Sign in

Evgeniy

@valyay.bsky.social
10 followers 7 following 47 posts

Frontend developer at Evil Martians

PostsRepliesMedia
Evgeniy @valyay.bsky.social · 02/07/2026
A handy checklist to help you decide whether MCP makes sense for your product
110
Evgeniy @valyay.bsky.social · 01/07/2026
MCP servers are popping up everywhere, and it’s not always obvious when you actually need one. That’s why I wrote this article. It’s based on hands-on experience: building my own MCP server and working with MCP servers on client projects.
112
Reposted by Evgeniy
Evil Martians @evilmartians.com · 30/06/2026
Not every product needs an MCP, and it's also the most expensive option to maintain. Here, @valyay.bsky.social presents a framework to decide between direct API calls, CLI, Skills, and an MCP before you pull the lever. It includes what to trust, costs, and the soft spots worth watching:
evilmartians.com
Most MCP servers don't need to exist. Your case might be an exception.—Martian Chronicles, Evil Martians’ team blog
An MCP server is a product interface for the age of agents, not an AI feature itself. This post presents a framework for deciding between direct API calls, CLI, Skills, and MCP, detailing the architec...
022
Reposted by Evgeniy
Андрей Ситник @ru.sitnik.es · 19/05/2026
Мой коллега в @evilmartians.com написал хорошую статью, почему от LLM разработчики быстрее выгорают и как это избежать evilmartians.com/chronicles/a...
151
Evgeniy @valyay.bsky.social · 19/05/2026
This is the line between vibe-coding and shipping. You stay the architect. AI stays the builder.
000
Evgeniy @valyay.bsky.social · 19/05/2026
So start here. Don't accept what you can't explain. Before you click Accept, read the diff and say back what it does — in your own words. If you can't, paste the code to the model and ask: "explain every choice you made and why." Then argue with the answer.
100
Evgeniy @valyay.bsky.social · 19/05/2026
The question is no longer "how do I build this from scratch?" It's "how do I understand, verify, reshape, and own what was generated for me?" The bottleneck used to be production. Now it's comprehension.
100
Evgeniy @valyay.bsky.social · 19/05/2026
AI makes the first version cheap. It can make every next version much more expensive. That's the new complexity of AI-assisted development.
100
Evgeniy @valyay.bsky.social · 19/05/2026
And now learning the topic is no longer enough. You also have to learn the topic through a huge codebase that already exists. That makes understanding harder. Every change now has a higher price, because you're editing an implementation you barely understand.
100
Evgeniy @valyay.bsky.social · 19/05/2026
You have a codebase. Thousands of lines of code. Patterns you didn't fully choose. Abstractions you didn't fully design. Edge cases you didn't fully consider. Dependencies you didn't fully understand.
100
Evgeniy @valyay.bsky.social · 19/05/2026
Now you can generate a working prototype in an evening. And that feels like magic. Until the next day, when you open the project and realize you don't have a product.
100
Evgeniy @valyay.bsky.social · 19/05/2026
AI didn't remove complexity from software development. It moved it. Before AI, if you wanted to build something, you had to study the topic first. You had to understand the domain, the constraints, the architecture, and only then slowly turn that understanding into code.
120
Evgeniy @valyay.bsky.social · 11/05/2026
Link to skill: github.com/mattpocock/s...
github.com
skills/skills/engineering/grill-with-docs at main · mattpocock/skills
Skills for Real Engineers. Straight from my .claude directory. - mattpocock/skills
010
Evgeniy @valyay.bsky.social · 11/05/2026
A good example of this idea in practice is the grill-with-docs skill from @mattpocock.com : it helps stress-test ideas against existing documentation, clarify terminology, expose hidden assumptions, and make communication with AI more precise
110
Evgeniy @valyay.bsky.social · 11/05/2026
It is a practical tool for building shared meaning between people, teams, and AI systems.
100
Evgeniy @valyay.bsky.social · 11/05/2026
Philosophy can help us formulate AI problems correctly, and in AI, as in ordinary human life, correct formulation is already a large part of the solution. This is why philosophy is not something distant or abstract.
110
Evgeniy @valyay.bsky.social · 11/05/2026
The same is true for LLMs. If you and an LLM speak the same "language": using the same terms, the same context, and the same definitions —the model understands you much better, and you understand its answers much better too.
100
Evgeniy @valyay.bsky.social · 11/05/2026
Philosophy helps us assign clear terms to complex cases. It makes interaction easier, because people can finally understand what exactly they mean and what the other person means.
100
Evgeniy @valyay.bsky.social · 11/05/2026
A lot of philosophy is about defining the right terminology. In human arguments, people often don’t even understand what they are arguing about, because they use the same words while actually thinking about different things.
100
Evgeniy @valyay.bsky.social · 11/05/2026
I want to show that philosophy can help us even with AI problems, and that this is a very relevant issue right now.
100
Evgeniy @valyay.bsky.social · 11/05/2026
I refreshed my limited knowledge of philosophy and came to this conclusion. Philosophy and AI actually are best friends 😄 Many people don’t understand how philosophy can help us solve practical, urgent problems.
110
Evgeniy @valyay.bsky.social · 04/05/2026
None of this is specific to astro-iubenda. That is the point. If someone installs it in production, the supply chain risk remains real. Most of this is just config.
000
Evgeniy @valyay.bsky.social · 04/05/2026
Sixth: no dependency-managed postinstall hook setup. I removed simple-git-hooks postinstall behavior and switched to native git hooks: .githooks pnpm prepare-hooks Less install-time magic. More explicit repo config.
110
Evgeniy @valyay.bsky.social · 04/05/2026
Fifth: workflow permissions are scoped. The release workflow permissions are scoped to what this workflow actually does: contents: write — release commits/tags pull-requests: write — release PR id-token: write — npm OIDC publishing No broad default permissions just because it is easier.
100
Evgeniy @valyay.bsky.social · 04/05/2026
Fourth: GitHub Actions are pinned by commit SHA. Not: actions/checkout@v6 But: actions/checkout@de0fac... # v6.0.2 The SHA gives immutability. The comment keeps the version readable.
100
Evgeniy @valyay.bsky.social · 04/05/2026
Third: package manager pinning. The repo now requires pnpm 11 and pins the exact package manager with SHA512: packageManager: pnpm@11.0.4+sha512... Wrong package manager or wrong pnpm version? The install should fail.
110
Evgeniy @valyay.bsky.social · 04/05/2026
In astro-iubenda, I keep it explicit in .npmrc too: minimumReleaseAge=1440 Together with: package-manager-strict=true package-manager-strict-version=true verify-deps-before-run=error verify-store-integrity=true audit-level=moderate
100
Evgeniy @valyay.bsky.social · 04/05/2026
Why does that help? Many malicious npm releases are detected and removed quickly. A 24-hour delay reduces the chance of installing a compromised version during the first exposure window. If you are not on pnpm 11 yet, you can still enable it manually.
110
Evgeniy @valyay.bsky.social · 04/05/2026
Second: delayed fresh releases. pnpm.io/settings#min... pnpm 11 also sets this by default: minimumReleaseAge=1440 That means newly published package versions are not resolved until they are at least 24 hours old.
pnpm.io
Settings (pnpm-workspace.yaml) | pnpm
pnpm gets its configuration from the command line, environment variables, pnpm-workspace.yaml, and
110
Evgeniy @valyay.bsky.social · 04/05/2026
Why does that matter? Unexpected dependency build scripts now fail unless they are explicitly allowed. Exotic subdependencies, such as git or tarball-based subdeps, are blocked by default. And the dependency state is checked before the scripts run.
100
Evgeniy @valyay.bsky.social · 04/05/2026
First: pnpm 11 pnpm.io/blog/release... This is not just a tooling bump. pnpm 11 adds stricter supply-chain defaults: strictDepBuilds=true blockExoticSubdeps=true verifyDepsBeforeRun=install It also moves build-script control to the explicit allowBuilds model.
pnpm.io
pnpm 11.0 | pnpm
pnpm 11 is here! This release tightens the security defaults introduced throughout the v10 cycle, drops the npm CLI fallback for publishing in favor of a native implementation, replaces the JSON-per-p...
120
Evgeniy @valyay.bsky.social · 04/05/2026
Small open-source npm package? Same supply-chain risk. I’ve just updated astro-iubenda, a small Astro integration for using iubenda in @astro.build projects: github.com/Valyay/astro... Here are 6 supply-chain hardening techniques I added to the repo:
github.com
GitHub - Valyay/astro-iubenda: Astro integration to manage privacy policies, cookies and terms from Iubenda.
Astro integration to manage privacy policies, cookies and terms from Iubenda. - Valyay/astro-iubenda
111
Evgeniy @valyay.bsky.social · 30/04/2026
But now the developer from the future is often a coding agent. Stop giving AI agents broken memory.
130
Evgeniy @valyay.bsky.social · 30/04/2026
When coding agents use that memory as context, better memory leads to better reasoning. We used to say: write commit messages for the human developer from the future. That is still true.
100
Evgeniy @valyay.bsky.social · 30/04/2026
That commit gives the agent more than a code change. It gives the agent memory of a decision. Good commit messages do not magically make LLMs smarter. They make project memory better.
100
Evgeniy @valyay.bsky.social · 30/04/2026
Context: The CTA must stay visible because it is the main signup entry point. Trade-off: Keep the layout CSS-only instead of recalculating header position in JS.
100
Evgeniy @valyay.bsky.social · 30/04/2026
fix(header): prevent CTA layout shift on mobile Description: Why: On slow mobile devices, the header CTA moved after hydration and caused accidental taps. Goal: Keep the header stable before and after hydration.
100
Evgeniy @valyay.bsky.social · 30/04/2026
That is why we should use commit descriptions more actively. The title should stay short and scannable. The description is where memory lives.
100
Evgeniy @valyay.bsky.social · 30/04/2026
But they usually do not answer: why was this needed? which bug should not come back? which constraint must be preserved? what was the goal? which trade-off was accepted? Agents need more than type and scope. They need intent.
100
Evgeniy @valyay.bsky.social · 30/04/2026
They make git history machine-readable. They do not automatically make it understandable. They answer: what kind of change is this?
100
Evgeniy @valyay.bsky.social · 30/04/2026
Now tools know what kind of change happened. Sometimes they know the scope. Changelogs get easier. Breaking changes become clearer. But Conventional Commits are not enough for AI coding agents.
100
Evgeniy @valyay.bsky.social · 30/04/2026
Many teams stop too early. They adopt Conventional Commits. And that helps. fix(header): prevent nav jump during hydration is much better than: fix bug
100
Evgeniy @valyay.bsky.social · 30/04/2026
This matters because coding agents rely on broader project context: issues, PR discussions, repository instructions, commit history. Better project memory → better agent reasoning.
110
Evgeniy @valyay.bsky.social · 30/04/2026
When it says fix mobile nav layout, it learns a little more. But when it says fix mobile nav layout to prevent CTA from jumping during hydration, it learns why the change exists. That is the difference between a label and memory.
100
Evgeniy @valyay.bsky.social · 30/04/2026
The difference is that now the “future developer” is often a coding agent reconstructing intent from context. When git history says fix layout, the agent learns almost nothing.
110
Evgeniy @valyay.bsky.social · 30/04/2026
Git history can explain that. But only if we write it that way. This problem is not new. Bad commit messages always made projects harder to understand months later.
100
Evgeniy @valyay.bsky.social · 30/04/2026
Coding agents don’t just need code. They need intent. A diff can show what changed. But it rarely explains why the obvious solution was not used, which bug happened before, which constraint must not be broken, or which trade-off the team accepted.
100
Evgeniy @valyay.bsky.social · 30/04/2026
These were always bad commit messages. But in the age of AI coding tools, they are worse than bad style. They are broken memory.
210
Evgeniy @valyay.bsky.social · 30/04/2026
We already have memory for AI coding agents. It’s called git. And many teams are filling it with garbage: fix bug update styles refactor component
131
Reposted by Evgeniy
Evil Martians @evilmartians.com · 07/01/2025
Building a dev-facing product and looking to fundraise in 2025? We analyze the top 16 active VCs and investors right now: get the data, see who might be the best fit for your product, and tips on how to effectively connect. evilmartians.com/chronicles/t...
evilmartians.com
The 16 most active developer tool investors and VCs going into 2025—Martian Chronicles, Evil Martians’ team blog
Building a developer-facing product and eyeing a fundraise in 2025? Here are the current active investors and VCs. We analyze the top 16, who might be the best fit for your product, and how to effecti...
094