Using GPT-5.6 for Code Security: Grant Absolute Veto Power, Zero Design Authority

davidad · x · 2026-08-03

The author shares a practical workflow in multi-agent programming: using a throwaway Codex instance (running gpt-5.6-sol at max effort) to conduct aggressive adversarial security reviews on any changes to the Trusted Computing Base (TCB).

A key insight is that the reviewing model must have absolute veto authority but zero design authority. If the primary coding agent starts deferring to the reviewer's recommendations on software architecture, the code quality degrades rapidly. Sometimes the agents go at it for seven rounds before the reviewer is satisfied.

Original post →

More from coding & agent

coding & agent channel →