A permission slip your AI agents actually can't exceed.
The name is the checklist: Context, Harness, Authority, Recovery, Telemetry, Evals, and Responsibility.
Every agent ships with one small charter.yaml that lists the only things it's allowed to do: which model, which tools, how much it can spend, which sites it can reach, which secrets it holds, and who owns it. A loader reads that file and is the only door. If it isn't in the charter, the agent can't do it. You can watch one agent, but you can't watch a thousand, so the rules live in the walls instead of a doc nobody reads.
Self-hosted YouTube and RSS aggregator. No algorithm, no recommendations, just the channels and blogs you chose.
Subscribe to channels and blogs and get a clean, chronological feed instead of a recommendation rabbit hole. It needs no API keys and runs entirely on your own machine.
Air-gapped GPG key generation with three-YubiKey redundancy for paranoid-level security.
A guide and scripts for generating elliptic-curve GPG keys (ed25519/cv25519) on an air-gapped Tails OS machine, then splitting them across three YubiKeys with LUKS2-encrypted backups. Every signature needs a physical touch, because your identity is worth protecting properly.
| Post | What it's about |
|---|---|
| From IoT Fleets to Agent Fleets | What running IoT fleets taught me about governing fleets of AI agents, and why I wrote C.H.A.R.T.E.R. |
| Reverse Engineering IoT Devices | Tearing apart a BLE smart bulb with Wireshark and gatttool, without touching the manufacturer's SDK |
| Minimising the Delta | How to encode your values into AI agents so they do what you actually mean |
- Blog: codensolder.com
- Contact: codensolder.com/contact
- PGP Public Key: codensolder.com/public.key
curl https://github.com/iayanpahwa.gpg | gpg --importKey fingerprint: 97CE 3B9E 75CF F9C7 6B9F C0A2 D87D 45E4 CCC3 57A7