Hekton

The Hekton Field Journal

Build logs from a personal agentic software factory. One human, several AI agents, and the architecture, mistakes, and controls that survive contact with reality.

Field Notes

Recent posts

See all 69 posts

agentic-sdlc-patterns

Two Reviewers, One Exploit, Two Real Bugs

Two AI reviewers, independently, with real build and openssl access, found a bypassable revocation path and a spoofable certificate identity field in device-CA code. Both were confirmed with a live exploit, before and after the fix.

28 Aug 2026

agentic-sdlc-patterns

Shipping With a Watch, Not a Verdict

Five doubt cycles on one small registry guard, and the finding rate never reached zero. What actually caught the headline bugs was mutation testing and fresh-context review, self-inspection caught none of them.

27 Aug 2026

agentic-sdlc-patterns

It Wasn't a Matched-Cast Comparison

A live-model coordination comparison looked decisive: peer-delegation succeeding, central-orchestrator starving the colony. An independent review asked whether it was actually a fair fight. It wasn't.

26 Aug 2026

agentic-sdlc-patterns

Doubt Before the Code Exists

Adversarial review, applied at intent-declaration time instead of code-review time, caught real defects before a single commit existed to review, proving the doctrine is a decision-making technique, not just a code technique.

25 Aug 2026

agentic-sdlc-patterns

The Fixes That Held Changed a Rule

Three adversarial review rounds on the same new codebase, and the diagnostic that separated a durable fix from a fragile one: did it change a rule, or just a line?

24 Aug 2026

agentic-sdlc-patterns

No Model Reviews Its Own Homework

Four documented review cycles, one recurring shape: a fix, left unreviewed by a second perspective, quietly introduces the next bug. The sentence the factory arrived at after proving it the hard way, four times.

23 Aug 2026

Five doors, not nine categories

Find your way in

All series

Arcs

Connected reading paths

All arcs

The Local Coding Harness

7 posts

One week, one question: can a 24GB laptop running only local models safely fix real code? The honest answer went from "it cannot produce a single valid patch" to "two local labs autonomously fix each other's code" in seven days, not by making the models smarter, but by repeatedly moving trust from model instruction-following to mechanical verification.

From Control Tower to First Product

9 posts

One question, asked after a project spent 25 days producing documentation and no working code: why does a factory that can build individual tools still struggle to coordinate them into one real product? The answer took three working sessions to build and prove: trust moved out of the agents doing the work and into the contracts between them, so a status can be checked instead of just believed, and a failure shows up loudly instead of quietly passing as success.

No Model Reviews Its Own Homework

6 posts

The factory's adversarial-review practice didn't start as doctrine, it became doctrine because the same failure kept recurring: a fix, itself unreviewed by a second perspective, quietly introduced the next bug. This arc is that doctrine's origin story plus four demonstrations that it holds outside its original context, closing on the sharpest evidence available: two real, live-exploit-confirmed bugs a second reviewer caught that the first pass missed.

Live ยท Factory Pulse

Fetched from GitHub on this page load, not baked in at the last deploy. Scoped to the specific repos that have graduated to public artefacts -- most of the actual factory stays private.