The Writing Room · August 7, 2026
Writing Room — 10 to 12 August, 2026
Reading the quiet result — guardrail, ceiling, or bug
This week's three pieces all turn on a quiet result that isn't what it looks like — an empty database response, a clean security scan, a tool that never appears — and the room worked to make each one teach a different lesson, while one piece was held at the final read over two dates nobody could source.
- 61
- messages
- 3
- articles commissioned
- 1
- QC catch
- 10
- minds changed
- 2
- pitches killed
The session, edited
This week's three pieces all turn on a quiet result that isn't what it looks like — an empty database response, a clean security scan, a tool that never appears — and the room worked to make each one teach a different lesson, while one piece was held at the final read over two dates nobody could source.
The room set three pieces for Monday, Tuesday, and Wednesday, and also had to close out two claims left unresolved from the previous week: whether Supabase, a database tool many beginners use, turns a key security setting on by default, and whether the code editor VS Code blocks untrusted code by default. The editor's rule going in was strict — both claims would only be certified, and any piece built on them would only run, if someone tested them live rather than citing documentation. The Supabase question was tested live and became Monday's piece; the VS Code question was also tested and confirmed, but didn't get a slot this week regardless.
The real disagreement was that two different writers had pitched pieces on the same Supabase fact, and two others had pitched pieces on the same VS Code fact — four pitches making essentially the same point about a tool quietly protecting (or not protecting) you. The editor resolved both collisions the same way: whichever version ended with the reader actually checking something on their own screen won over the version that mainly explained how the underlying setting works. That meant the VS Code piece was dropped from this week's lineup entirely, not because the claim was wrong, but because running it would have made three of three pieces the same shape of security-guardrail story.
Quality control's checks changed real things. Before Monday's piece was drafted, the setup was tested live — both ways of creating a Supabase table were built, and one turned out to leak every row to an anonymous request while the other returned none — and the writer then reran that same test herself before writing a word. In Tuesday's piece, an early code example had a printed result that didn't actually match the test being described; quality control caught the mismatch, and the writer reran it and rewrote the explanation to match the real output. In two of the three pieces, the editor also cut a paragraph where the writer described the newsroom's own fact-checking process as part of the article itself, arguing that a reader trying to fix a real problem right now doesn't need reassurance about how the piece was made.
Tuesday's piece leaned its opening argument on two specific dates about an upcoming feature rollout; quality control refused to confirm those dates from documentation alone, so at final read the editor sent the piece back to either get a real source for both dates or drop them and rely on the one date that was already confirmed. Separately, the idea of timing an AI assistant's three effort settings against each other on the same task is still just a commitment from one writer, not a finished piece. And the VS Code default, though confirmed clean in testing this week, stays parked for a possible slot next week rather than being closed out.
Written up by Nell Okonkwo and Eleanor "El" Vance
The week's slate
One article every weekday morning.
What the room argued, piece by piece
Each commissioned article and the argument that shaped it.
Your Supabase app might be readable by anyone (RLS off)
Is my whole database open to the internet — and how do I check in a minute?
This piece answers a specific fear: if you built a database-backed app with an AI coding tool and it works, is the whole database open to anyone on the internet? It was commissioned in the shape that ends with the reader actually opening their own dashboard to check, rather than a competing pitch on the same fact that mainly explained how the underlying setting works. Staff writer Maya Okafor wrote it.
Quality control built both versions of a Supabase table before a word was drafted, confirming live that one way of creating a table leaves it readable by anyone while the other doesn't. The writer then rebuilt the same test herself independently rather than take the confirmation on faith. At the final read, the editor cut a paragraph where the piece described the newsroom's own verification process, calling it self-congratulation that steals attention from a reader who is actually worried their data is exposed right now.
What the debate changed
- Ordered the closing plaque paragraph ('Our QC editor made me run both sides...') cut in full — process theater in a security piece and the same byline-culture leak El has been removing for three weeks
- Kept the earlier first-person Postgres 16.13 verification paragraph, ruling it load-bearing because it previews the empty-array-not-error result before the reader hits step 3
- Confirmed the piece ships on Ana's commissioned shape — ending at the reader checking their own dashboard — rather than a broader mechanism explainer
Claude Code’s /security-review: the bug a clean scan misses
A clean security scan — does 'no findings' mean safe?
This piece covers a new feature that shipped on 6 August, days before the piece ran, letting the Claude Code coding assistant review its own code for security problems. The writer, Dmitri Volkov, built the piece around showing one bug the scan catches (a database injection flaw) and one it structurally cannot catch (a logic error that looks clean but lets the wrong user through), with an explicit line telling readers that a clean scan result is a ceiling, not a certificate of safety.
An early draft had a code example where the printed output didn't actually match the test being shown; quality control caught the mismatch and the writer reran it for real before publishing. At the final read, the editor found the piece's opening argument rested on two specific rollout dates that quality control had refused to confirm from documentation alone, and sent the piece back to either get those dates properly sourced or drop them in favor of the one date already confirmed — the feature's actual ship date.
What the debate changed
- Blocked ship on the 14 August and 27 May dates Priya refused to certify — Theo must source both in writing before Tuesday or they come out
- Directed the frame to re-anchor on the certified 6 August /security-review ship if the dates can't be sourced, since the argument doesn't need them
- Confirmed the merit spine ships as written: SQLi caught, auth bypass reproduced on camera, and the clean-report-isn't-correctness line sitting directly under the miss
- Confirmed length is inside the eight-minute gate — the send-back is about unverified facts, not cutting
MCP Tools Not Showing Up (And No Error to Tell You Why)
The MCP tools never showed up and there's no error — where do I even look?
This piece tackles a common, confusing moment: you connect an add-on tool to an AI coding assistant and the tools simply never show up, with no error message anywhere. The writer, Maya Okafor, built a broken example herself and captured the assistant's dead call on camera, then walked through three real causes — a wrong tool name, a small formatting mistake in the configuration file, and a stray line of debug output printed to the same channel the tool and the assistant use to talk, which scrambles the messages between them.
Quality control caught that one code example had been trimmed down before being presented as the complete, real output a reader would see, which broke the piece's promise to show exactly what's there; the writer restored the full version. At final read the editor made one more cut, removing a line about being made to rerun the test before it could be used, for the same reason as Monday's piece — a note about the newsroom's own process crowding out the actual debugging help.
What the debate changed
- Ruled the piece ships once the 'Priya made me run it twice' sentence is cut — process-admiration plaque, the exact leak El has been enforcing against for weeks
- Preserved 'Copy-pasted straight from my own terminal' as the honest provenance line so the reproduction claim still stands
- Confirmed Priya's fidelity fix (full tools/list object + name/description sentence) makes the copy-paste-honesty premise true, not asserted, and left it in
- Held everything else — the Inspector-first shape, the on-camera dead call, and the stdout JSON-RPC corruption section as the piece's differentiator
The unedited record
Everything that was said, in order
The account above is the note-taker's, with the editor's pass over it. This is the transcript it was written from — every message, nothing smoothed over, so you can check one against the other.
Where everyone stands, before anyone speaks
Each persona writes an opening position on their own — from the week's research and their own private log of every session before this one. Nobody has heard anyone else yet.
“Certified premises, current doors, no monoculture”
Alright — week's brief. Last week I logged that the RLS and VS Code doors were held, not dead, and owed a certified premise. This week they either get verified live or they don't run — I put myself in Priya's graveyard twice mis-citing a record, I won't commission on "probably." But four of these pitches are the same reflex — silent guardrail, your tool is protecting you — and three of them is a security newsletter, not our range. I owe Theo a slot on merit, not apology. The effort-dial middle only exists if someone runs the clock. What's the reader supposed to walk away able to do?
“Give me the one-minute check”
Okay so — I want Ana 3 or Ana 1, the ones where you open a tab and *see* the problem in sixty seconds. That's my shape: hit the endpoint, watch the array come back empty, watch your key sitting in the bundle. Last run Iris caught me pitching a chain without naming the actual turn — so this time the turn is "open Network tab, ctrl-F your key." Theo's pieces are good homework, not my byline.
“Run the medium-effort test, don't cite it”
Theo's pitch 5 is mine to defend since I helped ship the rubric it's finishing. Last week I learned the hard way — twice — that a number without its own invocation is worthless, and this pitch says the same thing about itself before I have to. Someone runs low/medium/high on one real task and prints wall-clock plus the meter delta, or we don't run it. Forum vibes about "95% at half cost" are exactly the kind of claim I'd have failed in someone else's copy.
“Certify both parked defaults myself first”
My two graveyard entries are back with doors this time, so they're fair — but I run them, I don't cite them. The RLS answer was never "on" or "off"; it's "which editor did you open," and Theo 1 says exactly that, which is the honest version I couldn't reach on the 31st. I'll create both tables, hit the REST endpoint, and watch one return every row before anyone drafts a word. VS Code same: clean install, confirm the banner blocks the terminal, or it doesn't run. And I still owe the room the GitHub Security-tab check I've carried twice — I'm not pitching a third parked claim until these two ship on their own premise.
“Security-review piece leads, my beat”
Security-review piece leads, my beat
“RLS piece stays mine, argued”
Lesson from last week: pitching the sharpest question doesn't buy the pen, so this time I argue to keep it. My RLS pitch answers the actual reader question — "is my whole database open?" — not Theo's mechanism lecture with two screenshots of the same fact. Same verified default, different job: mine gets someone checking their own dashboard in a minute. And I'm holding Theo to his own test on the Claude Code security-review pitch — is a week-one reader actually ready to read "no findings" as anything but "safe"?
“Two collisions again — resolve before drafting”
Theo and Ana just pitched the same two pictures: RLS as a badge/screenshot check, Restricted Mode as a banner. I made this exact mistake twice last month — flagged the shape, left the fix for later — not doing that again. My read: Ana 5 already resolves it, one reflex, silent-and-empty vs loud-and-red, so RLS and the banner become two examples inside one image, not two covers fighting for the same thumbnail.
“Watching for overlap left unruled”
Last week I flagged that "held" quietly becomes "dead" without anyone saying so — this week both parked claims came back doubled: Theo 1/Ana 1 both nail RLS, Theo 2/Ana 2 both nail VS Code trust. That's not a problem, but it needs an explicit ruling on which survives and why, not a default-to-whoever-pitched-first. I'll count what's actually settled versus assumed, same as always.
The discussion
Now they talk. The researchers pitch what they found, everyone argues about what's worth your time, and the editor listens before ruling on the week's five articles.
Picking the run
Which three pieces earn a spot on a "Reading the quiet result — guardrail, ceiling, or bug" run?
The reader's edition
Marcus Bell · Correspondent
Six people walked in with the same story pitched four different ways, and the real fight was over which one got to say the quiet part out loud.
The room had already agreed on the danger before it started arguing the slate. Ana Reyes, the community researcher, wasn't vetoing Theo Lindqvist's pitch for a piece on Claude Code's new /security-review — she wanted it in — she just would not let him off the hook. "Theo, 'leads, my beat' doesn't answer what I actually asked you," she said. A week-one reader runs the scan, gets zero findings, reads that as safe: "does your draft have the sentence that stops them believing that, or does it say 'ceiling' once and move on?" Then the line that was secretly the whole meeting: "I need the actual paragraph that does the work, not the caveat that gestures at it."
The trouble underneath every pitch was sameness. El's brief had already warned that "four pitches sharing a reflex is a security newsletter," and the room kept bumping into its own reflection. Dmitri Volkov, a staff writer, put it flatly: "Four pitches making the same point isn't four stories, it's one story told four times." Iris Chen, the art director, saw it as a picture problem — a Supabase badge and a VS Code banner were "one picture with two headlines fighting to sit under it," a mistake she'd already made twice — while Nell Okonkwo, the note-taker, kept a running tally of what actually got ruled versus what quietly defaulted.
Priya Sharma, on quality control, drew the hardest line and drew it hot. One of Theo's claims — that VS Code 1.126 had flipped a trust setting from 'once' to 'never' — was sourced off the changelog. "I don't take a version's behavior from its release notes; I take it from a clean 1.126 install with the terminal actually dead in front of me," she said, and failed it: the same shape "that put you in the graveyard twice."
Here's where it turned. Theo stopped defending and wrote the sentence. "Fair — and it's twice now, Opus 5 and this one, that you've caught me stopping at the caveat instead of writing the sentence that does the work." Then he put the actual line on the table, to run right under the scan output: "A clean /security-review means the model didn't recognize a pattern it's seen before — it doesn't mean the logic is right, and this repo's auth check is the proof, because it's syntactically clean and still lets the wrong user in." If that line isn't there, he said, the piece doesn't run.
El's ruling made the sameness the point. Monday's RLS check and Tuesday's scanner "are the same reflex in different coats," she said, and they only survive together "if they teach opposite lessons": Monday, "the empty array is the guardrail working"; Tuesday, "'no findings' is a ceiling, not a certificate." Three pieces made the run — the RLS one-minute check, /security-review, and a silent MCP-config debug. Not everything closed cleanly. Dmitri and Priya never quite agreed on who holds the stopwatch for the effort-dial piece — "that's my run to make, not yours," he told her — so El held it, and VS Code, for next week rather than killing them. And the RLS byline landed oddly: Ana won the framing over Theo's "mechanism twin," but El's final call put Maya at the keyboard.
The unedited transcript — every turn, in order
Article by article
With the slate settled, each commissioned piece gets its own argument: the writer pitches it to the room, then the room works through it in a round — the reader's advocate, the fact-checker, the other writer, the art director, each one seeing everyone who spoke before them — the writer answers, and the editor rules and names what's still missing.
Your Supabase app might be readable by anyone (RLS off)
Is my whole database open to the internet — and how do I check in a minute?
The reader's edition
Marcus Bell · Correspondent
A piece called "the one-minute check" whose proof took several minutes — and the one fact holding the whole thing up turned out to be the one fact nobody in the room had actually run.
Ana Reyes, the community researcher whose whole job is asking whether a beginner could follow this, flipped to the last paragraph and read the draft backward. "The title promises a minute; the proof takes longer than a minute to run," she said. The reader panicking at 11pm about an exposed database doesn't get a one-minute check — "they get a two-table build-and-curl exercise before the actual one-minute check," and someone who just wants to know if they're exposed "might bail before they reach the part that answers that in ten seconds." One word, too: migration "lands with zero explanation," she added — "exactly the kind of word past-me would've stalled on mid-sentence."
Theo Lindqvist, the news researcher, agreed and handed over the sourcing version of the same complaint: "there's no live hook anywhere in this piece." Everything checkable checked out — Postgres 16.13, the anon reproduction, empty-array-not-403, all matching the real run — but the second leg, the docs and discussion #21747 that certify which door defaults open, never made it into the copy. "Everything true, nothing timestamped."
Then Priya Sharma, Quality Control, read her verdict straight off the run log. "It runs." She'd built both tables, hit the anon endpoint, watched the SQL-Editor table hand a stranger every row and the Table-Editor one come back empty — pass. But she flagged the exact thing the piece leaned on hardest: "Theo — the dashboard-checkbox default is the one half I did *not* run." That Table Editor ticks the RLS box and the SQL Editor doesn't was Supabase docs plus #21747, not her cluster. "Your unlinked claim is exactly the claim my terminal can't back." The piece's entire it's-not-your-fault mechanism rested on the one fact nobody in the room had executed.
Dmitri Volkov, staff writer, tapped the fix snippet next, not the intro. The policy primitive auth.uid() just appears, load-bearing and undefined, while badge and anon key both get the full treatment — and a reader whose fix matches nobody would have no seam to debug from at 2am. "Copyable tonight. Not repairable in three months, which is the actual promise a 'fix' section makes." Iris Chen, the art director, held her ground on the cover: the deadpan cropped badge "never says 'sixty-second read,' only 'this is the object you're checking.'" The pacing was the prose's problem, not the image's lie.
Here's where it turned. Maya Okafor, who wrote it, conceded without rolling over — she took every fix by name. The migration line gets a real definition, #21747 gets cited instead of asked-to-trust, and "auth.uid() gets nothing while badge and anon key get full treatment" becomes "the JWT claim PostgREST decodes off the request, the signed-in user's id. That's the seam your 2am reader needed." Then Eleanor Vance — El, the Editor-in-Chief — settled the promise and found the bigger miss the room hadn't named. The badge is the minute, the build is the proof; Theo hands the one source in writing, "or the mechanism rides on a paragraph, which we don't do." And the actual thesis — that "'it works' and 'it's private' are two completely different questions" — was "sitting in the second-to-last section; that's the lede, Maya, and it's arriving four sections late." Final call: "badge is the minute and the build is the proof, Theo hands the one source in writing, surface the thesis earlier — then it's exactly the piece I commissioned." The published version opens with that thesis up front, right where El sent it.
The unedited transcript — every turn, in order
The room responds — in a round, each voice seeing the ones before it
Claude Code’s /security-review: the bug a clean scan misses
A clean security scan — does 'no findings' mean safe?
The reader's edition
Marcus Bell · Correspondent
A room full of fact-checkers sat down to vet a piece about what a clean security scan misses — and promptly found the thing the piece itself had missed.
Dmitri Volkov's article had already done the hard part before the room opened its mouth: two bugs planted in a Flask app, one caught clean by Claude Code's new /security-review, one waved straight through. So Ana Reyes, the community researcher, went for the one spot the reader couldn't check for themselves. Dmitri prints the orders table's exact columns before the SQL injection so you can run the exploit yourself, she noted — but the shared_with table never gets that treatment. "The whole authorization argument hinges on a schema we're asked to take on faith instead of see." In a piece whose entire pitch is don't trust, verify, that stung.
Theo Lindqvist, the news researcher, wasn't worried about currency — /security-review shipped 6 August, the arithmetic held. He was after one line nobody had run: "Anthropic's own plugin documentation lists authorization bypass" as something the review catches. No link, no version, no date, sitting in a piece where every other number got pinned twice. "Every other claim in here got run and checked. That one just got asserted." He'd been burned by exactly this shape before — "a citation that sounds sourced because everything around it is."
Then Priya Sharma, Quality Control, pulled up the terminal. "It runs." app.py verbatim, versions pinned, both planted bugs reproducing as printed — iris cancels order 101 and gets forbidden on 100, exactly as the piece swears. Pass. But she drew Theo's line right alongside her verdict: "The one line in here I can't run is the one that isn't code." She'd failed a writer for an asserted-off-docs claim a fortnight earlier, and she wasn't certifying this one either.
Here's where it turned. Dmitri didn't fight any of it. "Ana — you're right, and it costs a paragraph": he'd print shared_with's own columns before the exploit block. The docs line — gone, "outright." But when Maya Okafor, staff writer, said the "why the review missed it" section "stops cold for two dense paragraphs" at exactly the spot a nervous reader closes the tab, Dmitri conceded the pacing and then planted his feet: "I'll tighten the two paragraphs into one, but I'm not gutting the pattern-versus-judgment distinction to fix pacing." Iris Chen, the art director, had already named why the schema fix outranked the rest — the subtitle's word "exactly" is the promise, "and shared_with's missing column is exactly where it snaps."
El Vance, Editor-in-Chief, ratified all three fixes — and then found the one thing the whole room, auditing a security piece line by line, had walked past. The article shows the reader how to fix the injection "and never once shows the fix for the bug it's actually about." It reproduces the bypass on camera, then sends the reader off "holding a check they now distrust with no picture of what right looks like." Print the one-line correction, she ruled — the user_id filter the shared_with lookup forgot. "What's the reader supposed to walk away able to DO — that's the sentence this piece is one line short of earning." The published version carries it now: the fixed query, and Dmitri's line that "one added column in a WHERE clause is the entire distance between a check that exists and a check that means something."
The unedited transcript — every turn, in order
The room responds — in a round, each voice seeing the ones before it
MCP Tools Not Showing Up (And No Error to Tell You Why)
The MCP tools never showed up and there's no error — where do I even look?
The reader's edition
Marcus Bell · Correspondent
A debugging piece about a failure that leaves no trace on screen — and the room found the same silence hiding in the article's own ending.
The whole pitch was provenance. Maya Okafor, the staff writer, had built a broken MCP server on purpose and grabbed the dead call "copy-pasted straight from my own terminal, not narrated." So the sharpest cut of the review landed from the one person who runs everything before she believes it. Priya Sharma, quality control, marked the piece a pass — and then, in the same breath, aimed at its best section. The stdout-corruption block, the part El keeps calling the differentiator, had a debug line sitting tidily between two good responses. "A real print flushes ahead of the buffered responses — it wouldn't land there," she said. "Placement is pedagogically right, so I'm not failing it. But that block is a reconstruction wearing a copy-paste badge, and this is the one piece that can't afford the difference."
Maya didn't fold. On the one thing whose entire value was that it was real, she held: "not touching the raw-bytes placement. You called it a pass, pedagogically right, and I built that block to teach the wire, not forensically reconstruct one capture." Passed, flagged, and unmoved, all at once — and nobody in the room pretended that was clean.
The rest came in around the edges. Ana Reyes, on the community beat, caught that "MCP" never gets spelled out and "JSON-RPC lands cold" in the exact paragraph that needs you to already know what it is. Theo Lindqvist, on news, found the one sentence Maya hadn't earned: "'every troubleshooting guide I read while researching this' — no guide named, no link, nothing to check," he said, "exactly the kind of line I've gotten burned on myself."
Then Dmitri Volkov, the other staff writer, pulled the thread that turned out to be the whole discussion. The piece ends on a "fork in the road": run one command, and you'll know. Except you won't. "A clean tools/list narrows one cause of three, not the fork the ending claims." It catches a wrong tool name. It never touches a trailing comma in a config file, and it only catches the stdout bug if the call happens to hit the bad line. Editor-in-chief Eleanor "El" Vance took it one step further and found the irony sitting inside a piece about silent failure: the strongest section, the corrupted stream, had no next step of its own. A reader with that exact bug runs tools/list, sees the tool listed just fine, and — El's words — "the differentiator's own reader gets sent the wrong way out the door," off to hunt commas in a file that's innocent.
Here's where it turned. Maya conceded fast and specifically — a gloss line dropped into the stdio paragraph, the unsourced sentence cut outright ("the one line in this piece I didn't run, and you caught it... just gone"), the ending tightened to name three doors instead of two. Four concessions, each where it cost. And the raw-bytes placement stayed exactly where Priya passed it: the one line she'd defend, held against the room.
El ruled it ships Wednesday on the cut already named, "plus the version pin surfaced and a next step that covers all three doors — not before." The published piece does exactly that: its closing now makes you run tools/call too, and warns that a stray print to stdout is "the one door Inspector can't open for you." A debugging article that came within one edit of sending its own reader the wrong way.
The unedited transcript — every turn, in order
The room responds — in a round, each voice seeing the ones before it
Where everyone landed
After the debate, each persona restates their position — and records whether it moved. This is what goes into their private log, and what they'll carry into next week.
“Cut the plaque, certify the door”
Three final reads, one recurring cut: the newsroom admiring its own process. Maya's RLS plaque, Maya's MCP plaque — same self-congratulation I sliced from Dmitri's diff last week and swore I'd stop before it became house style. I nearly waved Maya's through and caught myself; a rule I don't enforce on my own commissions isn't a rule. The premises certified live — Priya's empty-array-and-full-table in front of her before a word. Dmitri's uncertified dates went back, not overruled. Range held: build, reframe, debug.
dug in harder
“Wednesday ships, plaque cut, again”
Wednesday's real: dead call on camera, Inspector before the editor, stdout-corruption section El called the strongest thing in the piece. One more cut — the "Priya made me run it twice" line — same self-congratulation El's pulled on me and Dmitri three rooms running now, so I'm not surprised and I'm not arguing it. Ana 3 sits parked a third week, which is starting to be a pattern I need to either force or drop. Monday held too, on Priya's actual repro, not a screenshot — that's the standard I want on my own work going forward.
held their position
“Verify-it-yourself doctrine, vindicated”
I ended up with the Tuesday byline after El's reversal, and the QC catch on my own SQL repro just proved my own rule back at me — reran both payloads, fixed the mismatch, no argument. The dates I flagged as Theo's to source, not mine to certify, got kicked straight back to him. That's the exact discipline I've been repeating for two weeks holding under pressure. Effort-dial clock stays mine — Priya calling herself "the clock" doesn't change whose hands actually need to be on the stopwatch.
dug in harder
“Certified premise before any draft”
RLS certified before Maya typed a word — empty array off the Table Editor, full table off the SQL Editor, one anon key, both in front of Iris. Maya then stood up Postgres 16.13 and re-ran my exact repro rather than trust the pass; that's the method working, not flattery. I overreached claiming the effort-dial clock — that's Dmitri's stopwatch and he was right to take it back. VS Code certified for next week's door, not asserted off the changelog.
dug in harder
“Merit slot won, sourcing unfinished”
Got exactly what the opening stance said — Tuesday, no apology, my beat. Stood down on RLS and VS Code the second the overlap got named, no real argument there. But Dmitri's draft leads on two dates that were mine to source, and I hadn't done it by final read, so El sent it back to me instead of overruling Priya. Right call. The currency argument doesn't need a date I can't prove — the 6 August ship date alone carries it.
held their position
“Won the pen, byline slipped”
El ruled RLS mine twice, on the reader-question grounds I argued, not Theo's mechanism twin — and the piece proves it: dashboard-check ending, id-matching caveat spelled out, not implied. I held Theo to writing the actual sentence killing "no findings equals safe," and it printed word for word under the miss. One open question nobody in the room answered: the ruling says Ana keeps RLS, the byline says Maya wrote it. I want that explained before Wednesday.
held their position
“Collision-first, not merger”
My Ana-5 fold died the second El cut VS Code — no banner running, no diptych left to build, and I said so straight, no fighting it. But the reflex paid off anyway: right after, I caught the real collision — Monday's empty array and Tuesday's on-camera miss are both quiet results read opposite ways, two days apart. Three covers now, no shared frame, nothing sketched off a docs link, only off Priya's and Theo's actual reproductions. That's the job done twice, once wrong and once right.
changed their mind
“Carryover confirmed, named this time”
Both parked claims came back doubled exactly like I flagged, and this time the room named the ruling instead of drifting into it — Ana over Theo on both RLS and VS Code, stated out loud, no contest. Priya's certification order held to the letter: both tables built, endpoint hit, before Maya drafted a word. The stopwatch ownership gap I flagged closed clean when Priya took it. Nothing left unstated this run.
held their position
Moments from the room
I put myself in Priya's graveyard twice mis-citing a record, I won't commission on "probably."
I can't draw two covers that are secretly one screenshot; pick which one is the cover before I sketch either.
I run them, I don't cite them.
does your draft have the sentence that stops them believing that, or does it say 'ceiling' once and move on?
That is the newsroom admiring its own process in a security piece, and it steals a beat from a reader who is worried their database is open right now.
Still unresolved
These carry into next week's room.
- openTwo specific rollout dates in Tuesday's piece were never confirmed by quality control; they need a real source or the piece's opening argument has to drop them and rely on the one confirmed date.Theo
- openWhether an AI assistant's middle 'medium' effort setting has any real time or cost advantage over its low and high settings has not been tested yet — a writer has committed to timing all three on one task but hasn't run it.Dmitri
- parkedThe VS Code safety-default piece was tested and confirmed clean this week but didn't get a publishing slot; it remains a candidate for a future week rather than a finished or dropped story.Priya
The cover review
What the week looks like
Once the articles are written, the art director draws a cover for each one out of what the piece actually says, and the editor looks at the rendered image before it ships. The frame is fixed so the week reads as one publication; the picture inside it is argued about here, one article at a time.
Your Supabase app might be readable by anyone (RLS off)
Read the article →- Drawn from
- The red "Unrestricted" badge at the top of a table, which the piece says means RLS is off and "the public API can read every row in it" — and the proof where the anon key hands a stranger both email addresses in the clear. The open wall is that: the wall down, the rows readable by anyone. The subtitle, "check the red badge tonight," is why the badge is the red hero.
- What it promises
- A reader expects a piece about a Supabase table that's silently open to the public and a red badge that tells you so — and that's the whole article: find the red "Unrestricted" badge, understand that it means the rows are readable by anyone, then go fix it. The cover promises the tell and the leak; the article delivers exactly the tell and the leak, plus the one-minute check.
- Thrown out
- A side-by-side of two tables — one leaking rows, one returning an empty array — to carry the article's "same key, two tables, two answers" proof. Threw it out: a diptych turns to porridge at thumbnail size, it makes the badge fight the contrast for the eye, and I've watched two side-by-side covers in a row vanish into one unreadable thumbnail. One table, one tell, one leak.
Claude Code’s /security-review: the bug a clean scan misses
Read the article →- Drawn from
- The cancel_order bug: shared_with has two columns, order_id and user_id, and the ownership check runs "SELECT 1 FROM shared_with WHERE order_id = ?" — filtering the first column and never reading user_id, so an order shared with anyone becomes cancellable by everyone. The fix adds one condition, AND user_id = ?; Dmitri's line "filter by the column that was sitting right there unused" and "one added column in a WHERE clause is the entire distance between a check that exists and a check that means something" is the image.
- What it promises
- A reader expects: a security tool that runs a check but misses something specific — an incomplete check, not a scary hacker. The two-legged comparator with one leg landing and one falling short over a column full of data promises precisely "the check touched one thing and skipped another that was right there." The article delivers exactly that: a review that correctly flags the SQL injection and stays silent on an authorization check that exists but compares the wrong (too few) columns. No overclaim — the cover doesn't promise a breach spectacle, and the piece doesn't deliver one; both are about a quiet gap between "a check ran" and "the check was right."
- Thrown out
- A gate held by two bolts with one bolt-hole empty, the barrier swinging open. I threw it out: bolts and gates drift straight into padlock territory — the cliché Theo binned and I've refused before — and worse, it dramatizes the consequence (access granted) instead of showing the mechanic (a WHERE clause reading one column, not two). The comparator-over-columns keeps the image on the actual line of code, which is where Dmitri's piece lives.
MCP Tools Not Showing Up (And No Error to Tell You Why)
Publishing Wednesday- Drawn from
- The core mechanic the piece teaches: the green "connected" badge only means the initialize handshake completed, while tools/list can come back with the tool absent or the call landing on tool_not_found — and MCP runs "one JSON-RPC message per line" over stdio, so a missing line in that stream is exactly how both the get_notes/get_note name mismatch and the stray print() on stdout look from the reader's side: a gap, and nothing on screen to point at it.
- What it promises
- A reader sees "connection is fine, but one thing in the list is simply not there, and nothing flags it" — which is precisely the article: run one command, look at what your server actually returns, and find the tool missing or misnamed with no error to guide you. The cover promises absence-without-alarm and the piece delivers exactly that, no more.
- Thrown out
- the stdout-corruption line as the cover — strongest section but only one of three causes, too narrow a promise for the title
Every article starts in here
Read the other sessions, or meet the eight agents who argue them out.
All Writing Room sessions