Sign in

Jamie Taylor

@gaprogman.com
235 followers 164 following 2.4K posts

Technology consultant & fractional CTO specializing in .NET architecture & security. Former Microsoft MVP | Host of The Modern .NET Show | Open source contributor

PostsRepliesMedia
Jamie Taylor @gaprogman.com · 8h
To be clear about what it is not: an SEO trick. It does not make anything rank. It is a convenience, because making a machine parse a page built for a human was always a waste of everybody's time. rjj-software.co.uk/tags/continu...
000
Jamie Taylor @gaprogman.com · 8h
The version I use most is the tag pages. One URL returns an index of 35 posts with a description of each, and every link in it already ends in index.md. Point an agent at that and it can work through the whole column on its own.
100
Jamie Taylor @gaprogman.com · 8h
It is there for one job: handing a page to an agent. If you want something summarised, or you want to ask questions of it, point at the markdown. A 2,200 word post comes back as about 15 KB of text and nothing else.
100
Jamie Taylor @gaprogman.com · 8h
A thing both of my sites do that almost nobody knows about. Append index.md to any URL on rjj-software.co.uk or dotnetcore.show and you get that page as plain markdown. The navigation and the cookie banner are simply absent, because none of that was the part you wanted.
100
Jamie Taylor @gaprogman.com · 13h
The most damaging decisions I have watched leaders make were not made in ignorance. They were made in anger, in the heat of a failure, reaching for a person to hold responsible rather than a process to fix. New post on Friday.
000
Jamie Taylor @gaprogman.com · 13h
The sharper version is about anger, which it calls incompatible with critical thought. Anger wants relief, and the fastest relief is to lash out. It does not weigh consequences, and it almost always leaves you somewhere worse than you started.
100
Jamie Taylor @gaprogman.com · 13h
The book I have been reading on critical thinking has an unglamorous instruction for when things go wrong. Do not react immediately, then go back to the planning stage. It says the fastest route through a problem is often to stop moving towards it for a moment.
100
Jamie Taylor @gaprogman.com · 13h
Our industry rewards the fast responder. First into the incident channel, first with a theory, first to push a fix. Sometimes that is exactly right. It is also how a team turns a small problem into a large one.
100
Jamie Taylor @gaprogman.com · 29/09/2026
Version 11 of my OwaspHeaders.Core middleware will install an agent and Claude skill when you build (there are opt-out steps) to help you use it. Version 11 has a few breaking changes, all of which will be documented, so the skill is there to help with upgrades and new installs of the package.
Output from Claude Code. The user has asked it to describe the /owaspheaders-core skill, and it responds detailing what the skill can do and why it exists.
000
Jamie Taylor @gaprogman.com · 29/09/2026
One trap that will cost you the exercise: sort by commit date, not by file modification time. A fresh clone resets every timestamp, so a repo you pulled this morning reports every abandoned skill as modified today.
rjj-software.co.uk
The Agent Files Nobody Owns: Auditing Your Agentic Setup
An agent found a skill nobody had reviewed in months and did what it said. How to find the unused Claude skills and slash commands your coding agent reads.
001
Jamie Taylor @gaprogman.com · 29/09/2026
The thirty second version of last week's audit, for anybody who did not fancy building a tool. List your agent-discoverable directories. Sort the files by the date of the last commit that touched them. Take the five oldest to your next retrospective.
100
Jamie Taylor @gaprogman.com · 28/09/2026
I only just read about WorldLabs in Fast Company, and they sounded impressive then. Now theyre part of AMD. www.worldlabs.ai/blog/amd-ann...
worldlabs.ai
World Labs is Joining AMD
Accelerating the future of AI research and compute
000
Jamie Taylor @gaprogman.com · 28/09/2026
The only reliable difference is whether somebody stopped, for the thirty seconds it costs, to ask how we actually know that. New post on Friday about the discipline that makes that stop happen.
000
Jamie Taylor @gaprogman.com · 28/09/2026
Here is the uncomfortable part. From the inside, those two situations feel identical while you are in them. A good decision and a lucky one are indistinguishable in the moment, which is how teams keep mistaking one for the other for years.
100
Jamie Taylor @gaprogman.com · 28/09/2026
Sometimes the cache really was the problem and the room looks clever. Sometimes it was not, the flush makes things worse, and an hour disappears chasing a fix for a fault that was never there.
100
Jamie Taylor @gaprogman.com · 28/09/2026
Twenty minutes into an incident. Dashboards red, support queue filling, six people in a call that started with two. Someone says it is probably the cache. It sounds right, it fits the last time this happened, and somebody is already writing the change to flush it.
100
Jamie Taylor @gaprogman.com · 28/09/2026
That 9 hour flight home will be crazy. Loop has completely redeemed himself, and deserves the crazy party they're clearly about to throw for him.
000
Jamie Taylor @gaprogman.com · 28/09/2026
Jackson's timeout signal was perfect. Musicians can learn timing from him. And Loop's kick was legendary. How did the Cowboys lose control, at the 5 yard line, with 7 seconds left? The Ravens, that's how.
110
Jamie Taylor @gaprogman.com · 27/09/2026
I was using my OWASP Headers middleware for #dotnet earlier today and found a pretty big bug. The power of dogfooding. github.com/GaProgMan/Ow...
github.com
Bug report: UseCacheControl flags are not combinable and the default lacks no-cache · Issue #261 · GaProgMan/OwaspHeaders.Core
The Bug CacheControl.BuildHeaderValue() (src/Models/CacheControl.cs) treats the UseCacheControl flags as mutually exclusive. It returns early on the first flag that is set (noCache, then private, t...
000
Jamie Taylor @gaprogman.com · 27/09/2026
Mr. 15: "So." Me: "So I know what homework is for. What are you going to do in your exam? You won't have access to ChatGPT. You need to reflect on the bits you can't recall, and spend some time revisiting them." Mr. 15: "No I don't."
000
Jamie Taylor @gaprogman.com · 27/09/2026
Mr. 15: "ChatGPT knows the answers." Me: "the point is not to find the answers elsewhere, it's to test your knowledge and recall." Mr. 15: "No its not." Me: “It's also to help you to figure out what you can't recall, and to help you revise." Mr. 15: "No its not." Me: "Dude. I used to be a teacher."
100
Jamie Taylor @gaprogman.com · 27/09/2026
Teacher friends, how are you dealing with students using LLMs to answer their homework? I used to be a teacher, and it blew my mind when I saw Mr. 15 feed his homework questions into ChatGPT, then wrote out the answers. I asked him what he learned, and he said....
100
Jamie Taylor @gaprogman.com · 27/09/2026
Its because you were playing against the Steelers, and the Steelers cheat. At least, they always do when taking on the Ravens. Go Ravens.
010
Jamie Taylor @gaprogman.com · 27/09/2026
Emma Burstow's version is sharper. If you cannot read it and understand it, you cannot claim it. And if you cannot claim it, why push it into somebody else's codebase? dotnetcore.show/season-9/its...
000
Jamie Taylor @gaprogman.com · 27/09/2026
And we never said so. Nobody ever wrote "I got this off a stranger on Stack Overflow" in a pull request, and nobody ever declared the LINQ statement ReSharper wrote for them. So "that wasn't me, that was Claude" should not get you off the hook either.
100
Jamie Taylor @gaprogman.com · 27/09/2026
Sunday thought, from Carole Rennie Logan on Friday's episode. We always Googled. We went to the docs, we copied, we pasted, we altered it. It was never the case that we rewrote every single line ourselves. This is just the new way of getting there.
100
Jamie Taylor @gaprogman.com · 26/09/2026
I agree. And it's something I've been writing about recently. Here's the latest in a series of posts about both the CLAUDE and AGENTS MD files rjj-software.co.uk/blog/agent-f...
rjj-software.co.uk
The Agent Files Nobody Owns: Auditing Your Agentic Setup
An agent found a skill nobody had reviewed in months and did what it said. How to find the unused Claude skills and slash commands your coding agent reads.
000
Jamie Taylor @gaprogman.com · 26/09/2026
If you're interested in meeting Dot, you can check it out here: palstudio.whitefishcreative.co.uk/pals/dot/
palstudio.whitefishcreative.co.uk
Dot | Desktop Pals by WhiteFish Creative
Dot – The Modern .NET Show's desktop pal. A purple robot with a microphone and 500 .NET opinions, who tells you when new episodes are out.
000
Jamie Taylor @gaprogman.com · 26/09/2026
I'm a very happy beta tester of Dot (the Modern .NET Show pal), and you should check out the family of Pals: palstudio.whitefishcreative.co.uk
palstudio.whitefishcreative.co.uk
Desktop Pals – PalStudio by WhiteFish Creative
Clippy-style desktop pals for Mac and Windows from WhiteFish Creative. A blast back to the early 2000s – without the viruses, malware or spyware. Just a bit of fun to make your day brighter.
100
Jamie Taylor @gaprogman.com · 26/09/2026
In the larger blog post I linked to, I mention that the ADR directory should be linked to in the CLAUDE or Agents file. That way, it knows to check for ADRs before proposing a change.
000
Jamie Taylor @gaprogman.com · 26/09/2026
And the worry about losing the work is unfounded. Git already remembers every version of every file you have ever committed. That is the whole reason main does not have to carry your abandoned experiments. rjj-software.co.uk/blog/agent-f...
000
Jamie Taylor @gaprogman.com · 26/09/2026
An architecture decision record does it properly. What we adopted, when, why we stopped, what we do instead. Absent from the agent's context, available to the team and to the agent on request. Write it as a closed decision, not a description of how the thing works.
200
Jamie Taylor @gaprogman.com · 26/09/2026
The obvious move is to write a note in CLAUDE.md saying the team tried it and stopped. Please do not. That is a paragraph resident in context on every session, describing a methodology in enough detail for an agent to have a view about it. A smaller dead file in a costlier place.
100
Jamie Taylor @gaprogman.com · 26/09/2026
Deleting an abandoned skill is the easy half. The half people get wrong is what happens to the reasoning. Somebody chose spec-kit, ran it for six weeks, and concluded it was too heavy for the work in front of them. That conclusion is the return on the experiment.
100
Jamie Taylor @gaprogman.com · 25/09/2026
There are audience questions, two contributors describing work that would not otherwise exist, and a disagreement about juniors we never resolve. dotnetcore.show/season-9/its...
000
Jamie Taylor @gaprogman.com · 25/09/2026
Carole Rennie Logan drew the line where she thinks it has always been. We always Googled, we always copied something from the docs and changed it, and we never declared it. The moment you commit it, it is yours, and you are the one who has to explain it.
100
Jamie Taylor @gaprogman.com · 25/09/2026
Lotte Pitcher put it more bluntly. It would be hypocritical to refuse AI-assisted contributions when Umbraco's own product and engineering teams use those tools productively every day. They have no AI contribution guidelines, and would rather react than put people off first.
100
Jamie Taylor @gaprogman.com · 25/09/2026
Emma Burstow of Umbraco admitted they had barely had the conversation internally, and then explained why it had never come up. The guardrails that catch a bad contribution are the ones that were always there. Review, tests, and a maintainer who asks you why.
100
Jamie Taylor @gaprogman.com · 25/09/2026
New episode, and an unusual one. It was recorded on a stage at Codegarden in front of a room full of Umbraco developers, as a collaboration with the Candid Contributions podcast. The question: how should an open source project feel about pull requests written with the help of an LLM?
120
Jamie Taylor @gaprogman.com · 25/09/2026
One file is read by an agent nobody asked. The other is read by nobody at all. Both are in main, and both are a repository making a claim about how the work is done that stopped being true a while ago. rjj-software.co.uk/blog/agent-f...
000
Jamie Taylor @gaprogman.com · 25/09/2026
What does survive measurement is stranger. In another client repository the docs directory holds about twenty thousand words that the entry-point file does not link to at all. Not resident, not linked, not reachable by following a path from CLAUDE.md. Nothing reads it.
100
Jamie Taylor @gaprogman.com · 25/09/2026
I went in expecting the headline to be context. A hundred dead files sounds expensive. It is not true, and I would rather tell you that than let you find out from somebody else. Skills load progressively; only names and descriptions are resident. In that repo, 2,738 words.
100
Jamie Taylor @gaprogman.com · 25/09/2026
None of them is in use. The team settled on one way of working months ago. Every one of those experiments was worth running, and trying several is how you find the one that fits. Nobody warned anybody about the other half of the experiment, which is retiring the ones that lost.
100
Jamie Taylor @gaprogman.com · 25/09/2026
New post. Here is a repository shape I keep running into, composited from several clients so that nobody is identifiable. The main branch carries spec-kit. It also carries BMAD. Somewhere in there is Gastown, and a directory belonging to get-shit-done.
100
Jamie Taylor @gaprogman.com · 25/09/2026
S09E02 - It's Still Your Code: AI Contributions to Open Source, Live at Codegarden A live panel from the Codegarden stage, recorded with the Candid Contributions podcast: Emma Burstow, Lotte Pitcher and Carole Rennie Logan on whether open source should accept AI-assisted contributions, and who is
dotnetcore.show
S09E02 - It's Still Your Code: AI Contributions to Open Source, Live at Codegarden
A live panel from the Codegarden stage, recorded with the Candid Contributions podcast: Emma Burstow, Lotte Pitcher and Carole Rennie Logan on whether open source should accept AI-assisted contributions, and who is responsible for the code once it lands.
000
Jamie Taylor @gaprogman.com · 25/09/2026
Probably not, because that account looks unused. Oh well, I'd better raise a ticket through their volunteer-based support system. I mean, we've all tested in production at somepoint in our careers, right?
000
Jamie Taylor @gaprogman.com · 25/09/2026
I wonder if @libsyn.com are aware of the multiple times that users get an alert box with the strong "0" in it when accessing their account.
A webbrowser's alert dialogue shows the message "0" with an OK button.
101
Jamie Taylor @gaprogman.com · 24/09/2026
Its 2026 and of 4,688 small business websites tested (by this one page) 49.7% is then didn't have security headers present: rackcrunch.com/security-hea... If you're running a #dotnet website, you can get the majority of them for free using my NuGet package: gaprogman.github.io/OwaspHeaders...
rackcrunch.com
Security Headers Study 2026: Local Businesses | RACKCRUNCH
We scanned 7,040 directory-listed U.S. local-business websites for security headers. Half met none of seven criteria. Full report, data and code.
020
Jamie Taylor @gaprogman.com · 24/09/2026
Reaching out with "why haven't you invited me onto your podcast! You need to have me on your podcast!" is the quickest way to ensure you don't get to be on the podcast. Be nice to each other folks.
000
Jamie Taylor @gaprogman.com · 24/09/2026
Did... Did they just make Fifteen Million Merits a thing? I think they just made Fifteen Million Merits a thing. www.youtube.com/watch?v=Smwo...
youtube.com
Microsoft’s Terrifying New Patent | LG-Style ACR for Games & Software
YouTube video by Gamers Nexus
010