Kind of have an urge now to post an issue that the nstall skill has installed a malware on my machine.
It's pretty plausible that could happen, and good luck debugging that.
Welcome to Programmer Humor!
This is a place where you can post jokes, memes, humor, etc. related to programming!
For sharing awful code theres also Programming Horror.
Kind of have an urge now to post an issue that the nstall skill has installed a malware on my machine.
It's pretty plausible that could happen, and good luck debugging that.
Vibestrapping
it used to mean something better... 😔
Something less degenerated
You may as well just completely replace your package manager with this one simple script.
#!/usr/bin/env python3
import sys
exec(TrustedAgent.request(f"Write a Python statement to install {sys.argv[1]}, make no mistakes"))
I mean, you could do away with package managers altogether... Just always include "use standard library components only" in every prompt.
Added bonus, your program will be very secure because it would very rarely be affected by any publicly known CVEs.
/s
Also "Please don't reformat my hard drive"
"Try to keep out the worst malware'd packages"
How am I still learning about XKCDs I've never seen especially ones in the 1000 range.
if $1 is not installed after that, wipe your hard drive and start over
They saw curl | bash and were like you know what the problem with this is? It's deterministic
While I'm not a fan of most AI usages, this is the thing that infuriates me the most.
I like writing scripts to automate parts of my job. I've had a few for things like build performance testing comparison and the like.
All of it was replaced by skill.md, that does exactly the same, but burns like 3$ per run in tokens, and has also at least once generated hallucinated results, because it ran into an error, ran wrong builds, or in general fucked up in a way that was not easy to detect (and we did in fact not detect it until much later).
But hey, at least my colleagues now don't have to open the filthy commandline and write py perf-test.py main feature/branch to run the test, and can just talk about it to a clanker.
This needs to be killed with fire.
We can do even better: just post the readme+prompts used to design the software, and let the users AI agent recode it themselves! Perfectly secure.
This kind of does something similar :D https://codeberg.org/TheMikina/git-llmfs
"How the fuck did Doom get installed onto my smoke alarm and not my D: drive? This is the last time I ask AI to help."
Imagine:
Is this satire or is it from a real project O_O?
This is... uh...
It reads like the author doesn't know what containers are. Because this is actually a great use case for containers unless I'm missing something.
Now, do I want reverse engineering software from someone who in 2026 doesn't know of a better way to manage dependencies than "tell AI to install everything"? Not particularly lol
Also:
Install Eclipse Adoptium 21: https://adoptium.net/temurin/releases/?version=21
It's Eclipse Temurin not Eclipse Adoptium. And why not install from distro repo?
Install from https://cmake.org/download/
Also why not from distro repo?
Install Visual Studio 2022, or apt install build-essential / xcode-select --install
NOW distro repo is fine, but only if you use an APT based distro?
and then 3 more dependencies it tells the agent to install from websites.
The weirdest thing is you can get much better results from AI. I'm 99% sure this person gave the AI particularly bad instructions to generate the install instructions, or used a cheap, crappy model.
It is a self-contained runbook with explicit verification gates at every step — preflight checks, building libghidra, installing the LibGhidraHost Ghidra extension, building ghidrasql, and a first live query. Hand it to your agent and let it drive the install; intervene only if a gate reports a failure.
Even the install instructions are written by AI. Good grief
Look what they have to do to mimic a fraction of tar -xaf!
You may not, without prior written permission from the Author...create an API-compatible replacement, behavioral clone, competing implementation, or Derivative Implementation
Loooooooooooooool. "You're not allowed to reverse-engineer this reverse-engineering tool."
I think the reverses would cancel each other out making this simply an engineering tool
This is absolutely insane
What the actual fuck. Sorry, I won't have better words for quite a while now
Completely vibe-coded project it seems, even documentation. And yet:
Human-Origin Source License
Also love this:
You may not, without prior written permission from the Author:
- ship or maintain a modified version outside the contribution-purpose
rules;
- maintain a divergent private or internal fork;
- port, clone, rebrand, or recreate the Covered Software;
- create an API-compatible replacement, behavioral clone, competing
implementation, or Derivative Implementation; or
- use AI-assisted implementation mining to create, improve, test,
document, or validate a Derivative Implementation.
Look, I use AI too (mostly to speed things up by working on multiple items in parallel), but I'm not gonna stuff "human-origin source license" on anything I use it for, nor do I think creating API-compatible replacements, competing implementations, etc, should reasonably be possible to block with a license... Also, quite literally, he's creating tools for reverse engineering, which in itself is generally in breach of the license of whatever software is being reverse engineered. Fuck off and use a FOSS license, whether it be permissive or copyleft...
"No! Nuh uh! You can't prompt Claude to do what it did for me, again! I did it first and called 'dibs' on ever doing it again!"
As if copyright even applied to this.
Non-deterministic, heavily corporation-influenced software issuing root shell commands in a scenario easily foreseen by attackers who can just make spam pages to poison training data? I'll have two!
Unfortunately not the first time I've seen this sort of thing:
(I don't use this project, just came across it)
I'll give it a pass because it's an OpenCode plugin, meaning the typical user is not tech-savvy enough to be able to edit a simple JSON configuration file.
But surely it also means the plugin fully slopcoded and the maintainer has no idea what they are doing if they are incapable a writing instructions
The Circle of Slop
If you trust the site, curl | sh is no worse than any other install method. If you don't trust the site, it's also no worse.