Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More

Owned by Bas

456 contributions to Clief Notes
WISE ARCHITECTS CORNER - The Fourth Rung Is Open - 🔁 Loop Engineering
I want to take a minute to thank @Jake Van Clief for giving me the opportunity to bring this material to our community. This community is more than just a place to post, it's a place to engage with people, to learn and grow together and I am grateful to Jake and the community for making this skool what it is. If you have been following the releases of my latest classes, the latest rung on the ladder is open! (If you are just getting here, do not worry, the first three rungs are open, and you can find the links below in the "where you are standing" section of this post ☺️) Rung three built what survives the window. Rung four is what runs without you, open from today. Think of the last thing you asked the model to redo. It drafted, you read it, you said "shorter." It drafted again, you read again, you said "warmer." Then "send it." Four rounds, and every one of them waited on you, because the only thing that knew what good looked like was sitting in your head. That is not the model being lazy. That is a loop with a person welded into the middle of it, and the person is you. 📚 What just opened: Loop Engineering, the whole rung at once. The Overview draws the line the rung stands on, single-pass against a closed circuit, and the three classes carry one claim each: (1) The acting is easy, the evaluating is hard (2) A loop that does not know when to stop is not careful, it is lost (3) Some judgment stays with a person, on purpose Then the payoff, the whole series on one card, and my perspective on rung four. By the end you own a loop: your "done when" line rewritten as a check the system runs on its own work, a rule for when it stops, and one clear place where you still sign off. Fewer "agains," and every one that is left is one you chose. 🪜 Where you are standing (Rungs 1, 2 & 3 should be completed) If not, you can find them here. They are in order and should be taken from series 1 to series 2 and so on: PROMPT ENGINEERING 📚 Series 1 Overview
WISE ARCHITECTS CORNER - The Fourth Rung Is Open - 🔁 Loop Engineering
1 like • 8h
@Jordan Shaw Lets Go!!!!
0 likes • 8h
@David Vogel Thank you my friend! ☺️🙏🤓
Jeff takes the win this week!
Congratulations to @Jeff Van Leenen ! Jeff already has Lifetime VIP, so this time he gets a 30 minute 1-on-1 call with Jake directly! ⏰ The 7-day clock resets. Next Monday someone new takes the top spot. 🎯 How it works: - 📝 Post things worth reading - 💬 Help people in the comments - 🛠️ Share what you're building, what's working, what's breaking - ❤️ Engage with what others are putting out there The leaderboard tracks all of it. 🎁 The prize, depending on where you're at: 🆓 Free member? You get lifetime Premium, free ⭐ Already Premium? We convert your Premium so you stop paying 👑 Already VIP? We convert your VIP so you stop paying 💎 Lifetime VIP? Get a 30 minute 1-on-1 with Jake. Either way, you stop paying.
0 likes • 12h
@Jeff Van Leenen congratulations! Well deserved! 🙌😊🏆
Is Claude Desktop with Cowork Secure?
Does anybody know just how secure the above setup is (on my Daily Mac machine)? Specifically, if I give it access to ONE folder in my Dropbox. • I use Dropbox on my Daily machine... that's what's making me a bit nervous. • My sensitive files are encrypted, but I still wonder what kind of "escaping" Claude Desktop/Cowork could do when I've unencrypted and mounted sensitive volumes also "Cowork runs inside a secure Virtual Machine (VM) on your computer (using the Apple Virtualization Framework on Mac). This means it can safely "mount" your local files to read, edit, and reorganize them without risking your entire machine." Source: https://www.lumetric.ai/resources/claude-web-vs-desktop-vs-code-vs-cowork Thank youuuu!!!
Poll
4 members have voted
1 like • 7d
Hi @Alessandra Turati sorry for the delay here!Short answer: the VM is a real safety layer, but it isn't a guarantee. It's worth setting things up so a failure wouldn't hurt you. What the VM does: In local mode, the agent runs inside a Linux virtual machine as an unprivileged user. Local file access is limited to the folders you've connected in the desktop app, and each local tool call is checked against those permissions. The caveat: In July, Accomplish AI researchers showed that a local session could exploit a Linux kernel flaw to get root inside the VM, and from there reach the Mac's filesystem through a writable mount. They connected one folder, and the agent then read and wrote files outside that folder without another permission prompt. That's close to your exact scenario. Anthropic rated the report as informative and didn't ship a specific patch. Note: the newer versions run in the cloud by default, so this local-VM escape is no longer the default path. A cloud session only reaches your local files through the desktop app, only for folders you've connected, and only while the app is online. What I'd do in your setup: - Close decrypted volumes first. Unmount them before running a session, especially one in local mode. That's the biggest risk in what you described. - Use a dedicated folder. Make a folder that holds only non-sensitive working files, and connect that instead of a broad Dropbox folder. - Skip Full Disk Access. Some Dropbox/OneDrive troubleshooting guides tell you to grant Claude Full Disk Access. That gives the app much wider reach than you need. - Know that changes sync. Anything Claude edits or deletes in that Dropbox folder syncs everywhere. Dropbox version history is your undo button. - Watch what it reads. Only have it read files you trust, since instructions hidden in a document can steer an agent. We learn together, we grow together, we win together. 🙌
1 like • 2d
@Alessandra Turati Great question. The honest answer starts with a caveat: you can't filter prompt injection the way you filter SQL injection. With SQL, there's a clean fix. Parameterized queries separate code from data, so the database always knows which part is a command and which is just a value. Untrusted input literally can't cross into the instruction channel. A language model has no equivalent, because it has only one channel. Instructions and data both arrive as text, and the model decides what to act on by meaning, not by structure. There's no syntax that marks something "data only, never obey it." In fact the UK's National Cyber Security Centre argues prompt injection may be harder to solve than SQL injection ever was. OWASP ranks it the #1 risk for LLM apps and says outright there may be no foolproof prevention. So you can't sanitize your way out — the goal is to contain it, not eliminate it. That means "watching what it reads" is really about containment. A few habits: Break the combo. An injection needs two things at once: the agent reads content you don't trust, and it can take actions that hurt you. Remove either one and the attack has nowhere to go. Read the unknown file in one session; do your trusted edits in another. Keep approvals on. Skip "Act without asking" “Bypass Permission” settings when untrusted content is involved. Each approval pause is your chance to catch something off. Watch the steps. If you asked for a summary and it suddenly wants to open other folders, send something, or delete files, stop. That mismatch is the tell. Never auto-approve deletions. The app asks before permanently deleting. Treat that as a real checkpoint. Limit the web. If it browses, allow only sites you trust — web pages and emails are the most common place for hidden instructions. Be picky about add-ons. Only install plugins from sources you trust; some run with far more access than the agent itself. Pre-screen. Skim outside files yourself first, or paste just the text you need instead of handing over the whole thing.
🥳Not a funnel. A room. 50k members, and Jake’s ICM got us there.
We just crossed 50,000 members 🎉. Today. Not a projection. Not a “coming soon” slide. That number broke because Jake showed up with ICM and actually shipped it into a room that doesn’t treat people like leads. The welcome here isn’t a drip sequence. It’s people answering questions, sharing the folder, and sticking around after the first win. Most communities rent attention. This one compounds it. Jake’s ICM didn’t land in a vacuum - it landed in a stack that already preferred transparent workflows over vendor theater. Members didn’t just buy. They stayed, tested, and pulled the next person in. From empty chairs to a milestone that pays people back. Stop chasing the next shiny cohort. Start owning the room that keeps grinding after the launch email dies. If you’re in, say what you got out of it. If you’re watching, the door’s still open.
🥳Not a funnel. A room. 50k members, and Jake’s ICM got us there.
1 like • 4d
@David Vogel
2 likes • 2d
@David Vogel It takes a village my friend!
My ideas kept dying in old chats... Now they come back when they fit.
A while back @Carla Bosteder was talking about ideas... This one stuck with me as I am constantly thinking about how I handle my ideas. I created an animation for fun, but kept thinking about what could be done with ideas while chatting in Claude. Unfortunately, most die in the chat they came up in. I'd been working on this for a while when I read @Bas Rosario on how he handles memory. There's some crossover with his idea, and it's a great one. It got me thinking more about how ideas connect to each other, and when an old one should come back. It's called the Idea Engine, and it plugs into Claude. The video is the 80 second version. The short version of what it does: 1. You float an idea while you're working on something else. Claude saves it in your words, with what you were doing and the date, and you keep going. 2. A small model checks that it really is an idea and not a task or a question before it's kept. 3. Later, when you're working on something new, an old idea that fits can come back with one line on why. Or you just ask, "what have I thought about pricing?" It's in testing on my own machine right now, with 148 of my ideas loaded. The testing is doing its job. Yesterday it missed every idea I had across a full day of chats, so the part that notices an idea is getting fixed before anyone else gets it. It goes out to a small group very soon. If you lose ideas the way I do and want to try it, let me know below. How do you keep track of your ideas now?
My ideas kept dying in old chats... Now they come back when they fit.
1 like • 3d
@Jeff Van Leenen 🏆 This is a great way to battle scope creep. In my experience my best ideas are always built with intention, and keeping my sessions scoped to their focus has proven to be a strong building habit for me. When I first started building with AI, I created a dashboard, the dashboard was accessible by my AI & I. After scoping out an idea, we would chunk a build into features, each feature got a check box on the dashboard, as we progressed through the build AI AND myself had to approve a task was completed, we would check off the tasks once we agreed it completed. The dashboard eventually evolved a "Parking lot" for the ideas that inevitably pop up while you're building! Inspiration does not have a date or time! I love this idea and think it will absolutely help with building, scope creep, follow through and ultimately development. ☺️💪🏆 Brilliant work here!
1-10 of 456
Bas Rosario
7
4,100 points to level up
@bas-rosario-6872
I’m a Husband and Dad, an IT Manager, AI Architect, AI Engineer, and Full Stack Developer. I love to help people so please Don’t be Shy! Say Hi!👋 😊

Active 7h ago
Joined Jun 10, 2026
INTJ
Southern California
Powered by