#CodeMode
FASTMCP: FASTMCP V4.0.10 FIXES TASK-ENABLED TOOLS BEHIND SEARCH TRANSFORMS AND CODEMODE
September 28, 2026 at 1:45 AM
more codemode fun, doing a large mysql operation and the agent wanted to do it 50K rows at a time

it writes a single codemode script which runs it in a loop

and then you visualize it step by step even though it's code
September 18, 2026 at 1:03 AM
I agree in theory, in practice I've just found codemode like implementations less useful than I thought it would be. Need to think more on why.
September 16, 2026 at 5:20 AM
CVE-2026-57138 - praisonai
Versions 1.4.0 through 1.7.1 of PraisonAI allow code entered into the codeMode feature to break out of its sandbox and run arbitrary commands on the server. An…

Too many irrelevant or confusing CVEs? Use stackflag.com

#praisonai #mervinpraison #npm #CVE #infosec
CVE-2026-57138: PraisonAI 1.4‑0‑1.7‑2 lets code tamper with host
Versions of PraisonAI from 1.4.0 through 1.7.1 run user‑provided JavaScript in a weak isolation that can be bypassed.
stackflag.com
September 16, 2026 at 4:50 AM
CVE-2026-57141 - praisonai
Versions of PraisonAI before 1.7.2 let a user who can influence the codeMode tool run their own JavaScript, which can break out of the sandbox and access the server.…

Too many irrelevant or confusing CVEs? Use stackflag.com

#praisonai #mervinpraison #npm #CVE #infosec
CVE-2026-57141: PraisonAI before 1.7.2 lets attacker run system commands
Versions of PraisonAI prior to 1.7.2 run user‑supplied JavaScript in a way that can be bypassed, giving an attacker the ability to execute.
stackflag.com
September 16, 2026 at 4:50 AM
🚨 CVE-2026-57141 — CVSS 9.8 CRITICAL

PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/bu...

🔎 https://stemshop.top/cve/CVE-2026-57141

#CVE #CyberSecurity #InfoSec
September 15, 2026 at 12:08 PM
🚨 CVE-2026-57138 — CVSS 9.9 CRITICAL

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/bui...

🔎 https://stemshop.top/cve/CVE-2026-57138

#CVE #CyberSecurity #InfoSec
September 15, 2026 at 12:08 PM
now that we have codemode you can add as many MCPs as you want without cost

i still don't add a ton up front but occasionally i'll come across another good use case

and over time my agent gets more and more capable - esp with project specific ones
September 11, 2026 at 6:42 PM
fiend - build 3D stuff with your agent in the browser

connect the mcp server, ask your agent to make a new scene and get a link. you can point out areas for feedback and prompt it further

works beautifully with opencode2's codemode
September 9, 2026 at 3:30 AM
get my DIY/nights-and-weekends AI lab functional enough to start producing meaningful R&D

(initial side-quests: golden-gate-gemma-J-space, virtual tools + git-ified codemode, RegimeBenchmaxxing via RLAIF, Lean-4-fun-and-profit, SOTA full-press AI Diplomacy, CUDA-specialist SLMs)
September 6, 2026 at 8:03 PM
still, in opencode2 we implemented codemode in a way that allows us to render decent ui and still prompt for permissions even when the model is just lobbing over a hunk of code

but if astra really wants to write raw python, should we even be fighting that and making it use our own thing? 2/3
September 6, 2026 at 3:36 PM
What IS codemode?
August 26, 2026 at 1:37 PM
our anti fraud system gets access to honeycomb, stripe, and database to correlates things and find very obvious fraud

the models are incredible at doing this via codemode. the whole script didn't even fit in the screenshot

composing these tools together to get what it needs
August 26, 2026 at 1:30 PM
Still think we should deprecate MCP. It was built around the idea of tool calls, which turned out to be a mistake IMHO. And codemode is a limited hack.

Models mostly output Bash scripts anyway and they should probably *only* output Bash scripts.

Structured output can be produced from bash scripts.
thdxr.com dax @thdxr.com · Aug 26
i complained a lot about the mcp spec in the past
but it's getting very good now
August 26, 2026 at 1:56 AM
codemode is so good man it just did a giant analysis to answer a question i had in one go

this is pretty much a non-negotiable thing at this point
August 25, 2026 at 9:51 PM
Have you tested codemode with small/local models, or does it realistically only work with big cloud models?

And what's your thoughts on safety/permissions, visibility of what's being executed, etc? - would probably be horrible trying to handle step permissions and interim results?
August 8, 2026 at 5:33 AM
opencode2 has tool search and codemode built in

this means it can handle infinite mcps, custom tools, apis, etc

and it's the simplest implementation we've seen
August 7, 2026 at 11:10 PM
**The cheapest token is the one you never send.**

Most AI agents keep sending the same context back to the LLM.

CodeMode keeps execution inside a **Code Sandbox**, sending only what's needed for the next decision.

Fewer tokens. Lower cost. Faster agents.

datalayer.ai/guide

#AI #AIAgents #LLM
Datalayer ☰ AI Agents for Data Analysis
Datalayer ☰ AI Agents for Data Analysis
datalayer.ai
July 31, 2026 at 3:29 PM
Proxy #MCP servers via @cloudflare.social #AI Controls. Instead of loading every tool into context, #CodeMode turns an agent's tool into an #API. #Agent chain & filter across dozens of tools in one pass, without a round-trip to model for every call. Cut #token #costs by ~93%
#LLM #Agents
Cloudflare Dashboard | Manage Your Account
Log in to the Cloudflare dashboard. Make your websites, apps, and networks fast and secure. Build modern apps on our developer platform.
dash.cloudflare.com
July 24, 2026 at 12:25 AM
if mcp servers implement their own codemode
and then your agent native supports codemode
now everything is going through an extra useless layer

if you insist on doing this plz provide a more raw mcp endpoint
July 20, 2026 at 1:27 AM
🧠 Context engineering > prompt engineering.

We compare CodeMode vs no CodeMode with reproducible GitHub Actions workflows. Less context → fewer tokens → lower cost.

🎥 Demo: www.loom.com/share/1edbbe...

Report deep dive next.
Datalayer ☰ AI Agents for Data Analysis - 17 July 2026
Use Loom to record quick videos of your screen and cam. Explain anything clearly and easily – and skip the meeting. An essential tool for hybrid workplaces.
www.loom.com
July 17, 2026 at 5:14 PM
Cuando un agente de IA puede ejecutar código, la promesa de sandbox no vale nada si el aislamiento real se puede romper...
laautopsia.com/vulnerabilid...
June 20, 2026 at 11:04 AM
i think it’s still underrated for a few reasons:
- many people don’t what the point of DSLs are
- codemode/full computer use is the current meta and north star
- most people read the bitter lesson to mean “let the model figure out everything from scratch”
- designing DSLs is hard
June 15, 2026 at 9:18 AM
my kingdom for a wasm codemode harness with a granular permission model + memgpt
June 3, 2026 at 12:03 AM
This tweet appeared under this Techmeme headline:

Tobi Lutke / @tobi:

@dexhorthy @walden_yan @karpathy There is so much alpha still left in harness engineering. That's exactly what we saw with /autoresearch. Codemode DSL for orchestration is brilliant. Great work by the claude team.
May 29, 2026 at 1:47 AM