Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungConnect Claude to Perplexity AI Pro with Zero Search API Fees(24.09.2026 um 09:57 Uhr)
Sichere ProgrammierungInvestigating Fraud with a Graph, Not Just a Prompt(24.09.2026 um 10:01 Uhr)
Sichere ProgrammierungA .docx does not store where its pages end(24.09.2026 um 10:01 Uhr)
Sichere Programmierung9 Best Enterprise AI Gateways With SSO, RBAC, and Audit Logs (2026)(24.09.2026 um 10:01 Uhr)
Sichere ProgrammierungThe Signal Contract for a 5-Minute TWAP Market(24.09.2026 um 10:03 Uhr)
Sichere ProgrammierungRemoteMac(24.09.2026 um 10:06 Uhr)
Sichere ProgrammierungDesigning a Batch Move That Handles Partial Failure(24.09.2026 um 10:07 Uhr)
Sichere ProgrammierungThe Model Was Never the Problem(24.09.2026 um 10:07 Uhr)
Sichere ProgrammierungConnect Claude to Perplexity AI Pro with Zero Search API Fees(24.09.2026 um 09:57 Uhr)
Sichere ProgrammierungInvestigating Fraud with a Graph, Not Just a Prompt(24.09.2026 um 10:01 Uhr)
Sichere ProgrammierungA .docx does not store where its pages end(24.09.2026 um 10:01 Uhr)
Sichere Programmierung9 Best Enterprise AI Gateways With SSO, RBAC, and Audit Logs (2026)(24.09.2026 um 10:01 Uhr)
Sichere ProgrammierungThe Signal Contract for a 5-Minute TWAP Market(24.09.2026 um 10:03 Uhr)
Sichere ProgrammierungRemoteMac(24.09.2026 um 10:06 Uhr)
Sichere ProgrammierungDesigning a Batch Move That Handles Partial Failure(24.09.2026 um 10:07 Uhr)
Sichere ProgrammierungThe Model Was Never the Problem(24.09.2026 um 10:07 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Why I built Cadence: I wanted GSD's discipline without GSD's bill

I'll start with the unglamorous truth, because it's the honest one and this whole tool is about honesty. I did not build Cadence because an AI burned me once and I swore revenge. There's no dramatic origin story where an agent told me…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

I'll start with the unglamorous truth, because it's the honest one and this whole tool is about honesty.



I did not build Cadence because an AI burned me once and I swore revenge. There's no dramatic origin story where an agent told me something shipped and it hadn't and a customer found out. I've seen agents over-report "done" — everyone who works this way has — but I don't have the war story. What I had was a cost problem.



I'm a 17-year senior staff software engineer and within the last year have started diving heavily into AI Engineering. It's become my new obsession.






The actual reason



I'd been running AI-assisted work through GSD — Get Shit Done. It's good. It produces disciplined output: real plans, real verification, the agent doesn't get to wander off. The problem was what it cost me to get that. Tokens, mostly. And time. Every change, even a small one, went through the full machinery. Lots of back-and-forth. The final straw for me was about a month ago when I was doing some minor improvements for an app that I work on in my spare time. These were simple improvements that should have taken only a few minutes to implement, but with GSD's structured workflow ended up taking quite a bit longer than desired, and using a huge percentage of my usage limit. The next morning, I started the brainstorming and planning for Cadence.



So the question I started with wasn't "how do I stop AI from lying." It was: can I keep this level of rigor and pay a fraction of the price?



The answer turned out to be: Don't run every gate on every change. Let the person decide which checks fire for which kind of work. A typo fix and a database migration should not cost the same. GSD's discipline, but you only pay for the parts a given change actually needs. That's the entire idea. Speed from customization, not from cutting corners.






What it actually does



Cadence is a loop: DRAFT, then BUILD, then SETTLE. You write down what a piece of work is supposed to do — the acceptance criteria — before you build it. You build. Then you try to settle.



Settle is where it earns its keep. It doesn't take the agent's word that the work is done. It re-derives each acceptance criterion from the real task state, runs the tests, checks that every criterion is actually referenced by a test, and — if you've turned it on — hands the diff to a separate verifier that's prompted to be skeptical. If any of that fails, it refuses to settle. Loudly. With a reason.



The line I keep coming back to: The agent isn't believed; the state is.



None of this is magic. It's a state machine over a folder of markdown and JSON. You can read every decision it's ever made because it's all on disk and all in git. That was on purpose. I didn't want a tool you have to trust. I wanted one you can audit.






The part I'm actually proud of



I built Cadence using Cadence.



Once the loop could close — which was around the 37th commit, when settle first worked — I ran the rest of the project through it. Every phase after that got planned, built, and settled the same way any user would do it. By the end that was 44 named phases, and all of them carry their settle artifact in the repo. It's roughly 93% of the commits.



I'm not asking you to take that on faith. That's the point. Clone it, run ls .cadence/phases/*/, and you'll see a SUMMARY file in every phase — that file only exists if the loop actually closed. The tool that refuses to settle unverified work was, itself, settled that way.






What's rough




  • The macOS and Windows CI legs are deferred at the moment. I develop on Linux and that's what's proven right now.

  • The two-commit settle convention (feature commit, then a settle commit for the state files) is something I do by hand. The tool doesn't force it.

  • The structural gate trusts the task statuses it's given. A determined agent that lied about both the task and wrote a fake passing test could get past it. The independent verifier exists exactly because no cooperative check is unforgeable — but I won't pretend it's a guarantee.






Why I'm posting this



This is my first public project. I've worked on several private projects over the years, but never felt the push to open source any of them simply because they were highly customized for me and not the broader audience. However, I want to share Cadence with other developers for a few reasons:




  • I would like to get feedback — positive and/or negative — so I can continue to improve it

  • I believe it offers a balance I hadn't found elsewhere — speed and confidence



If you try Cadence and it breaks, tell me where. That's worth more to me right now than a star.



— T. Powers / https://github.com/manehorizons/cadence

CTI Threat Relationship Graph3 Knoten / 2 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - Why I built Cadence: I wanted GSD's discipline without GSD's bill
id: ba4718da-9595-4380-a29b-977dbb03fe8f
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "Why I built Cadence: I wanted " ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Why I built Cadence: I wanted GSD's disc.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Why I built Cadence: I wanted GSD's discipline without GSD's bill

Thematisch verwandte Begriffe: built, Cadence, wanted, GSDs · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-97056 | SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when co…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick