惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
S
Secure Thoughts
S
Schneier on Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Cyberwarzone
Cyberwarzone
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Privacy International News Feed
L
Lohrmann on Cybersecurity
Schneier on Security
Schneier on Security
PCI Perspectives
PCI Perspectives
Google DeepMind News
Google DeepMind News
C
Cybersecurity and Infrastructure Security Agency CISA
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Latest news
Latest news
H
Hacker News: Front Page
月光博客
月光博客
Forbes - Security
Forbes - Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
S
Security @ Cisco Blogs
WordPress大学
WordPress大学
Recent Commits to openclaw:main
Recent Commits to openclaw:main
aimingoo的专栏
aimingoo的专栏
宝玉的分享
宝玉的分享
D
Docker
U
Unit 42
Recorded Future
Recorded Future
Spread Privacy
Spread Privacy
Microsoft Security Blog
Microsoft Security Blog
Recent Announcements
Recent Announcements
云风的 BLOG
云风的 BLOG
Application and Cybersecurity Blog
Application and Cybersecurity Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Heimdal Security Blog
Microsoft Azure Blog
Microsoft Azure Blog
V
Vulnerabilities – Threatpost
Vercel News
Vercel News
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
爱范儿
爱范儿
博客园 - 聂微东
Hugging Face - Blog
Hugging Face - Blog
L
LangChain Blog
G
GRAHAM CLULEY
Apple Machine Learning Research
Apple Machine Learning Research
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Blog — PlanetScale
Blog — PlanetScale
博客园 - 三生石上(FineUI控件)
罗磊的独立博客
Help Net Security
Help Net Security
Google Online Security Blog
Google Online Security Blog
S
SegmentFault 最新的问题

Stack Overflow Blog

Paging Charity! How can engineering leaders avoid becoming Bond villains? Code isn’t the only thing causing your production failures Your AI shipped a backend that boots. That is the whole problem. The 2026 Developer Survey is now open (for human developers only)! Oh the places you’ll go with spatial data Dispatches from O'Reilly: From capabilities to responsibilities You don’t understand DNS like you think you do The new bottleneck - Stack Overflow AI agents are a confused deputy with the keys to your kingdom If context is king, architecture is the castle Selenium vs Cypress vs Playwright: Choosing Your Test Automation Framework AI agents expose the security checks you never actually wrote Designing CherryScript: Optimizing Data-Driven Workflows via Custom Python-Based Interpreters Paging Charity? How do I get my leaders to stop running teams Into the ground? Developers are emotionally attached to their tools When the cost of code approaches zero, what does engineering leadership look like? Announcing Stack Overflow for Agents Creating checkpoints by gaslighting a Postgres database What can 500 years of journalism teach developers about AI trustworthiness? Making the OWASP top ten in the vibe code era What it takes to be a player in the international AI game Best of the Heap: First post of the past The find out stage of AI is just supply chain and password protection In an AI world, the most valuable developers will be both artisans and builders Agents on a leash: Agentic AI remains mostly single-agent and monitored at work Do you have what it takes to run AI in production? Dispatches from O'Reilly: The accidental orchestrator Breaking your AI storage bottlenecks Coding agents are giving everyone decision fatigue Pack your agentic stack in Slack Your fridge could be a threat to national security Interviews aren’t about you (sorry) “You can't vibe code scale”: What the AI hype gets wrong about software engineering No Dumb Questions: What is cloud computing and why is everyone doing it? Observability and human intuition in an AI world How Braze’s CTO is rethinking engineering for the agentic area You shipped it fast. But did you ship it right? Building a Google Drive Sync Engine that Survives MV3 Service Workers Connecting the dots for accurate AI When the Sensor Starts Thinking: SnortML, Agentic AI, and the Evolving Architecture of Intrusion Detection OAuth 2.0 – Device flow explained for Engineers, especially for Backend Engineers Introducing the Heap, the software engineering blog for everyone Compile-Time Map and Compile-Time Mutable Variable with C++26 Reflection No Dumb Questions: What is an MCP server and why do I care? AI giveth and AI taketh CPU How we replaced Ingress-NGINX at Stack Overflow What (un)exactly do you mean by semantic search? Dispatches from O'Reilly: Fast paths and slow paths Time is a construct but it can still break your software The Worst Coder in the World goes agentic: building a leaderboard cracking AI Turning scattered knowledge into trusted intelligence: Stack Internal 2026.3 Your LLM issues are really data issues Welcome to the “find out” stage of AI Lights, camera, open source! - Stack Overflow Black box AI drift: AI tools are making design decisions nobody asked for How to get multiple agents to play nice at scale We still need developer communities No country left behind with sovereign AI Human input needed: take our survey on AI agents Why AI hasn't replaced human expertise—and what that means for your SaaS stack Who needs VCs when you have friends like these? The messy truth of your AI strategies Gen Z needs a knowledge base (and so do you) He designed C++ to solve your code problems Seizing the means of messenger production What the AI trust gap means for enterprise SaaS How can you test your code when you don’t know what’s in it? Prevent agentic identity theft - Stack Overflow Multi-stage attacks are the Final Fantasy bosses of security After all the hype, was 2025 really the year of AI agents? AI is becoming a second brain at the expense of your first one Building a global engineering team (plus AI agents) with Netlify Keeping the lights on for open source Domain expertise still wanted: the latest trends in AI-assisted knowledge for developers Open source for awkward robots The context problem: Why enterprise AI needs more than foundation models Even the chip makers are making LLMs Organizing productive platform teams - Stack Overflow Building brains for bulldozers - Stack Overflow DeveloperWeek 2026: Making AI tools that are actually good AI-assisted coding needs more than vibes; it needs containers and sandboxes No need for Ctrl+C when you have MCP What’s new at Stack Overflow: March 2026 To live in an AI world, knowing is half the battle Beyond block or allow: How pay-per-crawl is reshaping public data monetization Your sneak peek at the redesigned Stack Overflow Dogfood so nutritious it’s building the future of SDLCs Defense against uploads: Q&A with OSS file scanner, pompelmi Even GenAI uses Wikipedia as a source Why Stack Overflow and Cloudflare launched a pay-per-crawl model Mind the gap: Closing the AI trust gap for developers Data is the new oil, and your database is the only way to extract it Even your voice is a data problem How everyone and anyone can use AI for good Is anyone using AI for good? The logos, ethos, and pathos of your LLMs Why demand for code is infinite: How AI creates more developer jobs AI attention span so good it shouldn’t be legal Code smells for AI agents: Q&A with Eno Reyes of Factory Generating text with diffusion (and ROI with LLMs)
Building shared coding guidelines for AI (and people too)
2026-03-26 · via Stack Overflow Blog

As engineering organizations grow, getting everyone to work on the same software starts to get unwieldy. Everybody has their own quirks and styles, which can lead to a Tower of Babel implemented as a service-oriented architecture. So leadership folks came up with ticketing systems, scrum, and deployment pipelines to bring some consistency to the process. For the code itself, they wrote coding standards and guidelines.

In 2026, software engineers are writing less and less code by hand. Instead, they use coding agents to write code based on their designs. But if those agents contribute to an enterprise code base, then they need to follow the standards and guidelines. Fortunately, most of the code generators have implemented ways to add standards and guidelines to your agents.

The catch is that it’s not the same as onboarding a new junior developer. You can’t just throw a few documents at them and let them explore. Agents are fast but lack the context of your code. And a lot of the context for human coders comes as tacit learnings as they see particular forms, styles, and patterns. We call red flags in code “smells,” which speaks to the vibe-based nature of a lot of code understanding. Despite popular discourse, coding agents don’t run on vibes, at least not in professional situations.

As coding agents create more and more code, the cognitive burden of software engineering is shifting to design and architecture as well as code review. Code review will be most engineers’ first look at the code since they didn’t write it themselves. They just know what they wanted the code to do. Coding guidelines for agents can inject a bit of determinism into a non-deterministic process.

Coding guidelines and standards (which I’ll just call “guidelines”) for agents need to be a little different—more explicit, demonstrative of patterns, and obvious. But not super different, as good documentation is for all coding entities.

Here’s how to best create coding standards for agents and humans.

The code that agents produce needs to work with a bunch of code that’s already in production (unless you live a blessed life building a purely greenfield project). It needs to use the same languages and libraries, hook into any build and deployment systems, and fit with the platform engineering systems and paradigms you use. If your front end uses Express, your agent shouldn’t code with React.

Beyond the tech stack, your engineering team has a set of methodologies and best practices they use to write code for a shared codebase. Some of these may be universal best practices, some may be team culture, and some may be the ways that your team deviates from or ignores best practices. While this may be assumed common knowledge with your human teammates, take nothing for granted with agents. “What are the prompts that you need to give it, like DRY?” said Vish Abrams, chief architect at Heroku. “There's classic programming principles that to seasoned engineers are common knowledge. The same thing is true about deployment. You want to build your application where configuration and code are separate. You can tell the LLM to build your application that way, or you can just say, build me a snake game and it'll do whatever it wants to. Maybe it’s not maintainable at all.”

This might be the time to revisit your coding guidelines altogether. Many of the best practices were created when code was artisanal and hand-written. If you’re only engaging with the code during review, maybe some guidelines change. Maybe having multiple copies of functionality is better for code review, so you see the functionality with the PR. Maybe not. But many of the best practices serve to make code readable and maintainable for humans.

Coding, like writing, has a lot of little decisions that can vary across organizations. For outsiders, they may seem small and arbitrary, but they can have downstream impacts and slow down reviews for colleagues used to certain conventions. We use the serial comma here on the Stack Overflow blog, but others don’t and are wrong.

Like a style guide, your agentic coding guidelines should indicate the decisions your team has made about which language constructs to use and why. Here are a few decisions to consider including:

  • Variable and method naming: Naming things is one of the hard problems of software engineering. Do you want your agents running wild and creating `FactoryBuilderBuilderFactory` or mixing camelCase and underscore_style? If you have differences in styles within a codebase, say between C++ and SQL code, then indicate them separately. Indicate how to identify and resolve duplicate names.
  • Tabs vs. spaces: If your team has an opinion on the tabs vs. spaces debate, let the agent know. Some IDEs and languages may make this debate moot; make sure your agent knows the score regardless.
  • Layout: Some programming languages like Python require specific indentation and formatting, while others (particularly the curly brace kinds) allow freer placement. You might have particular feelings about layout for these things, and research suggests that layout can affect the speed of comprehension.
  • Exceptions and logging: Your code needs to fail well, and agents need to know how you expect failures and collect data on software in production. It would be great if all this could happen automatically, but most of the time, it requires code within the software to do the job right. Might as well have the agent write that for you as well.
  • Comments: Agents can write comments, but should they do it before or after a method? Do they follow indent rules? Are you using an API documentation generator? How much detail do you want? This is something that human coders could probably guess at, but the agents need guidance.

This is not a comprehensive list of guidelines for coding agents, and you’ll likely find more annoying quirks your agent uses along the way. See below for dealing with that.

I know this is meant to be a guide for agentic coding guidelines, but ultimately good documentation is the same whether it’s for people or agents. In fact, many of the qualities below are more important for agents because they are much more unpredictable.

The guidelines should be clear and consistent. It should be dead obvious how to follow any guidelines that you write. Test your guidelines by approaching them in the most bad faith manner as possible; if you can find a way to misinterpret it, rewrite it. Write in a simple, repeated style throughout the document—you don’t have to be perfect, just predictable. AI loves patterns.

Don’t confuse the AI. When I wrote documentation, I assumed the reader could have a wide range of English skills. They could be a non-native speaker. That means not using idiomatic language or other constructs that require interpretation. Be simple, explicit, and boring. The same goes for code examples. Cover all edge cases so there are no decisions for the AI to make.

Make your decisions obvious. Engineers build conventions tacitly. “We take for granted as engineers that when you're writing code and you spend a whole evening and you're writing a bunch of new functions, you're also implicitly absorbing the context of the code base,” said Greg Foster, CTO of Graphite. Any guideline needs to take this tacit knowledge and make it explicit. Provide objective reasons for each guideline. Some guidelines might be inherited from standard conventions (“We use tabs because we’re primarily a Python shop and this makes indentation more consistent”).

I resisted examples in documentation at first. But once I had to use documentation to solve a problem, boy did I get it. Screenshots, sample code, API playgrounds, all these showed me how to use tools better than a numbered list of steps alone. There’s a reason that we jokingly offered a CTRL+C+V keyboard (and then not so jokingly): that sample code gives you a template you can use to customize your own code. And AIs love a good template.

Provide explicit examples of both correct and incorrect implementations of the code guidelines. AIs can use these as patterns to determine what the correct code looks like in most given situations. Multiple examples for each won’t hurt, but again, ensure that your examples are consistent.

Consider also giving the agents an overall example of what code looks like when it follows all guidelines—a “gold standard” file. Individual examples are like unit tests: your gold standard is the end-to-end test. There’s some discussion on whether you only need the gold standard file, or whether it can work in concert with individual examples. We suggest testing to see which gets the best results.

If you’ve worked with agents enough, you probably know already that you’re not gonna get this in one. Your first version of the coding guidelines isn’t going to deliver perfectly formed agentic code. That’s okay; those failures are feedback that you can use to make your guidelines better.

On this blog, Charity Majors talked about using CI/CD processes to speed up the SDLC feedback loop; agents are no different. While you don’t need to implement a Ralph Wiggum loop, you can and should take mistakes in the code as an opportunity to update your standards files. Those errors might even be helpful to reveal the tacit parts of your coding conventions, those secret requirements that you may not have been explicitly aware of.

Using failure as a feedback loop is how you’ll have better agentic processes in general. “There's a big difference between people that just chicken-type a prompt,” said Quinn Slack, CEO and co-founder of Sourcegraph. “They don't really want the AI to win. Then there's people that put in a ton of time defining their rules, their `agents.md` file, and they write out what it should do. If it makes a mistake, then they'll go and update that and try to get it to be a flywheel.”

The other feedback loop to pay attention to is human. Keep the standards file open as a dialogue with your engineering team. Put it in Stack Internal or another documentation repository and get everyone to edit, comment, and update. This is the code that everyone will be building and reviewing; they should have a say in the guidelines.

The last step, of course, is to make sure that these guidelines live with your code and your agent context. Explicitly put all these rules in your `agents.md` and check them into a standard repo or build a Claude skill for them. Document the standard package for a coding setup like you do for the deployment pipeline.

That said, this shouldn’t be your call to give up all those other deterministic code standard enforcers. Linters, formatters, and static analysis tools still have a place in your build pipeline. They catch the basics that your agents botch.

Big companies who have tried to wrangle the coding styles of hundreds or thousands of engineers have a leg up on folks just thinking about this now. “Big companies have well-articulated style guides and best practices and processes to build code and deploy software,” said Logan Kilpatrick, Senior Product Manager at DeepMind/Google. “All of that is perfect ripe context to give to the model to make it helpful for you. Without a lot of that context, you are just taking a shot in the dark.”