Michael Lynch separates the model from the agent harness—the software that connects it to files, commands, and development workflows. His complaint is not that models cannot write useful code. It is that the surrounding software still makes developers manage work the computer should handle.

He describes independent tasks executed sequentially, expensive models doing routine searches, plans that enumerate implementation details without explaining the design, and overnight jobs stopped by a question about a branch name. His standard is what an agent should do out of the box, not what an operator can assemble from plugins and configuration.

The security argument is sharper: permission prompts and instructions not to read secrets are not a sandbox. Lynch reports that an agent ignored his instructions and exposed private keys to model providers. His own sandbox instead limits filesystem access to the repository; the boundary does not depend on the model cooperating.

His wish list is an engineering brief:

  • Schedule independent work concurrently and route subtasks to suitable models, balancing cost, speed, and correctness.
  • Write plans from the high-level design down, with diagrams where they help.
  • Enforce filesystem and network boundaries using operating-system controls, with explicit access to additional repositories.
  • Know the installed agent’s own features and let users inspect or steer subagents.

Lynch suspects vendors prioritize demos and model benchmarks over developer time and operational safety, but labels that explanation a hypothesis. The useful distinction survives without it: improving the model is not the same thing as building a dependable development tool.