I’m amazed at how rapidly guidance files such PHANTOM-B as are assimilated into the agentic harnesses. I remember seeing similar guidance files that gave elaborate instructions on writing unit tests along the code for instance, whereas in the current models, tests are written by default without explicit mentioning.
I was quite skeptical and projected that many security issues will be surfacing due to vibe coding, but perhaps this was only a limited window of time, where the next iteration of harnesses might actually be more mindful of mitigating cyber risks in output than we would previously get with our previous specific (global) prompts.