'Manage MCP servers' with a visible 'snyk Configure' button. Large bold text at the top reads 'MCP SERVERS IN WINDSURF' in blue and purple gradient. On the left, there’s the Windsurf logo with teal curved lines on a dark background, all set against a bright purple and blue gradient backdrop.
020
Clarkio @clarkio.com · 07/10/2025
I asked Claude Sonnet 4.5 to build a secure Node.js note taking app from scratch. The results surprised me! Watch here 👇 youtu.be/YBl0BR3fgjA
Clarkio wearing a backward black Snyk cap looking surprised, set against a bright purple and blue background. To his right is an editor window titled 'SECURITY_REPORT.md' displaying a Markdown document describing a 'production-ready, security-hardened Node.js notes application.' Above him is the orange starburst logo for Anthropic, and bold gradient text at the bottom reads 'BEST IN THE WORLD?!' in blue and purple letters.
000
Clarkio @clarkio.com · 29/09/2025
Stop using .env files for your API keys. They’re not safe anymore. Here’s why and what to do instead 👇 youtu.be/pcbRwwaCPUg
Clarkio with a thoughtful face wearing a backwards Snyk cap, resting his chin on his hand. At the top is a code editor showing .env, package.json, and index.js tabs, with code that logs API_KEY from process.env. To the right is a tweet screenshot that says 'Cursor steals your dev creds,' with a red arrow pointing at it. At the bottom, bold red text reads '.ENV IS BAD' against a purple background.
000
Clarkio @clarkio.com · 22/09/2025
Spec-driven development + AI = the future? 🤔 I explored Amazon’s new Kiro IDE paired with Claude Sonnet 4 to find out. Watch and tell me if you’d code like this 👇 🎥 youtu.be/YpB1QS58KZE
Bright thumbnail image featuring a surprised clarkio on the left side, with wide eyes and open mouth. The background is a vibrant mix of purple and pink hues with binary code pattern. Bold text at the top reads 'SPEC DRIVEN DEVELOPMENT' in blue and white. On the right, a UI screenshot shows two options: 'Vibe' and 'Spec,' with the 'Spec' option highlighted, which says 'Plan first, then build. Create requirements and design before coding starts.' A red arrow points to the highlighted option.
000
Clarkio @clarkio.com · 19/09/2025
We’re in the wave of spec-driven development now.
010
Clarkio @clarkio.com · 15/09/2025
I put Replit to the test and was honestly shocked by the outcome. If you care about what AI coding tools can (and can’t) do, you’ll want to see this. 📹👉 youtu.be/gHGB3kptH_s
On the right-hand side is text in bold letters "This is crazy!" overlayed on the Replit logo. Above that is a screen shot of the application that was built in the video. On the left-hand side is an image of clarkio smiling. The background is a gradient from purple to blue with circuit lines and 1's and 0's
000
Clarkio @clarkio.com · 27/08/2025
This has been a fun loop🤪 Agent: Everything is done let me run the app Terminal: App running Agent: Perfect! Let me test it with curl *kills app for curl* Agent: Let me start the server again and test it Terminal: App running Agent: Perfect! Let me test it with curl
030
Clarkio @clarkio.com · 14/08/2025
When it comes to AI/LLMs I aim to have a balanced perspective on it. There are times I'm delighted by what they do and other times I'm unimpressed. Today I felt a bit unimpressed...
100
Clarkio @clarkio.com · 12/08/2025
Giving Claude Opus 4.1 a go at writing a secure app ↙️ youtu.be/ELSl0RmFxLg?...
Clarkio in the forefront thinking with a screen shot image of JSON showing project dependencies and bold text of "Claude Opus 4.1"
010
Reposted by Clarkio
Brian Vermeer @brianvermeer.nl · 06/08/2025
How to Add MCP Servers to VS Code by @clarkio.com youtu.be/50tkvZhOVqM?...
youtu.be
How to Add MCP Servers to VS Code (with GitHub Copilot)
In this tutorial, I’ll walk you through the step-by-step process of adding MCP servers to Visual Studio Code using GitHub Copilot. Whether you’re setting up your first MCP server or integrating…
021
Reposted by Clarkio
Liran Tal @lirantal.com · 03/08/2025
y'all are sleeping on npq ✨ Step 1: $ npm install -g npq $ alias npm="npq-hero" Step 2: *no more malicious packages hurting you ;-) *well, much lower risk based, nothing is absolute
1102
Clarkio @clarkio.com · 19/04/2025
Reading code is becoming even more valuable than writing it.
130
Reposted by Clarkio
Visual Studio Code @vscode.dev · 15/04/2025
VS Code Live: Agent Mode Day is tomorrow, April 16th! And we've got a special guest joining us - @wesbos.com will be closing out the stream with a live coding session! You won't want to miss this. Stream starts at 9 AM PT: youtube.com/live/HNly8eN...
A thumbnail with a dark background and a picture of Wes Bos in the top right. The thumbnail reads "Agent Mode Day with Wes Bos" and says "VS Code Live" in the bottom left
0201
Reposted by Clarkio
Visual Studio Code @vscode.dev · 07/04/2025
Agent mode is rolling out to all users! 🔁 Autonomous code editing 🔍 Full codebase awareness 💬 Built in tools for codebase search, terminal, fetching website content and more All extensible via MCP & VS Code Extensions. All available today. Learn more:
code.visualstudio.com
Agent mode: available to all users and supports MCP
Agent mode is now available to all users and supports MCP.
03111
Reposted by Clarkio
Liran Tal @lirantal.com · 04/03/2025
haha Brian is just hilarious 😂 checkout the new video about Claude 3.7 and whether it's actually better for generating secure code: www.youtube.com/watch?v=zM8c...
071
Reposted by Clarkio
HTTP Archive 💾 @httparchive.org · 03/03/2025
We've just published the 19th and final chapter of the 2024 Web Almanac on JavaScript by Abdul Haddi Amjad and Nishu Goel. almanac.httparchive.org/en/2024/java...
almanac.httparchive.org
JavaScript | 2024 | The Web Almanac by HTTP Archive
JavaScript chapter of the 2024 Web Almanac covering the usage of JavaScript on the web, libraries and frameworks, compression, web components, and source maps.
2113
Reposted by Clarkio
Visual Studio Code @vscode.dev · 08/02/2025
Agent mode (preview) is here for GitHub Copilot in VS Code! In agent mode in Copilot Edits, Copilot can now iterate on its own output, execute terminal commands, and even self-heal from runtime errors. Try it in VS Code Insiders: code.visualstudio.com/updates/v1_97…
A thumbnail with a purple background, a 3d version of the GitHub Copilot logo in the foreground, and the words "GitHub Copilot agent mode"
0509
Reposted by Clarkio
Deno @deno.land · 03/02/2025
@jsr.io is now openly governed — meet its board members and check out its governance charter 👇 deno.com/blog/jsr-ope...
deno.com
Introducing the JSR open governance board
JSR, a modern open source JavaScript registry, is meant for the greater JavaScript and TypeScript community. We're thrilled to announce its own independent governing body.
512329
Clarkio @clarkio.com · 27/01/2025
Folks making videos, don't tell your audience to leave a comment/question where you'll reply with your answer and then don't reply to any of them. Of course, there are some exceptions to this like trolls or hate comments...
100
Clarkio @clarkio.com · 20/01/2025
Does anyone here enjoy the game "Words on Stream" and tune in to streamers playing that or channels that run it 24/7? Link to the game for those not familiar with it: wos.gg
wos.gg
WOS - Words On Stream
Words On Stream, the free game that will boost your live streams on Twitch or YouTube
110
Clarkio @clarkio.com · 08/01/2025
I was walking and talking on a call and my back just randomly goes out. Short quick sharp shot in the back. Boom! Ow! What the heck?!
210
Clarkio @clarkio.com · 06/01/2025
Today has been a good "catch up from the break" day while also sticking to my routine. Feeling good 💪
050
Reposted by Clarkio
Brian Vermeer @brianvermeer.nl · 06/01/2025
Securing your GitHub repo is critical! Here are 10 tips: • Enable 2FA 🔒 • Limit access 👥 • No secrets in code ❌🔑 • Scan w/ Snyk 🛠️ • Audit logs 🔍 • Automate updates ⏩ • Protect branches ✅ • Rotate tokens 🔄 • Enforce signed commits ✍️ • Train your team 🌱 More tips:
buff.ly
10 GitHub Security Best Practices | Snyk
Learn more about 10 GitHub Security Best Practices to be more secure as a GitHub user or contributor.
0104
Clarkio @clarkio.com · 03/01/2025
Tomorrow marks 7 years of live streaming! Whew! 😅 I learned a lot over that time and will be reflecting on it during today's stream. Tune in around 1pm ET. Hope to see you there 👍 twitch.tv/clarkio or youtube.com/clarkio/live
270
Clarkio @clarkio.com · 02/01/2025
Sure it may not be the most popular language but Rust seems to me like the unsung hero of 2024. Just thinking about the positive impacts it’s had on other languages and ecosystems makes it stand out to me. Agree? Disagree?
110
Reposted by Clarkio
Visual Studio Code @vscode.dev · 30/12/2024
Extensions are an integral part of VS Code - and now, Copilot functionality can be added to your extensions. See this in action with the GitHub Pull Requests extension, using Copilot to summarize issues/PRs. Available to everyone today with GitHub Copilot Free. Learn more: aka.ms/copilot-free
1273
Clarkio @clarkio.com · 25/12/2024
Netflix I want to watch the game live not resume 🤦
130
Clarkio @clarkio.com · 23/12/2024
Let's come up with some more random subject jumps/non sequiturs... "Great content mate, have you thought about saving 15% or more on your car insurance with Geico?"
110
Clarkio @clarkio.com · 23/12/2024
Talk about non sequitur! No I haven’t had a need to consider that. Thanks tho
A direct message that says “great content mate, ever considered ways of optimizing your testosterone?”
000
Reposted by Clarkio
Scott Hanselman 🌮 @scott.hanselman.com · 21/12/2024
Open Sauced has joined the Linux Foundation! Learn all about @bizza.pizza's team's experience building Open Sauced on this week's podcast www.hanselminutes.com/976/next-ste...
hanselminutes.com
Next steps for Open Sauced with Brian Douglas
Brian Douglas is the founder and CEO of Open Sauced where he works on increasing the knowledge and insights of open-source communities. In the past he’s lead Developer Advocacy at GitHub by fostering ...
4477
Reposted by Clarkio
Liran Tal @lirantal.com · 18/12/2024
I just scored 2159 on Vuln Vortex game by Snyk www.vulnvortex.com/api/invite?s... Think you can score higher than me on dodging vulnerable and malicious dependencies? Try your best 👇🎮 #vulnvortex #snyk
vulnvortex.com
Vuln Vortex
Can you escape all the vulnerable npm packages? Try your luck with Vuln Vortex
061
Reposted by Clarkio
Bun @bun.sh · 17/12/2024
Bun v1.1.39 - Fixes 61 bugs, addressing 99 👍 - bun.lock – bun's new text lockfile - 30% faster cached bun install - Lots of Node compatibility improvements - `bun build` Rust plugins - fetch() request body stream - more!! Thanks to 20 contributors bun.sh/blog/bun-v1....
bun.sh
Bun v1.1.39
Fixes 61 bugs (addressing 99 👍). bun.lock is bun's new text-based lockfile. Cached bun install gets 30% faster. fetch() request body streams. 100% of string_decoder, punycode and querystring Node.js t...
1495
Reposted by Clarkio
Brian Vermeer @brianvermeer.nl · 10/12/2024
This is a very nice example of a supply chain security problem. Even a plugin in your IDE or, in this case, your browser can do things you might not expect. Video by @clarkio.com
buff.ly
How Dark Mode Got Me Hacked
The infamous Light Mode vs Dark Mode battle has been waging for some time... I've always been a Dark Mode person, but now, I think I might be changing sides....
041
Reposted by Clarkio
Visual Studio Code @vscode.dev · 09/12/2024
Hello, World!
43581159
Reposted by Clarkio
GitHub @github.com · 09/12/2024
Turn your GitHub history into a masterpiece! With the new GitHub Skyline CLI extension, generate stunning 3D skylines of your contributions and print them IRL: github.blog/changelog/20.... Let’s see your #GitHubSkyline!
317035
Clarkio @clarkio.com · 07/12/2024
I'm setting up a new work machine and first thing I did is pop on the @w3cj.com @syntax.fm video for setting up a Mac in 2024: www.youtube.com/watch?v=GK7z... Such a great video and I've referred to it numerous times now not just for a new machine. Check it out!
youtube.com
Set up a Mac in 2024 for Power Users and Developers
YouTube video by Syntax
1111
Clarkio @clarkio.com · 04/12/2024
The comments are coming in hot on this one 😅
020
Reposted by Clarkio
Liran Tal @lirantal.com · 04/12/2024
🔮 New in Node.js native test runner — You can mock method calls with mock.method(object, method) and supply an optional implementation too: www.nodejs-security.com/newsletter/b...
1122
Clarkio @clarkio.com · 04/12/2024
Comedic timing @hankgreen.bsky.social @joelhooks.com
BlueSky feed containing two posts. The first from Hank Green sharing he wants to share one piece of advice for a commencement speech “do things more.” The following post is from Joel Hooks saying “Do as little as possible” sharing a link to a blog explaining this more.
420
Reposted by Clarkio
Warp @warp.dev · 03/12/2024
🎁 From now until the end of December, each referral to Warp is 1 entry into our Holiday Referrals Giveaway! Here’s what’s up for grabs: - North Face backpacks - Moleskin notebooks - Hydroflasks - Hoodies We’ll randomly send out swag to some of the first 200 to repost this! youtu.be/ZRk7I0Np1hk
youtu.be
We have new swag
YouTube video by warpdotdev
34564
Clarkio @clarkio.com · 03/12/2024
Recorded a remake of a previously old video (2+ years ago). Gonna experiment to see if the newer one does better. Plus I saw a suggestion that it’s not a bad idea to reuse past content this time of the year. It helps to create breathing room to think about content for next year.
020
Reposted by Clarkio
Clarkio @clarkio.com · 02/12/2024
Light mode vs. dark mode. I know it's boring, tired and you probably eye-roll whenever it comes up. BUT! I think this will actually be of interest to you because dark mode got me hacked! 😔😅 Full story in this ~12 min video 👇 youtu.be/2UJMgc68niY?...
youtu.be
How Dark Mode Got Me Hacked
YouTube video by Snyk
052