Live data from Hacker News

ZCode – Harness for GLM-5.2

zcode.z.ai

271–280 of 382 posts

Re: ZCode – Harness for GLM-5.2

#271

Has anyone come up with a decent harness for small local models, say, gemma4 e4b? I'm trying to roll my own but man, the capability gap is real.

This is precisely what I've been working on targeting with https://dirge-code.github.io/ I've written up an explanation of what trips small models ups and how the harness can address that here https://yogthos.net/posts/2026-06-08-dirge-code.html

Very interesting work! I put some effort into getting it to work with models my hardware can actually run well and they just fall over immediately. gemma4 12b runs like molasses on my 2080 super but it was the only model able to, with your harness, actually do anything useful. It was the only useful thing I've gotten any model runnable with my hardware with any harness I've tried, very impressive!

I suspect smaller models need more work than is practical to fit harnesses around. The smaller the model, the more work, and it doesn't carry over to other small models.

Deepseek r1 7b could not emit tool calls to save its life, gemma4 e4b couldn't get the names of files right, qwen3.5 4b gets stuck in dumb rabbit holes, I pointed it at a ruby script and asked it to run it, it tried running it with bash then got caught in a loop investigating.

Noble effort though! I guess I'll keep working on my barebones ruby_llm harness, with very tempered expectations. Each of these failure modes can be worked around, but there's too many of them to work around in the general sense.

Re: ZCode – Harness for GLM-5.2

#272

Earlier quoted context omitted.

I don't run agents directly on my desktop/laptop machine. I run them in VMs or containers (sometimes in containers on VMs). There have been too many credentials stealing exploits via prompt injection and the like for me to be willing to let an agent roam around on my personal system. I've also started creating new github deploy keys for each repo in use on a VM, so the blast area for any given agent disaster is "a co…

Do you not find a dedicated UNIX user to be sufficient for the sake of protecting personal files, SSH keys, etc?

Agent that can apt-get is more useful.

Re: ZCode – Harness for GLM-5.2

#273

Earlier quoted context omitted.

Good desktop apps in this category can manage agents across any number of remote SSH hosts.

But, it's still running on my desktop/laptop. I don't trust them to run on my machine. But, I guess I could run one VM with a desktop to contain the desktop app. Or, just keep using CLI agents.

Do you also run your browser in the VM? Why would an agent be less trusted than any other piece of software?

Re: ZCode – Harness for GLM-5.2

#275

Earlier quoted context omitted.

Now, if only we can figure out what all the others are providing as part of their subscriptions we can compare. (Though 3 million tokens of the top model per day seems kinda low. But, I guess that's what the 5x plan is for. I'd still like to be able to compare against all the big providers.)

You can just track the tokens used in Claude Code and codex until you hit the limit?

Can you?

Re: ZCode – Harness for GLM-5.2

#276

Earlier quoted context omitted.

But, it's still running on my desktop/laptop. I don't trust them to run on my machine. But, I guess I could run one VM with a desktop to contain the desktop app. Or, just keep using CLI agents.

Do you also run your browser in the VM? Why would an agent be less trusted than any other piece of software?

I don't run anything but the agent and the project it's working on and the tools it needs to work on the project in the VM.

You can't see how the agent having no access to anything other than what it's working on is safer than the agent having access to my home directory with all of my credentials?

Look, you do whatever you want to do with your agents and your computer. I'm going to...contain them.

https://venturebeat.com/security/six-exploits-broke-ai-codin...

Re: ZCode – Harness for GLM-5.2

#279

I'm somewhat surprised that this is not open source (from what I can tell). Compare to Mimo Code https://github.com/XiaomiMiMo/MiMo-Code (which is a CLI, while this is a desktop app).

I don't even know what I would do with a desktop app. I'm running these things in headless VMs, so I can run them with `--dangerously-skip-permissions` or whatever. I don't trust them, even without that flag, on my desktop/laptop.

I shared your fear some weeks/months ago so I was always using my harness in the cloud. However, latency started to become an issue when I traveled to other countries where I needed a VPN... so I ended up cooking skynot to be able to trust running my harness in my own computer: https://github.com/tarsgate/skynot (PRs welcome if you want to add support for another harness different than Pi)

Re: ZCode – Harness for GLM-5.2

#280

Does anyone use an agnostic TUI or harness for development tasks that can fairly seamlessly switch between providers? I'm wanting local context in the spirit of "here are 3 AI providers available, for coding tasks use this one... and for writing prose use this one... and for generating images use this one..." etc.

If you haven't yet you should give a chance to https://pi.dev

I've been using it exclusively (and extending it, see https://a.l3x.in/ai) for months with mainly GLM-4.7 then 5.1 and now 5.2 and I could hardly be any happier.

I'm still working on a "Github/Forgejo first" based workflow but also quite happy with it already, basically most of my sessions run as a ci/cd job (triggered by "/pi" comments) and generate PRs or push commits to PRs, see https://github.com/shaftoe/pi-coding-agent-action

Post reply on HN