惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
G
Google Developers Blog
B
Blog
Microsoft Azure Blog
Microsoft Azure Blog
博客园_首页
人人都是产品经理
人人都是产品经理
B
Blog RSS Feed
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
aimingoo的专栏
aimingoo的专栏
N
News and Events Feed by Topic
L
LINUX DO - 最新话题
V
Vulnerabilities – Threatpost
H
Hacker News: Front Page
T
Tor Project blog
P
Proofpoint News Feed
P
Privacy International News Feed
Recorded Future
Recorded Future
F
Fortinet All Blogs
量子位
博客园 - 聂微东
月光博客
月光博客
博客园 - Franky
SecWiki News
SecWiki News
G
GRAHAM CLULEY
腾讯CDC
Know Your Adversary
Know Your Adversary
宝玉的分享
宝玉的分享
The Cloudflare Blog
美团技术团队
小众软件
小众软件
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
T
Threatpost
爱范儿
爱范儿
A
Arctic Wolf
博客园 - 叶小钗
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Project Zero
Project Zero
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks
C
Cyber Attacks, Cyber Crime and Cyber Security
博客园 - 三生石上(FineUI控件)
PCI Perspectives
PCI Perspectives
Latest news
Latest news
V
V2EX
罗磊的独立博客
T
Threat Research - Cisco Blogs
Scott Helme
Scott Helme
S
Security Affairs
S
SegmentFault 最新的问题

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
We Have Code Review. We Need Intent Review.
huoru · 2026-05-07 · via DEV Community

We Have Code Review. We Need Intent Review.

Last month I watched Claude Code confidently rebuild a Redis queue that my team had abandoned three weeks earlier.

The repo had redis.go, TODOs scattered around, and redis configured in docker-compose.yml. Claude saw all of this and reasonably wanted to finish what looked like a half-built feature.

The problem: we'd already decided not to use Redis. Replication lag had been causing duplicate billing events, and the team made the call to rip it out. That decision lived in a Slack thread, a couple of PR comments, and the heads of three engineers.

Code search saw the Redis files. It couldn't see the decision.

This is a specific failure mode I keep running into, and the more I look at it, the more I think we're missing an entire layer of review in our AI-assisted workflows.

We have code review. We need intent review.

The Problem Isn't What the AI Wrote

Most discussions about AI coding focus on the output: did it produce good code? Was the architecture sound? Are the tests passing?

But the failure mode I'm describing is different. The agent isn't writing bad code. It's writing reasonable code based on the wrong historical premise.

Think about how a senior engineer behaves when they touch unfamiliar code. They don't just read the function signature and start typing. They:

  • Check the commit history to understand why it was written
  • Look for related PRs that touched this area
  • Ask the team in Slack: "anyone know why we did it this way?"
  • Pause before changing patterns that look intentional but unfamiliar

This isn't because senior engineers are smarter than AI agents. It's because they have humility toward unfamiliar code. They've been burned enough times to know that what looks like dead weight is sometimes load-bearing, and what looks like a half-built feature is sometimes an explicitly abandoned approach.

AI agents don't have this humility. They're optimized for agreement, not interrogation. If the code looks half-built, the agreeable thing to do is finish it. If a TODO looks reasonable, the agreeable thing is to address it. The agent extends rather than questions.

This works fine for greenfield code. It breaks badly in any codebase older than a few weeks.

Why Existing Solutions Don't Solve This

When I describe this problem, people usually point to existing tools. Each of these has a real role, but none of them fully addresses what I'm calling intent review.

AGENTS.md / CLAUDE.md — These work for the not-todos you can anticipate. You can write "don't use Redis" once you know Redis is dead. But what about the decision you'll make next week? Or the one your colleague made yesterday? AGENTS.md only covers the past you've already documented. New decisions don't write themselves into the file.

ADRs / RFCs — Heavy enough that most teams stop maintaining them after the first quarter. Even when maintained, they're written for human readers, not for agents querying contextually before a code change.

Wiki / Notion / Confluence — Documentation drifts from code. The wiki page from six months ago still says "we use Redis." Agents don't naturally query wikis the way they query code, and even if they did, they'd find a free-form page that doesn't structure decisions vs. risks vs. rejected alternatives.

PR descriptions — Buried in GitHub. Searchable in theory, ignored in practice. Agents don't proactively pull PR descriptions for related code regions.

Agent harnesses with built-in memory — Tools like jcode capture session memory automatically and inject it into future sessions. This works within the harness. But the moment you switch agents, change tools, or have a teammate who uses a different setup, the memory is gone. You're locked into the harness.

Each of these is a partial answer to a real problem. None of them gives an agent reliable, structured access to your team's actual historical decisions before it touches unfamiliar code.

Code Review vs. Intent Review

Code review answers: "Is this change well-implemented?"

Reviewers look at the diff. They check correctness, style, test coverage. They might catch a bug or suggest a better pattern. This is essential, and it works.

But code review is a poor place to ask: "Is this change well-conceived in light of what the team already decided?"

That question requires the reviewer to know the entire decision history of the codebase. To remember why a particular pattern exists. To recall that Redis was abandoned three weeks ago for replication reasons. Most reviewers don't have this context. Even the original author often doesn't, six months later.

Intent review is a different kind of review. It happens before code is written, not after. It asks:

  • What does the team already know about this area?
  • What decisions were made, and why?
  • What was considered and rejected, and for what reasons?
  • What risks were identified that haven't been mitigated yet?
  • What architectural claims are load-bearing?

For a human engineer, this kind of review happens informally—a quick Slack message, a glance at the commit log, a 30-second conversation with the person who wrote the original code.

For an AI agent, it doesn't happen at all. There's no equivalent to "let me ask the team." The agent reads the current state of the code and infers from there. The historical signal isn't accessible.

What Intent Review Looks Like

Intent review needs three properties to actually work:

1. Decisions need to be structured, not free-form.

A wiki page that says "we decided to use JWT" is fine for human reading. An agent needs to know: what was decided, what was rejected, why, what risks were identified, what files this touches, what subsystems it affects, what claims about the architecture were load-bearing.

Free-form prose hides this structure. An agent has to re-parse the entire document every time. Structured records let agents query specifically: "show me decisions affecting auth that mention session handling."

2. Decisions need to live near the code, not in a separate system.

Wiki pages drift from code. Notion pages get forgotten. Slack threads get buried. The only thing that reliably stays connected to code is git itself.

If decisions live in git, they survive everything that affects code: clones, forks, branches, time. Six months from now when the agent is touching this area, the decision is right there—same place as the code, fetched together, queryable in the same workflow.

3. The query must happen automatically, before the change.

If the agent has to be reminded "check the wiki first," it won't. If decisions live in a sidebar that requires explicit lookup, agents skip it. The query has to be part of the agent's normal workflow—the same way it grep's for symbol definitions before refactoring.

This is the hard part. An agent that already runs grep and read_file before editing should also run something like intent_context before editing. The friction of looking up decisions has to be lower than the friction of guessing.

What I'm Building

I've been working on this with a tool called Mainline. It records team intents and decisions as structured records in git itself, where any agent can query them before making changes.

Architecturally:

refs/heads/_mainline/actor/<id>   # per-developer append-only log
refs/notes/mainline/intents       # links between commits and intents

Enter fullscreen mode Exit fullscreen mode

Each sealed intent contains:

  • summary.what and summary.why
  • decisions[] with rationale and rejected alternatives
  • risks[] with mitigations
  • fingerprint covering touched files, subsystems, and architectural claims

Before an agent changes code, it runs something like mainline context auth and pulls structured records about past decisions affecting the auth area. After completing work, it seals a new intent with what was decided, what was considered, and what risks remain.

A few design choices that took me a while to settle on:

Process-based CLI, not a daemon. I considered a background daemon that would auto-capture activity. I looked at how that played out in similar tools (git-ai's daemon hits issues with macOS sleep, socket handling, zombie processes). Git itself is already a battle-tested protocol for this kind of thing. I didn't need to reinvent it.

Intent-level, not line-level. Line-level attribution (which file, which line, by whom) sounds appealing but is fragile. A formatter run, a git mv, a copy-paste, an --amend—any of these can break line-level tracking. Intent is task-level. Text transformations don't change the semantic meaning of "we decided X for reason Y."

Explicit seal, not automatic capture. Auto-capture sounds magical, but it produces a lot of noise: every keystroke and tool call gets recorded, and querying that later is harder than it looks. Explicit sealing has friction—the agent has to actively summarize what happened—but the resulting record is high-signal.

Append-only and immutable. Sealed intents can't be edited, only superseded. The original "what we thought at the time" stays intact. If we changed our minds, we add a new intent that supersedes the old one. The history of how thinking evolved is preserved, not overwritten.

The tool is open source (Apache 2.0) and currently in private beta. It's at mainline.sh if you want to look. I'm not pitching here—the point of this post is the idea, not the tool. If you build a different implementation of intent review that works better, I'd be genuinely interested in seeing it.

Where This Fits

There's a lot of energy right now in what people are calling compound engineering—the idea that each completed task should make the next one easier through accumulated learning. Tools like learning loops in Claude Code, the work Every is doing, the Ralph Loop pattern, all gesture at the same insight: AI coding workflows should accumulate knowledge instead of resetting every session.

I think compound engineering is heading the right direction, but it's missing a foundational layer. Most current implementations of "compound" rely on:

  • .claude/ files that humans maintain manually
  • Plain-text plans committed to the repo
  • Vector memory inside an agent harness
  • Retrospectives that update config files

These work, but they share a property: the knowledge is captured somewhere adjacent to git, not inside it. Switch tools, switch agents, switch teammates, and the compounding stops.

Intent review—done right—is the git-native foundation that compound engineering needs. If decisions live in git refs and notes, then any agent, any tool, any teammate can participate in the compounding. The knowledge isn't trapped in one harness.

What I'm Still Figuring Out

I've been dogfooding Mainline for about a month with a small team. Some things have surprised me.

The friction isn't where I expected. I thought engineers would resist writing structured seal records. They mostly didn't—it turns out the agent does the writing, and engineers just review and adjust. The actual friction is teaching agents when to seal. Too eager and you get a flood of trivial intents. Too conservative and important decisions go unrecorded.

The benefit shows up later than I expected. The first week, mainline feels like overhead. By week three, you start hitting moments where you ask "why did we do this?" and the answer is right there in the intent log. By week six, agents start using past intents as context without being asked. The compounding is real, but it's not immediate.

Cross-actor coordination is harder than single-user. When it's just me, sealed intents are mostly notes-to-self. When two engineers work in the same codebase, intents become a coordination protocol. We had to add explicit conflict detection (when two intents claim incompatible architectural changes) because otherwise we'd discover the conflict at PR review time, which is too late.

I don't think I've solved intent review. I think I've built one specific implementation of an idea that the field needs to develop further. Different teams will need different implementations. The structured-records-in-git approach is one path; others will work too.

What This Means for AI Coding

Code review is fundamental to software engineering. We don't ship code without review, even when the author is excellent. We don't trust raw output, even from senior engineers. We have a layer of structured human attention applied to every change.

AI agents are now writing significant fractions of new code in many teams. They're not getting reviewed less—if anything, the review burden is going up, because reviewing AI-generated code is often more cognitively demanding than reviewing human code. The reviewer can't ask the AI "why did you do it this way?" the same way they'd ask a colleague. The intent isn't legible.

Intent review isn't a replacement for code review. It's a complementary layer. Code review catches bugs in implementation. Intent review catches bugs in framing—the agent solving the wrong problem, finishing abandoned work, contradicting recent decisions, ignoring identified risks.

Without intent review, every code review has to do double duty: check the implementation and verify the framing. Most of the time, framing checks fail silently. The reviewer doesn't know that Redis was abandoned three weeks ago, or that this auth pattern was deliberately avoided, or that this risk was already identified and mitigated elsewhere. They approve the code, and the broken framing ships.

I don't think this is a problem we can solve with better prompts or larger context windows or more capable models. It's a structural problem about where institutional knowledge lives. Right now it lives in heads, Slack, and PR comments—places agents don't reliably look. We need it to live somewhere agents do reliably look. For most teams, that means git itself.

We have code review. We need intent review.

If you're seeing this same failure mode in your team, I'd be curious to hear how you're handling it—or whether you've decided it's not a real problem. Either is useful to know.


Mainline is at mainline.sh. Source on GitHub. Apache 2.0. Currently in private beta with a small group. If you have a 5+ person team using AI coding heavily and want to try it, reach out.