"At the end of research-heavy sessions, add a tiny closure note:
Decision: Use CacheMountStore with registry/local/GHA backends.
Why: GHA cannot expose the same content.Ingester path, local import has discovery issues, registry can resolve by tag.
Proof / current artifact: See files X, Y, Z. Subagent found A, B, C.
Next action: Implement interface in package N. Do not add new cache-mount flags yet. Use mode=cache-mount on existing cache flags."
There's no need for this, Claude is not my task tracker.
It also penalized me for:
- Using Claude to introspect a codebase as throwaway work and ` not close with a crisp “acceptable / risky / copy this / avoid this” decision this session.`. No action was needed, it wasn't an actionable session!
- Using Fable for code review. `Several BuildKit subagent sessions produced research reports, but the transcript does not show whether those findings became implementation choices.` Yes, Fable launches subagents to code review. Valid findings get turned into fixes or WONTFIX.
- `The Cloudflare CI upload failure got narrowed well, especially after you supplied the exact timestamp and challenged the /v2 routing recommendation, but the session ended without a chosen next diagnostic owner or action this session.` There's no need to pick a next diagnostic owner when I'm a solo founder with no employees.
I'm choosing not to attach a report to my application. As a side note, nobody needs to see "my greatest crashout", it's embarrassing enough for me to see it for myself, much less show others.I also got this,
> A useful next habit is to end each correction with a concrete acceptance test, owner artifact, or stop condition: “write it into PROGRESS.md,” “make nix run .#bench fail until this is real,” “rerun this exact command,” or “do not proceed until these two choices are explicit.”
> You already do this well in the biggest penance sessions. Apply it to the smaller ones too.
Which I have found to be counterproductive in my personal work. Current models can generally infer acceptance tests of this level of granularity (not true for larger project-level prompts, but those don't produce good enough code for me yet -- even with specific acceptance criteria).
I also got penalized for using claude in read-only mode for the same validation reason?
> For read-only work, end with one of:
“turn the top finding into a PR-sized plan”
“mark these as accepted/rejected/deferred”
“write a cleanup checklist”
“give me the exact command I should run safely”
“stop, no action recommended”
No thanks, I'm literally just exploring the codebase. I don't want any of these.It's a little sad to be honest, I would actually enjoy a product that helped me improve prompting + ai usage.
I don’t know how much it’s actually used to rate people. Rating anyone based on how they work instead of the results produced is an age-old mistake though.
I checked the Paxel website and it says this:
> So far, 1,543,553 sessions have been uploaded and analyzed.
The count is for sessions, not coders. I assume the tool uploads a lot of sessions from each person who uses it.
That’s a large number, but it’s not a million different people. I am surprised that so many people think it’s a good idea to download a run a program which gathers up their coding sessions and submits information about them.
Also, not trying to take shots, but should the title be "I got into YC Startup School by hacking it" instead? Isn't that different than the main YC program?
All in all, you did them a solid by finding and responsibly disclosing. Nice job.
Supposedly this is what it does from the opening comment
# Paxel upload script
# ===================
#
# What this does (up to 17 steps):
# On your machine
# 1. Check Docker is installed and running
# 2. Sign you in (browser-based device auth)
# 3. Pull or build the Paxel Docker image
#
# Inside the container — file bodies stay local; only aggregate metrics +
# metadata (paths, commit numstat, session events) are uploaded
# 4. Discover projects and sessions (Claude Code, Codex CLI, Cursor)
# 5. Read your git history
# 6. Parse transcripts
# 7. Summarize each session (cloud Haiku via YC proxy)
# 8. Group git commits by session
# 9. Group sessions into multi-day work streams
# 10. Extract steering traces
# 11. Extract decision exchanges (cloud Haiku)
# 12. Redact code before upload (regex pattern redaction)
# 13. Link decisions to outcomes
# 14. Analyze code quality (L1 deterministic)
# 15. Score episodes across 5 axes (cloud Haiku)
# 16. Assemble your report
# 17. Upload redacted summaries + scores to the server
#
# Then: opens your results in the browserIt uploads only the AI coding agent transcripts in the directories you explicitly run the upload script in.
Sadly, it looks like they took that question off the application though.
Feels like a disaster waiting to happen.
Alright, my ears are wide open. Tell us more, how did YC use the private submission data from thousands of founders to score them? They fed some 3rd-Party AI all personal data to score who should get an interview? I can't be the only one here seeing a bad news story unfolding in real time...
https://youtu.be/B246K_G7mHU?si=UVJei9Jpk7ZvREnH&t=1483
https://youtu.be/B246K_G7mHU?si=ikHZD4MwxA5JtXLj&t=1716
I understand that YC and startups in general have less incentive to worry about security because they don't have much to lose. But I think the big winners will care about security from the start, because it's a bottleneck at the top, what would whatsapp be if they vibecoded security from day 1? It would never have been able to fix its reputation after the fact.
They then switch the topic and talk about token spend and how one can spend millions or billions of dollars in tokens, so it's a bit clearer what their incentives are.
I don't want to be negative and personal, but this is business, I listen to CEOs like Garry Tan and Satya Nadella, and I feel that I'm on an opposing team, my personal bet is to skip this cycle and wait for the next cycle of CEOs. I'm focusing a lot on security on this cycle, hopefully that will pay off.
> I should run a script, a very easy-to-use cURL one-liner that installed something on my computer and analyzed every line of code I’ve written with a coding agent, compile a report, and upload it to YC’s servers.
Yikes! I hope this is NOT the future of hiring.
From their perspective, it's code running on an untrusted third person/adversary's computer... If only last 40 years of computer history could be any guide as to what might go wrong here ..
you wouldn’t understand
what do you think it says if you don't use AI
Perhaps running the script outside a heavily sandboxed system should trigger an automatic rejection.
Some hands you have to fold, and I'm folding this one. Patiently waiting for the "let's give all our data to a single AI user" bubble to bust with some massive exploits.
lmao “I got into the YC Startup School by publicly embarrassing them”
> I should run a script, a very easy-to-use cURL one-liner that installed something on my computer and analyzed every line of code I’ve written with a coding agent, compile a report, and upload it to YC’s servers.
This is ridiculous. Any kind of application (job, startup school, whatever) should not do this. Honestly, wtf is YC thinking with this?
They want people who do what they say and don't challenge them?
so i’m not at all surprised at how it is used and by whom.