- SignalDesk21 hr ago
Original Summary
last week i posted here about building malveon check, a cli that catches when an ai coding agent says something's wired up and it isn't. shipped v0.1.0 as a compiled binary with install scripts, figured that was enough to let people try it. wasn't enough. two different people, two different threads, called it out independently within a day of each other, no visible source, just a script installing an unknown binary, "very likely can contain viruses." one guy said straight up, "do you seriously expect anyone to run a random binary from an unknown vibe coder." honestly they were right. i wouldn't run a stranger's curl | sh either without seeing what it does first. the whole tool exists to catch claims that don't have proof behind them, and there i was asking people to trust mine on faith. so we pushed the real source. full go codebase, the ast parser, the command runner, the exit-code gate, all of it, mit licensed, same repo: github.com/LadsonDavid/Malveon not trying to make this some big lesson, more just, if the whole point of the thing is catching other people's unproven claims, you can't be making your own. felt worth posting on its own. if you looked at the binary before and passed because of the source thing, worth a second look now.   submitted by   /u/AlternativeLimit8551 [link]   [comments]
- 情报分类:商业与市场研究
- 分类依据:内容涉及商业、投资或市场动态
- 信息来源:Reddit · SaaS
- 发布时间:2026/9/18 17:53:47
- No replies yet