Sign in

Clarkio

@clarkio.com
1.1K followers 187 following 232 posts

Web dev and app sec things. Here for community, fun and learning. Not here to accrue numbers or influence you.

PostsRepliesMedia
Clarkio @clarkio.com · 20/08/2026
Anyone else getting a sense for what generation someone is in by how often they use the word “literally”?
011
Clarkio @clarkio.com · 20/08/2026
Whenever bun has a new release I enjoy the videos that go with them😁 youtu.be/i38DgEuaJwM
youtu.be
Bun v1.4
YouTube video by Bun
000
Clarkio @clarkio.com · 28/05/2026
A fun test to see how well you do at checking agentic AI permissions: llmgame.scalex.dev
llmgame.scalex.dev
Continue? Y/N
A 30-second game about LLM permission fatigue. How carefully do you really read AI commands?
010
Clarkio @clarkio.com · 20/05/2026
Your first instinct after getting hit by the TanStack npm attack is to revoke your GitHub token. Don't. The malware polls GitHub every 60 seconds. Gets a 401? It runs rm -rf ~/ Here's the right remediation order before you touch a single credential. youtu.be/YrwM2EFYrUY
youtu.be
Mini Shai-Hulud: The Most Sophisticated NPM Supply Chain Attack of 2026
YouTube video by Snyk
020
Clarkio @clarkio.com · 08/05/2026
I’ve personally not received access to Mythos to test it at this time
110
Clarkio @clarkio.com · 08/05/2026
Your posts are being flagged as spam for some reason
100
Clarkio @clarkio.com · 08/05/2026
FYI
100
Clarkio @clarkio.com · 08/05/2026
Companies are deploying AI-generated code into production. Much of that code contains vulnerabilities. Making traditional AppSec struggle to keep up Snyk + Anthropic's Claude = security at AI speed 👇 snyk.io/news/snyk-embeds-anthropics-claude-to-advance-ai-powered-security-for-software-development
snyk.io
Snyk Embeds Anthropic's Claude to Advance AI-Powered Security for Software Development | Snyk
Starting today, Snyk has integrated Claude into the Snyk AI Security Platform — powering automated vulnerability discovery, prioritization, and developer-ready fixes across code, dependencies, contain...
130
Clarkio @clarkio.com · 13/11/2025
Been getting messages asking how I use Codex in my projects. Finally made a video about it! I break down my entire workflow and share the tips and tricks that make the biggest difference in my daily coding. Hope it helps 👍 🎥👇 youtu.be/mP-GiOihhM0
A smiling Clarkio wearing a backward black Snyk cap against a purple background with binary code. To the right, there’s a screenshot of the OpenAI Codex interface displaying the text 'What should we code next?' with a red arrow pointing to the input box. Above, bold text reads 'TIPS & TRICKS' in purple and pink gradient letters.
030
Clarkio @clarkio.com · 06/11/2025
It's been validating seeing them struggle to get a CSP just right 😅
000
Clarkio @clarkio.com · 06/11/2025
Can your AI code gen model/tools of choice generate a proper Content Security Policy that allows everything to still work properly?
100
Clarkio @clarkio.com · 15/10/2025
AI is transforming how we build, deploy & secure software. Learn how to empower innovation without compromising security at #DevSecCon, the Global Community Summit on AI Security. Details: 💻 Virtual 🗓️ Oct 22, 2025 🔗 snyk.io/events/devseccon
The DevSecCon 2025 logo above large white text on a purple gradient background that reads “Securing the Shift to AI Native.” Below, smaller white text says “October 22, 2025 - Virtual.”
010
Clarkio @clarkio.com · 13/10/2025
If you’re using Windsurf and not adding MCP servers you’re missing out on serious power. I’ll show you how to add them from the store and manually (including Snyk!) Full video 👇 youtu.be/exGudnPb9Bo
A smiling clarkio wearing a backward black Snyk cap and a black shirt with the Snyk logo, pointing to text on the right that says 'Manage MCP servers' with a visible 'snyk Configure' button. Large bold text at the top reads 'MCP SERVERS IN WINDSURF' in blue and purple gradient. On the left, there’s the Windsurf logo with teal curved lines on a dark background, all set against a bright purple and blue gradient backdrop.
020
Clarkio @clarkio.com · 07/10/2025
I asked Claude Sonnet 4.5 to build a secure Node.js note taking app from scratch. The results surprised me! Watch here 👇 youtu.be/YBl0BR3fgjA
Clarkio wearing a backward black Snyk cap looking surprised, set against a bright purple and blue background. To his right is an editor window titled 'SECURITY_REPORT.md' displaying a Markdown document describing a 'production-ready, security-hardened Node.js notes application.' Above him is the orange starburst logo for Anthropic, and bold gradient text at the bottom reads 'BEST IN THE WORLD?!' in blue and purple letters.
000
Clarkio @clarkio.com · 29/09/2025
Stop using .env files for your API keys. They’re not safe anymore. Here’s why and what to do instead 👇 youtu.be/pcbRwwaCPUg
Clarkio with a thoughtful face wearing a backwards Snyk cap, resting his chin on his hand. At the top is a code editor showing .env, package.json, and index.js tabs, with code that logs API_KEY from process.env. To the right is a tweet screenshot that says 'Cursor steals your dev creds,' with a red arrow pointing at it. At the bottom, bold red text reads '.ENV IS BAD' against a purple background.
000
Clarkio @clarkio.com · 22/09/2025
Spec-driven development + AI = the future? 🤔 I explored Amazon’s new Kiro IDE paired with Claude Sonnet 4 to find out. Watch and tell me if you’d code like this 👇 🎥 youtu.be/YpB1QS58KZE
Bright thumbnail image featuring a surprised clarkio on the left side, with wide eyes and open mouth. The background is a vibrant mix of purple and pink hues with binary code pattern. Bold text at the top reads 'SPEC DRIVEN DEVELOPMENT' in blue and white. On the right, a UI screenshot shows two options: 'Vibe' and 'Spec,' with the 'Spec' option highlighted, which says 'Plan first, then build. Create requirements and design before coding starts.' A red arrow points to the highlighted option.
000
Clarkio @clarkio.com · 19/09/2025
We’re in the wave of spec-driven development now.
010
Clarkio @clarkio.com · 15/09/2025
I put Replit to the test and was honestly shocked by the outcome. If you care about what AI coding tools can (and can’t) do, you’ll want to see this. 📹👉 youtu.be/gHGB3kptH_s
On the right-hand side is text in bold letters "This is crazy!" overlayed on the Replit logo. Above that is a screen shot of the application that was built in the video. On the left-hand side is an image of clarkio smiling. The background is a gradient from purple to blue with circuit lines and 1's and 0's
000
Clarkio @clarkio.com · 27/08/2025
This has been a fun loop🤪 Agent: Everything is done let me run the app Terminal: App running Agent: Perfect! Let me test it with curl *kills app for curl* Agent: Let me start the server again and test it Terminal: App running Agent: Perfect! Let me test it with curl
030
Clarkio @clarkio.com · 14/08/2025
What's been your experience? Is it all hype? Or maybe all hate? Or are you finding it's been fairly balanced when using these technologies?
010
Clarkio @clarkio.com · 14/08/2025
Outside of this instance I've had plenty of delight moments as well. So tbh I don't know for sure when it's worth it or not as the answer is usually "it depends". Regardless I wanted to put this out there as a practical experience among all the hype and hate.
100
Clarkio @clarkio.com · 14/08/2025
I did this to tinker and experiment. I imagine in an agentic flow with auto accept conditions on it would eventually get to a fully working solution. But at what cost? How many tokens/etc.? And was it worth it vs. building it by hand or using an existing template?
100
Clarkio @clarkio.com · 14/08/2025
It failed to use the latest versions of the dependencies it chose It failed to use compatible versions of plugin packages for the main web framework dependency It failed to handle different environmental variations (e.g. file paths on diff OSes) Just to name a few...
100
Clarkio @clarkio.com · 14/08/2025
I'm using Claude Code and asked it to spin up a quick Node.js API to support an OAuth flow. While the code looked syntactically correct if you tried to run it things failed.
100
Clarkio @clarkio.com · 14/08/2025
When it comes to AI/LLMs I aim to have a balanced perspective on it. There are times I'm delighted by what they do and other times I'm unimpressed. Today I felt a bit unimpressed...
100
Clarkio @clarkio.com · 12/08/2025
Giving Claude Opus 4.1 a go at writing a secure app ↙️ youtu.be/ELSl0RmFxLg?...
Clarkio in the forefront thinking with a screen shot image of JSON showing project dependencies and bold text of "Claude Opus 4.1"
010
Reposted by Clarkio
Brian Vermeer @brianvermeer.nl · 06/08/2025
How to Add MCP Servers to VS Code by @clarkio.com youtu.be/50tkvZhOVqM?...
youtu.be
How to Add MCP Servers to VS Code (with GitHub Copilot)
In this tutorial, I’ll walk you through the step-by-step process of adding MCP servers to Visual Studio Code using GitHub Copilot. Whether you’re setting up your first MCP server or integrating…
021
Reposted by Clarkio
Liran Tal @lirantal.com · 03/08/2025
y'all are sleeping on npq ✨ Step 1: $ npm install -g npq $ alias npm="npq-hero" Step 2: *no more malicious packages hurting you ;-) *well, much lower risk based, nothing is absolute
1102
Clarkio @clarkio.com · 16/05/2025
Backwards hat Salma?! Hell yea!
120
Clarkio @clarkio.com · 19/04/2025
I had already felt this as my career progressed but that has accelerated with AI/LLM's
030
Clarkio @clarkio.com · 19/04/2025
Reading code is becoming even more valuable than writing it.
130
Reposted by Clarkio
Visual Studio Code @vscode.dev · 15/04/2025
VS Code Live: Agent Mode Day is tomorrow, April 16th! And we've got a special guest joining us - @wesbos.com will be closing out the stream with a live coding session! You won't want to miss this. Stream starts at 9 AM PT: youtube.com/live/HNly8eN...
A thumbnail with a dark background and a picture of Wes Bos in the top right. The thumbnail reads "Agent Mode Day with Wes Bos" and says "VS Code Live" in the bottom left
0201
Reposted by Clarkio
Visual Studio Code @vscode.dev · 07/04/2025
Agent mode is rolling out to all users! 🔁 Autonomous code editing 🔍 Full codebase awareness 💬 Built in tools for codebase search, terminal, fetching website content and more All extensible via MCP & VS Code Extensions. All available today. Learn more:
code.visualstudio.com
Agent mode: available to all users and supports MCP
Agent mode is now available to all users and supports MCP.
03111
Clarkio @clarkio.com · 08/03/2025
Had a blast today! Thanks for joining!
000
Reposted by Clarkio
Liran Tal @lirantal.com · 04/03/2025
haha Brian is just hilarious 😂 checkout the new video about Claude 3.7 and whether it's actually better for generating secure code: www.youtube.com/watch?v=zM8c...
071
Reposted by Clarkio
HTTP Archive 💾 @httparchive.org · 03/03/2025
We've just published the 19th and final chapter of the 2024 Web Almanac on JavaScript by Abdul Haddi Amjad and Nishu Goel. almanac.httparchive.org/en/2024/java...
almanac.httparchive.org
JavaScript | 2024 | The Web Almanac by HTTP Archive
JavaScript chapter of the 2024 Web Almanac covering the usage of JavaScript on the web, libraries and frameworks, compression, web components, and source maps.
2113
Clarkio @clarkio.com · 03/03/2025
Last Resort - Papa Roach. Well played 😁👍
060
Clarkio @clarkio.com · 13/02/2025
Love that HMR is for the API as well. Does this mean it’s something like ‘bun init react’? Are there plans to support other frontends too then?
020
Clarkio @clarkio.com · 12/02/2025
Yes! It’s always a bit of a pain when tools don’t have this because it’s not always clear how to go about upgrading to the latest version
020
Reposted by Clarkio
Visual Studio Code @vscode.dev · 08/02/2025
Agent mode (preview) is here for GitHub Copilot in VS Code! In agent mode in Copilot Edits, Copilot can now iterate on its own output, execute terminal commands, and even self-heal from runtime errors. Try it in VS Code Insiders: code.visualstudio.com/updates/v1_97…
A thumbnail with a purple background, a 3d version of the GitHub Copilot logo in the foreground, and the words "GitHub Copilot agent mode"
0509
Reposted by Clarkio
Deno @deno.land · 03/02/2025
@jsr.io is now openly governed — meet its board members and check out its governance charter 👇 deno.com/blog/jsr-ope...
deno.com
Introducing the JSR open governance board
JSR, a modern open source JavaScript registry, is meant for the greater JavaScript and TypeScript community. We're thrilled to announce its own independent governing body.
512329
Clarkio @clarkio.com · 27/01/2025
This space is moving fast! New AI code editors, tools, models...💨
000
Clarkio @clarkio.com · 27/01/2025
Absolutely love @astro.build and highly recommend. It's fairly easy to pick up and super flexible so you can use what you already know (re: frontend dev). This just from personal experience and not affiliated in anyway.
010
Clarkio @clarkio.com · 27/01/2025
But I've seen legit comments on videos with questions on topic related to the video content go unanswered - even years later. I'm personally not perfect at this and will catch comments I've missed but thought I'd share as it can definitely impact your reputation and audience trust.
000
Clarkio @clarkio.com · 27/01/2025
Folks making videos, don't tell your audience to leave a comment/question where you'll reply with your answer and then don't reply to any of them. Of course, there are some exceptions to this like trolls or hate comments...
100
Clarkio @clarkio.com · 25/01/2025
I’m itching to try it out when I get some time… and make a video for it 😁 What model does it use?
100
Clarkio @clarkio.com · 22/01/2025
You all were fantastic in this one. Had lots of laughs and thoroughly enjoyed it! Congrats!
010
Clarkio @clarkio.com · 20/01/2025
If you do, I built a very rough tool to assist with playing the game over the weekend. You can check it out here: clarkio.com/wos-helper
020
Clarkio @clarkio.com · 20/01/2025
Does anyone here enjoy the game "Words on Stream" and tune in to streamers playing that or channels that run it 24/7? Link to the game for those not familiar with it: wos.gg
wos.gg
WOS - Words On Stream
Words On Stream, the free game that will boost your live streams on Twitch or YouTube
110
Clarkio @clarkio.com · 09/01/2025
delete delete delete delete delete 🙂
010