proomt

Search

Search posts, papers, and topics

All posts

Simon Willison1 min readintro

Note on 24th September 2026

Summary

The author argues that LLM coding agents make software engineering harder and demand extraordinary discipline and expertise. A sponsor note adds that focusing on quality over quantity yields better security vulnerability detection.

  • Coding agents increase engineering complexity, not simplify it.
  • Effective use of LLMs requires strong discipline and deep knowledge of the codebase.
  • Prioritizing quality over quantity improves security bug discovery when using LLMs.

Engineers who rely on LLM code assistants need to understand the hidden costs and required rigor to avoid making their work harder.

3/10

Related reading

  1. 2026 in LLMs (so far)

    The post recaps 2026 LLM milestones, noting that Claude Opus 4.5 and GPT‑5.1 made coding agents reliable enough for daily use, sparking AI‑driven side projects and a surge of sandboxing and agent‑security discussions. The author reflects on "AI mania", personal experiments, and the cultural impact on engineers.

    Simon Willisonsimonwillison.net21 minHN5
  2. Non Cogito, Ergo Quid Sum?

    The essay argues that LLMs are already outperforming human programmers and rapidly becoming cheaper, which could render software engineers obsolete. It warns of societal consequences and doubts that handcrafted code will retain premium value.

    Yegor Bugayenkoyegor256.com5 min
  3. Constraint Decay: The Fragility of LLM Agents in Backend Code Generation

    A systematic evaluation of LLM agents generating multi‑file backend code shows a sharp drop in correctness when structural constraints (framework conventions, ORM usage, API contracts) are added. Across 100 tasks in 8 Python web frameworks, assertion pass rates fall ~27 points, with data‑layer bugs (bad queries, ORM violations) driving most failures. Mid‑size models cope with minimal frameworks (…

    arXiv cs.SE (Software Engineering)arxiv.org1 minpaperHN287197
  4. AI Agents Are Disrupting Open Source Security Disclosure

    AI agents can turn minimal public hints about software bugs into working exploits, rendering traditional embargoes ineffective. The article cites a study where a GPT‑4 agent exploited 87% of a 15‑vulnerability benchmark from CVE descriptions and discusses faster releases and revocable capabilities as mitigations.

    InfoQinfoq.com2 min
  5. Towards Self-Driving Codebases

    The post argues that AI agents could eventually handle low‑level engineering tasks—bug fixing, debugging, UI consistency, growth experiments—if the dev toolchain is made “agent‑legible”. It outlines missing primitives (global memory, code‑base rot prevention, better dev environments) and proposes a bootstrapping process to measure and improve a repo’s “agent readiness”. The piece is largely specu…

    Hacker News front pagedetail.dev9 minHN12099