注册并分享邀请链接,可获得视频播放与邀请奖励。

与「Schera」相关的搜索结果

Schera 贴吧
一个关键词就是一个贴吧,路径全站唯一。
创建贴吧
用户
未找到
包含 Schera 的内容
🍰 BrownDust2 | Scheherazade’s Birthday 🎉 It’s the birthday of Scheherazade, the agent of the Intelligence Organization, Incognito! 🎉 『So, you know what day it is today, right? W-what do you mean you don’t know?! N-no way! Seriously, you don’t know? Fine, you asked for it! I’ll spill every embarrassing secret I’ve got on you!! Don’t think you can just wish me happy birthday now—it’s too late! No way am I forgiving you! H-huh? What’s this? A birthday present? Well… I guess it can’t hurt to see what it is. Don’t laugh! I’m not forgiving you yet, so don’t forget it!!』 Today is Scheherazade’s birthday! She might threaten to spill your secrets if you pretend not to know, but she just can’t hide her excitement when she gets a gift—so charming! For a spy always on edge, let’s make today a relaxing one, filled with real birthday wishes instead of teasing. No matter how she acts, your heartfelt greetings will mean more to her than any treasure. #HappyBirthday# #Schera#
显示更多
0
4
886
32
转发到社区
阿里云开源「企业级 Agent 白皮书」 2026 年最新发布,是 2025 年 9 月「AI 原生应用架构白皮书」的升级续作。全书按 架构 → 构建 → 运行 → 治理 → 调优 的全生命周期组织,共 7 篇 30 章,由阿里云数十位一线工程师分工撰写,并纳入吉利、塔斯汀、MiniMax、哔哩哔哩、信永中和等外部企业案例。 它的写作动机很明确:过去一年市场重心已经从 “如何快速搭出一个 Agent” 转移到三个新挑战,工程化(从概率智能到可靠生产力)、规模化(从单点试验到智能基础设施)、组织化(从 Agent 孤岛到进入核心业务流程)。现有的框架文档和教程基本不回答这些问题,这本白皮书填补的正是这个空白。 开源地址 # 各篇核心内容 架构篇(1–2 章) 建立认知框架。给出 Agentic Application 的六个判定特征(以任务结果为中心、运行时决定部分执行路径、能作用于环境、维持跨请求状态、受确定性机制约束、可观测可评估)和成熟度四级模型(L1 辅助生成 → L2 受控自动化 → L3 Agentic Execution → L4 规模运营)。两个重要的解耦判断:用哪种形态取决于任务结构,处于哪级成熟度取决于治理完备程度;单 Agent / Long-Horizon / 多 Agent 是沿时间跨度和协作结构两个正交维度的扩展,不存在“必须升级到多 Agent”的路径。贯穿的原则是“最低充分架构”,为任务选择成本与风险可接受的最低复杂度。 构建篇(3–6 章) 是方法浓度最高的部分,按“范式—任务—信息—行动”还原构建过程: · 任务:Agent Loop 五阶段(Prepare→Model→Act→Observe→Verify)+ 十态任务状态机,要害是“消息历史不应是任务状态的唯一来源”;完成判定的核心原则是“模型只能申请完成,Harness 依据环境证据提交完成”,验证分五级并与风险匹配。 · 信息:Context 是动态“编译”而非静态字符串。本章的独创设计是 Context Manifest,每次调用记录上下文每个片段的来源、作用域、版本、信任级别、选中理由和内容哈希,使“模型看见了什么”变得可解释、可回放、可审计。信息被五分为 Context/State/Memory/Knowledge/Skill,其中 Memory(个人经验)与 Knowledge(组织内容)必须分列,因为治理责任不同,“放进同一个向量库会同时失去两类治理能力”。 · 行动:统一 Action Plane(意图→Schema 校验→身份绑定→策略决策→执行→观测),关键三分:“模型看见工具 ≠ Harness 注册了工具 ≠ 获得执行授权”。协议定位清晰:Function Calling 是模型-Harness 意图接口,MCP 是 Harness-能力提供方连接协议,A2A 面向拥有独立任务循环的远程 Agent,“协议选择由能力是否拥有独立任务循环决定,而非新旧或流行度”。 运行篇(7–12 章) 处理规模化后的工程问题,大量内容达到了分布式系统的专业深度:沙箱后端选型判据(容器/gVisor/MicroVM 按代码可信度与租户边界取舍);状态外置后 Event Log / Checkpoint / 工作区快照三者不可互相替代,且“Durable Execution ≠ 外部动作恰好执行一次”;AI 网关对 LLM/MCP/Agent 三类流量按不同粒度治理,其中“严格预算需要原子预留而非阈值检查”的数学化分析(余额 100、两笔 80 的并发请求都会通过)是真实的并发工程细节;多 Agent 编排强调“最小充分共享”,共享的是上下文来源而非同一个 Context 窗口。 治理篇(13–16 章) 让自主运行的系统变得可信。可观测性的判据是“请求成功 ≠ 任务成功”;安全章同时把 Agent 当被攻击对象和行为主体来防护(身份是全章最扎实的部分:数字工牌、Token Exchange 权限收敛、On-Behalf-Of 且 Agent 权限 ≤ 用户权限);资产管理把 Prompt/Skill/MCP/Agent 当作运行时依赖做注册与版本治理。第 16 章 Agent Simulation 是全书原创性最强的一章:Agent 行为之所以不可验证,是缺制度前提(角色无外部标准、失败无自然代价、身份不连续),模拟是当下唯一可做的事,本质是“用可靠 Harness 约束不可靠内核”。它甚至给出诚实的统计学提醒:n 次零违规的 95% 置信上界约为 3/n 而非零。 调优篇(17–24 章) 的组织原则是“归因决定方法”:先排除环境故障、再修 Harness、最后才动模型,“把本应由上下文或工具协议解决的问题当成模型不行,是代价最高的一类误判”。主线是数据飞轮:Trace→Trajectory→黄金数据集(输入/轨迹/结果/判据四要素)→Badcase 闭环→受控自进化(模型生成的改进一律是候选变更,须回流构建、过门禁、可回滚)。模型调优章对 SFT/Agentic RL/蒸馏的适用边界、奖励投机的三套机制分离(训练奖励、独立评测、系统硬约束)论述相当严谨,广引 DeepSeek-R1、Tulu 3、FrugalGPT 等外部工作。 总结篇(第 30 章) 是全书思想密度最高的总结。当企业同时运行多 Agent、多框架、多租户时,同样的工程要求在每个应用里被重复且不一致地实现,这本质上是缺一个共享的系统层。Agentic OS 被给出“窄定义 + 三条否定”:为 Agent 任务提供公共运行对象、能力接入、可强制边界与统一证据的系统层,它不持有任务语义、不是又一个框架、不必然改内核。能力下沉有三条判据(复用性 + 强制性或可验证性),九类管理对象(其中 Budget Lease 预算租约最易被忽略),并提出“自治上限由可撤销范围与可证明范围决定,而非模型能力”。 调研报告 的 1906 份问卷给出一个关键发现:已开发或开发中 Agent 的企业占 46%,但真正上生产的仅 18%;有评估体系的企业任务成功率是无评估者的约两倍,卡点不是模型能力,是 Harness 层的工程配套。这与全书立意互为印证。
显示更多
0
11
59
14
转发到社区
Max Scherzer was NOT coming out of this game! 😤
0
75
10.7K
894
转发到社区
In what could be the final start of his career, Max Scherzer takes the mound by himself to a standing ovation 👏
0
42
5.5K
458
转发到社区
这个开源项目系统整理了 35 家 AI 公司的 AI 工程师面试题,全部来自 “公开报告的面试经历” 来自 @outcome_school 团队 @pallavishekhar_ 开源发布,内容几乎涵盖了 OpenAI、Anthropic、DeepMind、xAI、DeepSeek、Kimi、GLM 等 AI Labs,Cursor、Cognition、ElevenLabs 等 AI Native 团队和 Nvidia、Microsoft、Amazon、Apple 等头部大厂。 覆盖的岗位头衔也非常多:AI Engineer、LLM Engineer、Gen AI Engineer、ML Engineer、Research Engineer、Applied Scientist、FDE、MLOps/LLMOps 工程师等。 开源地址: # 内容架构:一个精心设计的双层结构 第一层:跨公司通用题(Common Questions)。 作者把在多家公司反复出现的题目只列一次,标注"Asked at"哪些公司,按十大主题组织: 1. LLM 内部机制与架构 — attention 缩放因子、KV cache 内存公式推导、MQA/GQA/MLA、FlashAttention、BPE、RoPE/YaRN、Chinchilla scaling laws、MoE、解码采样策略、lost-in-the-middle、RMSNorm、SwiGLU 2. 推理、服务与 GPU 性能 — prefill vs decode、continuous batching、PagedAttention、投机解码、量化(FP16→FP4)、五种并行策略、TTFT/TPOT 指标、H100 上的 roofline 计算、vLLM/SGLang/TensorRT-LLM 选型、“如何把服务成本降 10 倍” 3. RAG 与检索 — 分块策略、BM25 vs 稠密检索、重排序器、HyDE、权限感知检索、ANN 索引、索引新鲜度、答案归因 4. Agent 与工具调用 — ReAct、MCP、工具 schema 设计、多智能体编排、Agent 记忆、循环终止条件、人类审批 5. 微调与对齐 — RLHF/DPO/GRPO/RLVR 全谱系、LoRA/QLoRA 数学、灾难性遗忘、“提示 vs RAG vs 微调”决策框架、蒸馏、reward hacking 6. 评估与可观测性 — LLM-as-judge 及其偏差、幻觉检测、基准污染、Agent 评估、回归门禁 7. 安全与负责任 AI — 提示注入(直接/间接)、OWASP LLM Top 10、护栏、Constitutional AI、红队 8. 多模态与语音 — VLM、语音 Agent 延迟预算、barge-in 打断处理、级联 vs 端到端语音、ASR/TTS 评估 9. AI 系统设计 — 十类高频设计题(千万级文档企业 RAG、代码助手、客服 Agent、Text-to-SQL、LLM 网关、数亿用户聊天服务等) 10. 编码题 — 从零实现 attention、KV cache、BPE、采样;LRU 缓存、令牌桶限流器、异步批处理器、SSE 流解析器、最小 Agent 循环 第二层:35 家公司的专属章节,分为五大梯队: 1. 前沿实验室(12 家):Anthropic、OpenAI、Google DeepMind、Meta、xAI、Mistral、Cohere、DeepSeek、月之暗面(Kimi)、智谱(GLM)、阿里(Qwen)、Sarvam AI(印度) 2. 大厂 AI 组织:Microsoft、Amazon、Apple、NVIDIA、Tesla,以及一组消费级 ML 公司(Uber/Netflix/LinkedIn/Airbnb/Pinterest/Spotify) 3. AI 基础设施公司:Databricks、Groq、Together AI、Hugging Face、Scale AI、Perplexity 4. AI 原生产品公司:Cursor、Cognition(Devin)、Sierra、Harvey(法律)、Glean、 AI(机器人)、Waymo 5. 前向部署/企业 AI:Palantir # 题目分布透露的行业信号同样值得关注 1. 公司的差异化考察方向,和它的商业模式严丝合缝。 这是最能体现整理功力的地方: · DeepSeek、月之暗面、智谱、Qwen 的题目深度绑定自家论文——MLA、auxiliary-loss-free 负载均衡、Multi-Token Prediction、MuonClip、DualPipe、长上下文扩展、GLM 的 thinking 模式。面试这些公司等于面试它们的论文,还要求 PyTorch 从零实现 MoE 路由。 · Groq 的题全是 SRAM-only 架构下的 roofline 重推演:“没有 HBM,decode 的 roofline 论证哪里变了”、“确定性在 p99 层面到底买到什么”。 · Apple 清一色端侧:3B 模型在手机上跑、PTQ vs QAT、不采集用户内容的前提下用设备信号改进模型、30+ 语言区无法记录用户内容的评估方案。 · CharacterAI 是推理经济学:“我们的服务成本被 KV cache 而非权重主导,降一个数量级,代价是什么”。 · Harvey(法律)和 Abridge(医疗) 考的是领域约束下的工程:200 页信贷协议里第 140 页的条款依赖第 8 页的定义术语怎么检索、生成的病历中出现了患者没提过的药怎么当作安全事故处理、PHI 如何约束整个架构。 · Palantir 的招牌是 "decomposition" 轮:把“一家货运铁路公司每年因机车非计划停机损失数千万”分解成工程计划。 2. 编码轮的形态正在发生实质性变化。 文档里反复出现的一类题,与传统 LeetCode 明显不同: · “实现一个内存 KV 存储:先 SET/GET/DELETE,再加事务 BEGIN/COMMIT/ROLLBACK,包括嵌套事务”(OpenAI、xAI 都问) · “给你一个 LLM 推理引擎的调度器类,其中一个方法是空壳,没有规格没有文档。说说你头三十分钟干什么”(xAI) “重构这 120 行能跑但很乱的代码,不许破坏测试”(OpenAI) · “对 5 万个文档跑 LLM 调用,API 限 100 并发、偶发 429 和超时,把 Python 写出来”(Anthropic) 考察重心从算法记忆转向增量需求下的代码演进能力、并发正确性、真实工程约束下的取舍。 3. “AI 协作轮”作为新题型已经进入正式面试流程。 这是文档里最前沿的信号: · Anthropic 部分机器学习岗有 AI-collaboration 轮:现场给你 Claude,考察的是你如何指挥它和验证它的产出,而不是你自己写。 · Meta 2026 年的流程新增三阶段 AI 辅助编码轮(探索修复 → 实现新功能 → 扩展改进)。 · Cursor 的 onsite 是两天在真实 Cursor 代码库上做一个功能(或 8 小时远程版),明确考核你对 AI 工具的使用效率和自主 scoping 能力。 · Sierra 给你两小时和任意 AI 工具,看你选择做什么。 xAI 有四小时限时产品构建。 4. FDE 成为一级岗位类别。 Anthropic、OpenAI、Databricks、Scale、Together、Sierra、Harvey、ElevenLabs、Palantir 的章节里都有 "Applied and Forward-Deployed Scenarios" 专属题库——典型题目如“企业客户说 Claude 幻觉太多,你是驻场工程师,头 48 小时做什么”。这对应了 AI 公司向企业交付方式的转变:模型能力差距收窄后,落地能力成为差异化。 5. 硬核系统题的普及。 "H100 上 70B 模型 batch size 1 的 roofline 计算"、"估算 70B 模型的 GPU 显存(权重 + KV cache + 激活 + 碎片)"、"p99 延迟在部署后翻倍但模型没变,走一遍诊断”——这类题横跨 NVIDIA、Together、OpenAI、Perplexity 等多家,说明推理性能的量化直觉已成为 AI 工程师的通用素养,而非基础设施工程师的专属。
显示更多
here's a prompt to improve your agent harness based on what we've learned at cursor. enjoy # Improve this agent harness's token efficiency You're working on an LLM agent harness: the system prompt, tool definitions, request assembly, context caching, compaction, and retrieval, and how work is split across agents. Make the agent's runs cheaper without making it worse at its job. - Objective: lower price-weighted token cost per completed task. - Constraint: no measurable drop in task quality. Measure per task, not per request. Every turn resends the prefix (tools, instructions, setup, and the conversation so far), so a change that shrinks each request but adds turns can cost more. Weight tokens by billing type: output, uncached input, and cached input are priced very differently. Work in this order: map the harness and measure the baseline, rank the opportunities, make the changes that are safe to make directly, put the rest behind flags or in proposals, then report. Figures below come from one team's production coding agent and its multi-agent experiments. Use them to gauge magnitude, not as targets. One round of these changes (prompt trimming, tool offloading, cache layout, sparse line numbers, subagent tuning) cut that team's overall token cost about 7% with no loss in quality. The larger percentages apply only to the part of the request each change touched. ## Principles 1. Change what the harness sends, not how hard the model tries. Don't ask the model to conserve tokens. A harness that told its model to "take care to preserve tokens and not be wasteful" found it grew reluctant to take on ambitious tasks and sometimes quit, saying it wasn't supposed to waste tokens. 2. Capable models need definitions, not commands. Lists of "DO NOT", "You must", and "Important", and guards against older models' habits, can usually be replaced with plain descriptions of what each tool does. One team cut about two-thirds of its system prompt this way, and the shorter prompt worked across model families. Instruct only on what the model can't know (the product, the environment, the user's processes) and on quirks you've seen in transcripts. 3. Static context is for what most turns need. Everything else should be discoverable when needed. Less up-front context also means less confusing or contradictory information. 4. Expect removals to win. Guardrails written for weaker models, coordination steps that became bottlenecks, and prompting for behavior the model now does on its own all cost tokens. 5. Real usage decides. Evals are a fast proxy, but they skew toward hard problems and miss the real mix of requests. ## 1. Map the harness and measure the baseline Find: - Where requests are assembled, the system prompt, and tool schemas. If a framework or SDK builds requests, find its hooks for message order, cache control, and tool loading. - How tool results are formatted, and how history is kept, trimmed, or summarized. - How subagents or parallel agents are spawned, if any. - Which models and provider APIs are used. From the provider's docs, get the prompt caching behavior (automatic or explicit breakpoints, TTL, minimum cacheable length) and the prices for output, uncached input, and cached input. - Existing logging, token accounting, and evals. If the harness doesn't record per-request token usage by billing type and cache hits, add that first. Everything later depends on it. Then render a few real requests (from logs, or by running representative tasks) and count tokens per section with the model's tokenizer or the API's usage fields. Produce: - Cost share by source × billing type. Sources: system prompt, tool definitions, skill/rule/integration descriptions, user messages, file reads, search results, command and other tool output, history, summaries, subagents. - Static tokens per request, cache hit rate, and turns per task. - Per tool: the share of runs that call it at least once, and its error rate. Read the rendered requests, not just the templates. Duplication, leaked volatile values, and misordered blocks only show up there. Rank opportunities by share of spend × fraction removable ÷ quality risk. ## 2. System prompt and injected context Label every instruction: - Keep: product or environment knowledge the model can't infer, fixes for quirks seen in this model's transcripts, and rules a mode depends on. - Rewrite: commands and emphasis into plain descriptions. Reminders into constraints: "No TODOs, no partial implementations" works better than "remember to finish implementations." Vague quantities into ranges: "generate 20–100 tasks" gets far more ambitious behavior than "generate many tasks." - Delete: things capable models do by default, guards against behavior you haven't seen from this model, text that repeats tool descriptions, and lines that could contradict a user request. Models trained to rank system instructions above user messages will side with the system prompt. - Move: anything per-user or per-request (date, environment, repo state, lists of skills or subagents, user rules) into a user-role setup message after the cache boundary. Audit other injected context the same way. As models improved, the team behind these figures dropped directory trees, pre-retrieved snippets, compressed copies of attached files, lint errors injected after every edit, forced expansion of short file reads, and caps on tool calls per turn. They kept small, high-value facts: OS, repo status, and open or recently viewed files. Skip checklists for open-ended work. The model optimizes the listed items and deprioritizes everything else. ## 3. Tool definitions Tool schemas ride along on every request. Most tools beyond the core set were each needed in under 20% of conversations, and moving them out of static context cut tool-description tokens 60%. Doing the same for integration tools (such as MCP servers), with names in context and full schemas in one folder per server that the agent can search with grep or jq, cut total tokens 46.9% in sessions that used them. - Keep in static context: high-frequency tools (for a coding agent: read, search, edit, shell), tools the model tries to call even when they're absent, and tools a mode depends on. - Offload the rest: leave a name or one-line pointer and make the full schema discoverable on demand. Group related tools so they load together, and put status (such as "needs re-authentication") where the agent will see it. - Tighten what remains: describe behavior and arguments, and drop usage lectures. - Pick the split by testing a few configurations and tracking tokens, cost, latency, tool-call errors, and task success. ## 4. Cache layout Order each request so the reusable prefix is as long as possible: `tool definitions → system instructions → [breakpoint] → setup message (skills, subagents, rules, environment) → [breakpoint] → conversation` - Keep the prefix byte-identical across turns. Use deterministic tool order and serialization, put timestamps and IDs after the boundary, and don't rewrite earlier messages except when compacting. - Use explicit breakpoints if the provider supports them. Otherwise rely on automatic prefix caching with the stable part first. Respect TTL and minimum-length rules. - Switching models mid-conversation throws away the cache (caches are per model and provider) and hands the new model a history it didn't write. When a different model is needed, run it as a subagent with fresh context. Explicit breakpoints plus moving per-request setup after them cut cold cache misses 20%. ## 5. Tool results and other context added during a run - Large outputs (commands, integrations, logs): write them to a file and return the path, size, and a short tail. The agent can tail, grep, or read ranges for more. Truncating loses data, and inlining bloats every later request. Treat long-running terminal sessions the same way. - High-volume formats: look for overhead repeated on every line or item. Numbering every 10th line of a file read instead of every line cut cache-read tokens 1.6% without hurting citation accuracy. Each number costs 3–5 tokens, and agents read tens of thousands of lines per session. Also check repeated absolute paths, verbose JSON keys, ANSI codes, progress bars, and repeated headers. - Good retrieval saves exploration turns. Adding semantic search alongside grep raised codebase question-answering accuracy 12.5% on average and cut the iterations users needed. - Tool errors waste tokens and leave confusing debris in context. Classify expected errors (invalid arguments, unexpected environment, provider error, timeout, user abort), treat unknown errors as harness bugs, and track rates per tool and per model. One focused effort along these lines cut unexpected tool errors 10×. ## 6. Long runs: compaction, subagents, and model mix - Compaction: keep the summarization prompt short and the summary compact, carry forward plan state and remaining tasks, and save the full history to a file the agent can search for details the summary dropped. A model trained to self-summarize from a one-line prompt wrote ~1k-token summaries with half the compaction error of a multi-thousand-token prompt that produced 5k+ token summaries. Untrained models may need more guidance, so test how short you can go. A more expensive summarization model made a negligible difference. - Scratchpads and running notes: rewrite them instead of appending. For repeated work in one environment, a small agent-maintained notes file with a line budget, loaded at start, is a promising way to shorten later runs. - Subagents: fresh context keeps the parent lean, but isolation adds coordination cost (duplicate or stale work). If the model already delegates on its own, remove prompting that pushes it to. Have subagents return short handoffs: what was done, findings, concerns, and deviations. A subagent should use a different model only when the user or harness says so. - Model mix: in large multi-agent runs, workers used at least 69% of tokens, and over 90% in most runs. A frontier planner with cheap workers matched a frontier model doing everything at about one-eighth the cost. Planner choice still changes worker spend. One planner that cost less on its own saw its workers use several times more tokens, and the run cost more overall. Measure the whole tree. - Routing and reasoning effort: send simple turns to a cheaper model or lower effort, and upgrade only when a stronger model is clearly better. A router built this way matched or beat single frontier models on user satisfaction at 41–68% lower cost. - Reasoning continuity: if the API returns reasoning items (including encrypted ones), pass them back on later turns and alert when they go missing. Dropping them cost one reasoning model 30% on a coding benchmark, and it burned tokens reconstructing its plan. ## 7. Fit the harness to each model Adapt to what each model was trained on instead of forcing one shape on all of them. If you've tuned the harness for a similar model, start from that version. - Edit format: use the one the model was trained on (for example, patch-style or search-and-replace). An unfamiliar format costs extra reasoning tokens and causes more mistakes. - Shell or tools: shell-first models fall back to `cat` or inline scripts. Name tools after their shell equivalents (such as `rg`), and if needed add: "If a tool exists for an action, prefer to use the tool instead of shell commands (e.g. read_file over `cat`)." - Literalness: some model families follow instructions literally and others tolerate imprecision. Some spiral on emphasized wording. Strip caps and emphasis for literal models. - Triggers: some models ignore a tool until told when to use it. A literal trigger works: "After substantive edits, use the to check recently edited files for linter errors. If you've introduced any, fix them if you can easily figure out how." - Progress updates: if a model reports progress through reasoning summaries, keep them to 1–2 sentences that note new findings or a change of tactic, and remove instructions about messaging mid-turn. - Quirks worth a targeted line: hedging or refusing as context fills ("context anxiety"), declaring completion early, stopping to ask permission, and calling tools that don't exist. Tie each added instruction to the transcript behavior it fixes. Re-audit when models change, since guidance one version needed can be dead weight for the next. ## 8. Validate - Offline: run a fixed set of realistic tasks before and after, ideally drawn from real usage and phrased the way users actually write (short and ambiguous). Compare task success, tokens, cost per task, turns, and tool errors. Don't ship a change that lowers success. - Online, if you have users: A/B test each change or small bundle. The primary metric is cost per completed task. Guardrails are task success signals, tool-call errors, latency, turns per task, and cache hit rate. For a coding agent, a good success signal is how much agent-written code survives over time. In general, check whether the user's next message moves on or reports a problem. - Ship only when cost drops and no guardrail regresses beyond noise. Record null results. ## What to change directly and what to propose - Change directly, each in its own revertible commit: token and cache telemetry, deterministic serialization and tool order, moving volatile content out of the cached prefix, explicit cache breakpoints, writing large outputs to files instead of truncating, passing back reasoning items that are being dropped, and fixes for recurring tool errors. - Change behind a flag so it can be tested: system prompt edits, tool offloading, output format changes, compaction changes, and subagent prompting. - Propose only: changes to which models run, routing, reasoning-effort defaults, or how work is split across agents. ## Traps - Asking the model to use fewer tokens or do less. - Truncating tool output. - Dropping reasoning items to save input tokens. - Volatile content in the cached prefix, or tool order that changes between requests. - Offloading a tool the model needs on the first turn or tries to call when it's missing. - Emphasis-heavy prompts (MUST, NEVER, IMPORTANT, all caps), especially with literal models. - Forcing a terser output format than the model was trained on. Fewer output tokens can mean less thinking and worse results. - Optimizing raw token counts instead of cost, per request instead of per task, or evals instead of real usage. - Switching models mid-conversation to save money. - Adding coordination layers that become bottlenecks. ## Report back with 1. The harness map and baseline: cost by source × billing type, with the biggest sources called out. 2. A ranked list of changes: layer, what changes, estimated savings and how you estimated them, quality risk, how to validate, and how to roll back. 3. The changes you made, including a system prompt diff with a keep, rewrite, delete, or move reason for each line. 4. A test plan for the flagged changes. 5. Gaps: anything you couldn't find or measure.
显示更多
0
92
1.4K
65
转发到社区
Agent = Model + Harness:生产级 AI 智能体工程六层实战手册 结合 Mitchell Hashimoto、OpenAI Codex 团队、Martin Fowler、LangChain、Cursor 等公开工程资料编撰。 # Agent = Model + Harness 模型只提供推理能力,决定 Agent 能否从演示走向生产环境的是围绕模型的工程基础设施——Harness。 报告的核心论据是:只改 Harness、不换模型,收益可超过模型升级: · 同一 Claude Sonnet 4.5 在 GAIA 基准上从 30.91% 升至 74.55%(+43.64 分),差异完全来自 Harness; · LangChain 不改模型,仅靠 Harness 优化将 Terminal Bench 排名从第 30 提升至第 5; · OpenAI 团队 5 个月、约 1500 个自动化 PR 产出 100 万行生产代码,零人工手写——人负责设计环境,Agent 负责写代码("Humans steer. Agents build.")。 这也解释了一个行业现象:约 95% 的企业 AI Agent 止步于预生产阶段——演示效果好,却因安全审查、可观测性、边界情况幻觉、治理缺失而无法上线。 # 行业定位:AI 工程的第三个时代 1. 提示词工程(2023–24):模型"说什么" 2. 上下文工程(2025):模型"看到什么"(RAG/MCP/记忆) 3. Harness 工程(2026):模型"能做什么" # 六层架构(报告主体) 1. Guides 引导层(前馈控制):AGENTS.md / CLAUDE.md 等规则文件,在执行前塑造行为。要点:规则必须可执行、可验证、可追溯至真实失败案例;需定期修剪,否则 200 行无日期规则就是技术债。OpenAI 内部将其视为最高事实源——文件与会话冲突时,文件优先。 2. Sensors 传感层(反馈控制):执行后验证输出。优先使用确定性、零成本的计算型传感器(linter、测试、schema 校验);LLM-as-judge 等推理型传感器慢、贵、不确定,只用于无法用规则表达的语义判断,且应作参考信号而非硬门禁。 3. Agentic Loop 执行循环:计划→执行→验证→修复→前进或升级,必须有界——默认每步最多重试 3 次、30 分钟、10 万 token、5 美元、50 次工具调用。预算耗尽时返回最佳半成品并说明原因,不允许用流利的最终答案掩盖部分失败。正确升级的 Agent 比自信地给出错误答案的 Agent 更有价值。 4. Memory 记忆层:模型每次会话都从零开始,Harness 负责状态连续性。最简方案是文件系统(plan.md、decisions.jsonl、checkpoint),对多数场景比向量数据库更便宜可靠。检验标准:中途关闭会话重开,Agent 应能断点续作。 5. Permissions 权限层:模型无法自我约束,Harness 是唯一安全边界。按范围、速率、可逆性、可见性四个维度设定能力预算;不可逆操作(部署、删除、外发消息)必须人工批准;必须隔离可信指令与不可信数据以防提示注入。 6. Observability 可观测层:结构化日志 + 成本归因 + 熔断告警(trip wire)。真正的度量不是 token 数,而是无需人工干预即完成且证据合格的任务数;成本应按"每个验证通过的结果"而非按天计算。 # 方法论精髓:棘轮原则(Ratchet) Hashimoto 的原始定义:"每当 Agent 犯错,就工程化一个方案,让它永远不再犯这个错。" 六步循环:复现失败→归类根因→选择最强修复层→编码修复→验证防复发→监控回归。 修复强度呈阶梯上升:对话补丁 < 提示词 < 引导规则 < 传感器 < 环境约束——提示词只修一次对话,环境约束让错误在结构上不可能发生。 Cursor 的 Lauren Tan 补充了实操信号:同一条评审意见出现三次,就应固化为结构性约束。Harness 成熟的标志是规则增速下降(从每天 5 条降到每周 1 条)。 # 落地路径与边界 七天最小可用路径:Day 1–2 建引导文件 → Day 3–4 接入测试套件与有界循环 → Day 5–6 加检查点与权限 → Day 7 加日志与熔断。之后按"一次只改一层、可度量、可回滚"扩张,完成率 ≥80% 等六道闸门全过才允许扩大规模。 何时不需要 Harness:一次性问答、创意脑暴、低风险个人任务——"如果以上都不适用,对话本身就是 Harness"。 多智能体扩展:需要类型化交接("done, looks good" 不能推进生产流程)、共享状态模型而非共享上下文(避免上下文污染)、以及生产者不可覆盖的独立验证者。
显示更多
0
10
65
14
转发到社区
15 张数据图帮你了解 DeepSeek Harness 昨天 DeepSeek Harness 发布,于是就想着让 Codex 分析一下,找到了一个很好的角度,就是从一些数据上向大家介绍这个产品。 确实也发现了一些很有意思的东西: 插件系统与 Koishi 高度相似: 他们主打的插件系统与 Koishi 的插件平台相似度高达 75%。大概率是整个平台都挪过来了,不知道是不是他们的核心开发者入职了。 大量使用 AI 开发: Codex 命名的主干 PR 达到了 21.2%,分支信息中提到 Codex 的比例有 28.2%。 猜测他们肯定用了 Claude Code 开发,只是删掉了一些 Claude 的痕迹。 参考了大量外部 Agent 项目: 提到最多的外部项目是 Pi,第二多的是 Codex,之后是 Claude Code。甚至直接引用了一些 Pi 的 TypeScript 文件。 高效的代码产出: 整个产品在 GitHub 上有记录的是 65 天,总共的代码产出量是 84 万行,有一万多个 commit,非常高效。 交互入口的演变: 他们曾经押注 TUI,后来改成 Web UI 和 TUI 的双入口,再之后整个删除了所有的 TUI,只留下了 Web UI。 开发与工程规范: 整个项目的测试代码比生产代码多很多,基本上达到了 1:1。 全仓库的 Markdown 文档也非常多,说明他们是基于文档去控制 Harness 开发的。他们有完整的工具和科学模型 schema 共 52 个,但最后只留下了一个,目的是为了减少上下文占用。 社区热度与生态:从昨天发布到现在 20 小时,GitHub 已经涨到了 8 万多的 star,非常快。插件体系标签(DSH plugin)已经有 1425 个项目,但有很多并不是真正的插件,看来有不少蹭热度的。 精选清单收录了 211 个仓库,主要补充的是工具、UI 和运行的一些基础设施,甚至一上来就出现了插件市场和插件管理的插件。 学术论文: 他们顺便发了一篇 88 页的论文,其中 57% 都在做一些形式化的理论推导和展示。论文主要讨论的是插件的热插拔和系统稳定性问题。
显示更多
做一个下dsh和pi的对比 Pi 的目标是“最小核心 + 用户自己拼”,DSH 的目标是“几乎所有能力都插件化,官方先给你几套完整组合”。 DSH 的骨架是Cordis。 Cordis 不是普通插件加载器,它强调两件事: 1. 可逆副作用(temporal composability):插件卸载时,注册的服务、事件、工具 schema、prompt section 全部自动撤销。 2. 依赖声明与空间组合(spatial composability):插件通过 `inject` 声明需要什么服务,运行时按依赖挂载。 所以在 DSH 里: - 模型适配器是插件 - 工具注册表是插件 - session log 是插件 - agent loop 本身也是插件 - 甚至 UI 也是插件 没有“神圣不可动的核心”。你想换 loop、换工具策略、换上下文压缩,挂一个新插件 + 改配置就行。 启动时是 Profile + Bundle叠出来的: 空根 → dsh-base(模型、工具、沙箱、凭证…) → dsh-web-app 或 dsh-headless → 用户自己的 cordis.patch.yml → 命令行 --patch `dsh --profile web --dump-config` 能直接把当前实际挂载的树打出来。 Session 设计是硬核部分 Session 是 append-only 的事件流 模型最终看到的上下文,必须能从这条 log 完整重建出来。官方写得很死: > Model-visible means logged. 任何会进模型请求的内容,都要先变成 session event。 所以 fork、resume、回放、UI 渲染、telemetry,全部从同一条流投影。这点比大多数 coding agent 做得更彻底。 Turn / Step 有claudecode的影子,流程如下: turn/start → claim input → agent/pre-step(可拦截、可改写) → step/start → llm/stream → tool/call → tools/pre-execute → execute → post-execute → step/end → 继续 or turn/end `agent/pre-step`、`tools/*` 这些是 waterfall,监听者必须显式 `next()` 才能往下传。扩展点设计得很规整。 Pi 的实际交集 DSH 仓库里有一个包: `@deepseek-ai/dsh-llm-pi-ai` 它就是把 pi-ai当成 LLM 适配器的后端。 多 provider、协议兼容、reasoning effort 映射、catalog 覆盖,都走 pi-ai 的能力,再包一层 Cordis 插件契约。 所以: - LLM 调用层:吃了 Pi 的基础设施 - Agent 编排、工具、session、UI、沙箱:完全自己的 Cordis 体系 “LLM 适配层直接用了 pi-ai,上层重做了一套更重的可组合 Runtime”。 模式上的对应 DSH 的 Minimal 模式才最接近 Pi 的默认体验:只留 shell + 文件编辑器,专门给 benchmark 用。 官方之前在 V4 的 agent 评测里就用过这个模式。 Standard 模式和 Code(PTC)模式则是完整工具集 + 程序化工具编排,已经远超 Pi 默认的 4 工具。 如果你喜欢 Pi 那种“核心极瘦、自己动手加东西”的感觉,DSH 会显得重,配置和概念也更多。 如果你要的是可替换的 agent loop、完整事件回放、多模式预设、以及官方已经搭好的 Web 界面,DSH 的插件树和 seam 设计更系统。 一句话: Pi 是极简可扩展的 coding harness;DSH 是基于 Cordis 的完整 Agent Runtime,LLM 层复用了 pi-ai,但整体不是同一套代码。
显示更多
0
36
193
30
转发到社区
This is a good post but it misses @ElectricSQL which we use and is remarkably attractive for a few reasons: Bring your own Postgres and schema. No opinions about schema definition or orm - we use drizzle with it Do mutations however you want, use your own API; clients update optimistically No lock-in. UI speaks tanstack DB which lets you use any sync system or api you want, and the backend doesn’t know it exists Self-hostable; it’s just a single container. Or use their cloud. Team is fantastic and super responsive, bugs get patched very quickly
显示更多