# blog.bokvi.com > A technical blog about AI software development, tools, > and practical guides for developers building with AI. ## Blog Posts - [Cloudflare's cf CLI: The Whole API, and a Clock on Wrangler](https://blog.bokvi.com/blog/cloudflare-cf-cli/index.md): Cloudflare launched cf on September 28, 2026: an open-beta CLI generated from its OpenAPI schema by the newly open-sourced Forge pipeline, covering about 3,000 API operations against Wrangler's roughly 280. It prints JSON by default, finds commands with a local cf cli search, configures Workers in a TypeScript cloudflare.config.ts and builds through Vite by default. When the beta ends, Cloudflare will ship a final major Wrangler release that points users to cf, then maintain Wrangler for 18 more months. Running cf migrate on this Astro static blog produced the new config files, but cf build then failed, so the blog stays on Wrangler for now. - [WebMCP Hands-On: A Search Tool for Browser Agents](https://blog.bokvi.com/blog/webmcp-hands-on/index.md): WebMCP lets a web page register typed tools for browser agents through document.modelContext. Chrome runs it as an origin trial from Chrome 149 to 156 and targets shipping in 157. I added a read-only search_posts tool to this blog, and Playwright MCP v0.0.82 exposed it to MCP clients as webmcp_search_posts without any glue code. WebKit opposes the API and Mozilla rates it neutral. - [Orca: The Open-Source ADE for Running Coding Agents in Parallel](https://blog.bokvi.com/blog/orca-ade-parallel-coding-agents/index.md): Orca is a free, MIT-licensed desktop app from Stably AI that runs Claude Code, Codex, Cursor CLI and about 40 other CLI agents side by side, each in its own git worktree. Its first commit landed on March 17, 2026; by September 23 the repository had 76,000 GitHub stars, 11,600 commits and 18 desktop releases in a month. Standout features are Design Mode, line-anchored diff comments sent back to the agent, per-line AI attribution, SSH and self-hosted remote runtimes, a scriptable CLI, and iOS and Android companions. Conductor is Mac-only and paid above its free tier, Superset skips Windows and uses a source-available licence, and the vendors' own apps run only their own agent. - [Grok 4.7, Opus 5.5, GPT-6 Sol and Luna: Four Models in Two Days](https://blog.bokvi.com/blog/grok-4-7-opus-5-5-gpt-6-sol-luna/index.md): xAI released Grok 4.7 on September 21, 2026 at an unchanged $2/$6 per million tokens. On September 22 Anthropic shipped Claude Opus 5.5 at $4/$20, 20% below Opus 5, and about 90 minutes later OpenAI released GPT-6 Sol ($2/$10) and GPT-6 Luna ($0.10/$0.50). xAI's headline table skips GPT-6 Astra, some OpenAI charts use older or lower-effort Anthropic models, and Anthropic's announcement leaves out results Astra wins. Artificial Analysis found that heavy token use cancels much of the per-token savings for Grok 4.7 and Opus 5.5 at their highest effort settings. - [Herdr: A Practical Guide to Running Coding Agents](https://blog.bokvi.com/blog/herdr-guide/index.md): Herdr gives coding agents persistent terminal workspaces and visible activity states. This guide covers installation, everyday controls, Git worktrees, scripted reviews, SSH, and the limits of detection and session restore. - [GPT-6 Astra vs ARC-AGI-3: One Model, Two Very Different Scores](https://blog.bokvi.com/blog/gpt-6-astra-arc-agi-3/index.md): On 3 September 2026 the ARC Prize Foundation reported that OpenAI's GPT-6 Astra scores 62.7% on ARC-AGI-3 under its standard, provider-neutral harness, and 99.9% when OpenAI's own reasoning-retention and compaction features are switched on. Both are records: the previous best was Claude Opus 5 at 30.2%, and the benchmark launched in March at 0.51%. In the high-scoring configuration Astra used fewer actions than the median human on 96% of levels. ARC Prize calls it a step-function change and says, in the same post, that it is not claiming AGI. The two numbers measure two different questions, and which one you quote says a lot about what you think a benchmark is for. - [LZ Caught One Event It Can't Explain. Is It Dark Matter?](https://blog.bokvi.com/blog/lux-zeplin-dark-matter-signal/index.md): On 16 June 2023 the LUX-ZEPLIN (LZ) dark matter detector recorded a single nuclear recoil of about 248 keV in a region where its background model predicts roughly 0.01 events. Announced on 1 September 2026, the result has a global significance of 2.6 sigma, meaning roughly a 1-in-200 chance that background alone would produce something this extreme, far short of the 5-sigma discovery bar. If it is dark matter, the particle is heavier and interacts more strangely than the textbook WIMP. The collaboration is explicit that it is not claiming a discovery, and roughly three times more data already sits unanalysed. - [Claude Fable 5.1: One Model, Two Names, Three Breaking Changes](https://blog.bokvi.com/blog/claude-fable-5-1/index.md): Claude Fable 5.1 (released September 1, 2026) is the same weights as the trusted-access-only Mythos 5.1, plus safety classifiers that can hand your request to Opus mid-flight. Per-token price is unchanged at $10/$50 per million, but cache reads drop 75% to $0.25. It leads Opus 5 and GPT-5.6 Sol on Anthropic's table and on Artificial Analysis, while costing more per task at max effort. Three API changes break existing code: forced tool_choice returns a 400, thinking blocks are bound to the producing model, and editing earlier turns invalidates later thinking for new accounts. - [Dyson CameraJet: A £420 Toothbrush With Computer Vision](https://blog.bokvi.com/blog/dyson-camerajet-toothbrush/index.md): Dyson's first toothbrush, the £419.99 CameraJet (launched 1 September 2026), uses a 100,000-pixel camera and an ML model trained on 470,000 dental images to detect interdental gaps and fire mouthwash jets at them within 100ms — the first mainstream appliance to close the sense-decide-actuate loop in your mouth. - [MCP Grows Up: What's Changing in the 2026-07-28 Spec](https://blog.bokvi.com/blog/mcp-2026-07-28-spec/index.md): The MCP 2026-07-28 spec — final on July 28 — removes the initialize handshake and protocol-level sessions, making every request self-contained and MCP servers trivially load-balanceable. Extensions become a formal mechanism (MCP Apps, Tasks), OAuth gets six hardening SEPs, tool schemas get full JSON Schema 2020-12, and Roots, Sampling, and Logging enter a twelve-month deprecation window. - [Zig in 2026: Colorless Async I/O and the Road to 1.0](https://blog.bokvi.com/blog/zig-in-2026/index.md): Zig 0.16.0 (April 2026) introduces std.Io, an interface that makes async explicit and colorless by passing I/O as a parameter, just like allocators. Combined with self-hosted backends and incremental compilation, Zig is faster and more coherent than ever — but 1.0 is deliberately not here yet. - [Inside Claude Code's Dynamic Workflows](https://blog.bokvi.com/blog/claude-code-dynamic-workflows/index.md): Dynamic workflows let Claude Code write a deterministic JavaScript script that orchestrates dozens to hundreds of subagents — fan out, adversarially verify, synthesize — for tasks too big for a single agent. Research preview, launched May 28, 2026 alongside Claude Opus 4.8. Powerful, and token-hungry by design. - [HTTP/2 Bomb: Remote Memory-Exhaustion DoS (CVE-2026-49975)](https://blog.bokvi.com/blog/cve-2026-49975-http2-bomb/index.md): A single HTTP/2 connection from a home laptop can pin tens of gigabytes of server RAM in seconds. How the AI-discovered HTTP/2 Bomb works and how to defend. - [CVE-2026-44578: Next.js WebSocket SSRF](https://blog.bokvi.com/blog/cve-2026-44578-nextjs-websocket-ssrf/index.md): High-severity (CVSS 8.6) SSRF in the Next.js WebSocket upgrade handler lets unauthenticated attackers proxy GETs to internal services on port 80. - [TanStack npm Supply Chain Attack: Detect, Fix, and Recover](https://blog.bokvi.com/blog/tanstack-npm-supply-chain-attack/index.md): On May 11, 2026, attackers published 84 malicious versions across 42 @tanstack/* npm packages. Here is how to detect compromise and recover safely. - [LiteLLM Supply Chain Attack: How to Check If You're Affected](https://blog.bokvi.com/blog/litellm-supply-chain-attack/index.md): Malicious LiteLLM versions were published to PyPI on March 24, 2026. Here's what happened, how to check if you're affected, and what to do. - [Getting Started with AI-Assisted Development](https://blog.bokvi.com/blog/getting-started-ai-assisted-development/index.md): AI coding tools work best when you treat them as collaborators, not replacements. - [The Next Generation of Developer Tools](https://blog.bokvi.com/blog/future-of-dev-tools/index.md): The next wave of developer tools moves from code completion to autonomous task execution — AI agents that understand your codebase, plan implementations, and execute multi-file changes. - [Engineering Responsible AI Systems](https://blog.bokvi.com/blog/ai-ethics-engineering/index.md): Responsible AI engineering means building measurable guardrails — input validation, output filtering, bias monitoring, and human escalation paths — not just writing policy documents. - [Fine-Tuning Models for Your Domain](https://blog.bokvi.com/blog/fine-tuning-guide/index.md): Fine-tune when you need to change model behavior, not just knowledge. Use LoRA for parameter-efficient training with as few as 100-500 high-quality examples. - [Designing AI Agent Architectures](https://blog.bokvi.com/blog/ai-agents-architecture/index.md): Effective AI agents use a loop of observe-think-act with explicit tool definitions, structured memory, and guardrails that prevent unbounded execution. - [Running AI Models Locally: A Complete Guide](https://blog.bokvi.com/blog/local-ai-models/index.md): Run production-quality AI models locally using Ollama for simple deployment or llama.cpp for maximum control — quantized models make this feasible on consumer hardware. - [AI-Powered Testing: Beyond Unit Tests](https://blog.bokvi.com/blog/ai-testing-strategies/index.md): AI testing tools generate edge cases humans miss, create property-based tests from type signatures, and use intelligent fuzzing to find bugs before production. - [Building RAG Systems from Scratch](https://blog.bokvi.com/blog/rag-from-scratch/index.md): RAG combines document retrieval with language model generation — embed your documents, store vectors, search by similarity, and feed relevant context into the prompt. - [Automated Code Review with AI](https://blog.bokvi.com/blog/ai-code-review/index.md): AI code review catches pattern-level issues that linters miss — security vulnerabilities, performance antipatterns, and logic errors — and integrates directly into your pull request workflow. - [The Developer's Guide to Prompt Engineering](https://blog.bokvi.com/blog/prompt-engineering-guide/index.md): Effective prompts use structured formats, explicit constraints, and few-shot examples to produce consistent, reliable AI outputs in production systems. - [How Large Language Models Actually Work](https://blog.bokvi.com/blog/understanding-llms/index.md): LLMs use transformer architecture with self-attention to process token sequences in parallel, enabling them to learn complex language patterns from massive datasets. ## About - [About](https://blog.bokvi.com/about/): Author background and blog mission.