// Seminar · AI-assisted programming
AI – Your peer programmer
GitHub Copilot, Claude Code & OpenAI Codex — how to use them well, and when not to.
Kaveh Bakhtiyari · TechWeek · 2026
web embed
// Warm-up
Quick show of hands
01
Used an AI tool to write code?
02
Shipped AI code you didn't fully understand?
03
Been confidently lied to by an AI?
All three? You're in the right room. None yet? Even better — you'll start with good habits.
// The next 2 hours
Where we're going
01 · 18 min
Foundations
What an LLM is and how agents work
02 · 8 min
The toolbox
Copilot, Claude Code and Codex
03 · 9 min
Prompt engineering
How to ask for what you need
04 · 8 min
Context engineering
What the model sees, and why
05 · 28 min
Building blocks
Prompts, agents, MCP, skills + demo
06 · 15 min
Workflow & specs
Spec-driven dev, tests, review
07 · 6 min
Guardrails
Do's, don'ts and security
08 · 5 + 15 min
Wrap-up & Q&A
30-day plan, then your questions
// 01 · Foundations
What is an LLM, anyway?
L
Large
Billions of learned numbers, called parameters.
L
Language
Trained on text and code: books, docs, public repos.
M
Model
A huge math function: text in, next-token odds out.
HOW ONE IS MADE
01 · PRE-TRAINING
Reads a vast library and learns to predict the next token.
02 · TUNING
Learns to follow instructions and hold a conversation.
03 · FEEDBACK
People and automated checks reward helpful, correct answers.
04 · TOOL USE
Learns to call tools: read files, run commands, search.
// 01 · Foundations
A very well-read autocomplete
→
Predicts the next token from patterns in huge amounts of text and code.
→
Knows nothing about your project unless you show it.
→
Sounds just as confident when it's wrong.
web embed
// 01 · Foundations
Tokens and the context window
Token
A chunk of text, often part of a word. Models read, write — and bill — in tokens.
Context window
Everything the model can “see” at once: its short-term working memory.
When it fills up
Older parts are summarised or dropped — details get lost.
No memory between chats
A new session starts blank — unless it's written down in a file.
web embed
// 01 · Foundations
Brilliant at some things, bad at others
Great at
Common patterns and boilerplate
Explaining and summarising code
Translating between languages
Drafting tests, docs and regexes
Weak at
Anything after its training cutoff
Your private code and business rules
Exact maths and long logic chains
Saying “I don't know”
Same prompt, different answer. Verify, don't trust.
Hallucination = a fluent, confident answer that is simply made up — a function, a package, a fact.
// 01 · Foundations
From autocomplete to teammates
2021
Copilot preview
AI autocomplete arrives in the editor
2022
ChatGPT
Chat becomes the way people ask for code
2023
Chat in the IDE
Ask questions about the code you're looking at
2025
Agents
Claude Code, Codex and Copilot agents edit, run and test
Now
Teams of agents
Parallel and background tasks; you review results
The shift: from typing faster → to delegating and reviewing.
// 01 · Foundations
Three ways AI helps you code
Autocomplete
You type. It suggests.
BEST FOR
Boilerplate, repeated patterns, finishing your thought
YOUR JOB
Accept only what you would have written
Chat
You ask. It answers.
BEST FOR
Explaining code, decoding errors, exploring options
YOUR JOB
Question the answer before you paste it
Agent
You delegate. It acts.
BEST FOR
Multi-file changes, refactors, tasks with tests
YOUR JOB
Scope the task, approve actions, review the diff
// 01 · Foundations
How an agent actually works
It's a loop, not magic. The model reads, plans, acts and checks — and repeats until the job is done or it needs you.
Every step is a tool call you can see — and approve.
web embed
// 01 · Foundations
Vibe coding vs. AI-assisted coding
Vibe coding
“just go with the vibes”
AI-assisted coding
“the AI types, you engineer”
Read the code?
Rarely. If it runs, ship it.
Every line, before it's merged.
Who designs?
The AI picks the approach.
You plan; the AI proposes.
When it breaks
Paste the error back and hope.
You debug it — you understand it.
Proof it works
“Looks fine when I click around.”
Tests, types, linters and review.
Great for
Prototypes, hackathons, throwaway scripts, personal tools.
Production code, teams, anything with users or their data.
Both are legit. The danger is not knowing which one you're doing.
// 02 · The toolbox
Three tools, one idea
GitHub Copilot
Claude Code
OpenAI Codex
Made by
GitHub (Microsoft)
Anthropic
OpenAI
Lives in
VS Code, JetBrains, GitHub.com, CLI
Terminal, IDEs, desktop app and web
Terminal, IDE, ChatGPT and cloud
Superpower
Inline suggestions + tight GitHub integration
Deep, agentic work across a whole repo
Parallel cloud tasks in sandboxes
Memory file
copilot-instructions.md
CLAUDE.md
AGENTS.md
Great first use
Autocomplete and chat while you learn
Multi-file changes, refactors, debugging
Well-scoped tasks you hand off and review
// Tool 1 of 3
GitHub Copilot
The assistant that lives inside your editor — and on GitHub.
BEST FOR
Learning as you type, quick questions, PR reviews
Inline suggestions
Ghost text as you type. Tab to accept, Esc to ignore.
Copilot Chat
Ask about selected code: /explain, /fix, /tests.
Agent mode
Multi-file edits and terminal commands, right in VS Code.
Coding agent
Assign it a GitHub issue, get a pull request back.
Code review
Request Copilot as a reviewer on your pull requests.
Custom instructions
Teach it your team's conventions once, in a file.
Tip: there's a free tier, and verified students can get Copilot Pro free through GitHub Education.
// Tool 2 of 3
Claude Code
An agent that works in your terminal and understands your whole repo.
BEST FOR
Multi-file changes, refactors, debugging, learning a new codebase
Terminal-first
Also in VS Code, JetBrains, the desktop app and the web.
Reads your repo
Searches, opens files and runs commands to get context.
Plan mode
Proposes a plan before touching any code (Shift+Tab).
CLAUDE.md
Project memory: commands, conventions, gotchas.
Subagents & skills
Delegate side research; package reusable workflows.
Hooks & MCP
Auto-run linters; connect GitHub, Jira, databases.
Tip: run /init in a project to generate a starter CLAUDE.md — then edit it by hand.
// Tool 3 of 3
OpenAI Codex
A coding agent in your terminal, your IDE — or the cloud.
BEST FOR
Well-scoped tasks you can hand off, several at a time
Codex CLI
Open-source agent that runs locally in your terminal.
IDE extension
Works in VS Code and VS Code-based editors.
Codex cloud
Many tasks in parallel, each in its own sandbox.
AGENTS.md
An open, shared format for agent instructions.
Approval modes
Choose read-only, auto, or full access.
PR reviews
Mention @codex on a pull request to get a review.
Tip: Codex is included with paid ChatGPT plans — you can start cloud tasks from the web or your phone.
// 02 · The toolbox
The wider ecosystem
Tools change every month. The habits in this talk work with all of them.
Cursor
AI-first code editor built on VS Code
Windsurf
Agentic IDE with a built-in agent
Gemini CLI
Google's open-source terminal agent
JetBrains AI
Assistant and the Junie agent in IntelliJ IDEs
Cline
Open-source agent extension for VS Code
Aider
Git-native pair programmer in the terminal
Zed
Fast editor with built-in AI agents
Local models
Open models on your own machine, e.g. Ollama
Pick one. Learn it deeply. Then compare. Don't tool-hop.
// 03 · Prompt engineering
Anatomy of a good prompt
ROLE
Who it should act as, or what the code is.
TASK
One clear verb: add, fix, explain, refactor.
CONTEXT
Files, errors, background it can't know.
CONSTRAINTS
Limits, rules and what not to touch.
FORMAT
What the answer should look like.
EXAMPLE
A pattern to copy beats a paragraph of rules.
ONE PROMPT, SIX PARTS
ROLE · You're a senior Node.js dev on this API. TASK · Add rate limiting to POST /login. CONTEXT · Middleware lives in src/middleware/.   Redis is already set up in src/lib/redis.ts. CONSTRAINTS · No new dependencies.   Max 5 attempts per IP per 15 minutes. FORMAT · Plan first, then the diff, then how to test. EXAMPLE · Follow the style of src/middleware/auth.ts.
You don't need all six every time. For a quick question, task + context is often enough.
// 03 · Prompting
Vague prompt, vague code
VAGUE
“fix the bug in the login”
It guesses which bug, which file, and what “fixed” means — then “fixes” something, confidently.
SPECIFIC
Users get a 500 error logging in when their email has uppercase letters. Repro: POST /login {"email":"[email protected]"} Look at: src/auth/login.ts, users table Expected: emails match case-insensitively. Constraints: don't change the DB schema. Verify: add a failing test first, then fix.
Context
+
Goal
+
Constraints
+
How to verify
// 03 · Prompt engineering
Six techniques that work everywhere
Plan first
“Propose a plan and wait for my OK before editing.”
Ask me first
“Ask me clarifying questions before you start.”
Show an example
One or two samples of what you want beat long rules.
Think it through
“List possible causes before changing any code.”
Name the format
“Answer as a table / a diff / a checklist.”
Iterate or reset
Refine in small steps. Lost? Start fresh with what you learned.
In every tool: @ or # to attach context · / for saved commands · a plan or ask mode
// 04 · Context engineering
Context engineering
Prompting is what you ask. Context is everything the model sees while it answers.
Write it down
Rules, plans and notes in files the agent can re-read.
Select
Only the relevant files, docs and tools.
Compress
Summarise long history — or start a fresh session.
Isolate
Split big jobs across subagents or separate chats.
web embed
// 04 · Context engineering
What to feed the machine
The exact error
Full stack trace and logs — not “it doesn't work”.
The right files
Point at them: @-mention, open tabs, or paths.
The goal
What does “done” look like? Be concrete.
Constraints
Versions, libraries, style — and what not to touch.
An example
“Follow the pattern in orders.ts.”
A way to check
A test, a command, or the expected output.
Switching tasks? Start a fresh chat (or /clear). Stale context confuses the model.
// Common ground
Give your AI a README
One file, loaded every session
copilot-instructions.md · CLAUDE.md · AGENTS.md
Keep it short
Commands, conventions and no-go zones. Not an essay.
Commit it
The whole team — and every agent — benefits.
Grow it
Same mistake twice? Add a line.
  AGENTS.md
# shop-api ## Commands - Install: npm ci - Test: npm test - Lint: npm run lint ## Conventions - TypeScript strict — no `any` - Validate input with zod - Tests live next to code: *.test.ts ## Never - Commit .env files or secrets - Edit /migrations by hand - Add a dependency without asking
Bonus — MCP: one plug-in standard all three tools support, for connecting GitHub, Jira, databases and more.
// 05 · Building blocks
The vocabulary, in one slide
Model
The LLM itself. Predicts the next token.
Prompt
What you ask for, in one message.
Instructions
Standing rules, loaded every session.
Tool
One action it can take: read, run, search.
Agent
Model + tools + instructions, in a loop.
Subagent
A helper agent with its own clean context.
MCP
A standard plug for adding tools and data.
Skill
A folder of know-how, loaded when relevant.
Analogy: the model is a new hire's brain. Instructions are the onboarding doc, tools their laptop, skills the team playbooks, MCP the badge that opens other systems — and the agent is the new hire actually doing the work.
// 05 · Building blocks
Instructions vs. reusable prompts
ALWAYS ON
Instructions file
Standing rules the agent reads at the start of every session.
Copilot  .github/copilot-instructions.md Claude   CLAUDE.md Codex    AGENTS.md
ON DEMAND
Prompt file / slash command
A saved prompt you run by name when you need it: /write-tests
Copilot  .github/prompts/*.prompt.md Claude   .claude/commands/*.md Codex    ~/.codex/prompts/*.md
EXAMPLE · write-tests.prompt.md
--- description: Write unit tests for a file --- Write tests for the given file: happy path, edge cases, errors. Don't change the code.
// 05 · Building blocks
Agents, custom agents, subagents
Agent
=
Model
+
Tools
+
Instructions
+
Loop
Built-in agent
Agent mode: reads, edits, runs and tests.
Custom agent
A named role with its own rules and tools.
Subagent
A helper with a fresh context; returns a summary.
Cloud agent
Works in a sandbox, then opens a PR for you.
EXAMPLE · a custom “reviewer” agent
--- name: reviewer description: Reviews diffs for bugs   and security issues tools: [read, search]  # no edit, no shell --- You are a strict reviewer. Never edit files. List issues by severity, with file and line.
Least privilege: give each agent only the tools it needs.
// 05 · Building blocks
MCP: a USB-C port for AI
→
An open standard (Anthropic, 2024), now supported by all three tools.
→
A server offers tools, data (resources) and prompt templates.
→
Set up once per tool: .vscode/mcp.json, claude mcp add, or ~/.codex/config.toml.
!
Only install servers you trust: they get real powers.
web embed
// 05 · Building blocks
Skills: know-how, loaded on demand
A SKILL IS A FOLDER
.github/skills/release-notes/ ├── SKILL.md ├── template.md └── scripts/collect_commits.sh
Instructions plus optional scripts and templates. An open format used by Claude Code, Copilot and Codex — folder names vary by tool.
SKILL.md
--- name: release-notes description: Drafts release notes from merged PRs.   Use when asked for a changelog or release notes. --- 1. Run scripts/collect_commits.sh <last-tag> 2. Group changes: Features, Fixes, Breaking 3. Fill template.md; one user-facing line each
1 · AT START
Only the name and description sit in context.
2 · WHEN RELEVANT
The task matches, so the agent reads SKILL.md.
3 · IF NEEDED
It opens extra files or runs the scripts.
// 05 · Building blocks
Prompt vs. skill vs. tool vs. MCP
PROMPT
What you want
TRIGGERED BY
You, every time you ask
EXAMPLE
“Fix SHOP-142 and add a test.”
SKILL
How we do it here
TRIGGERED BY
The agent, when the task matches
EXAMPLE
bugfix-playbook: repro → test → fix
TOOL
What it can do
TRIGGERED BY
The agent, step by step in its loop
EXAMPLE
read_file · grep · run_tests
MCP
Where it can reach
TRIGGERED BY
The agent, via a server you install
EXAMPLE
jira.get_issue · github.create_pr
They stack: one prompt can trigger a skill, which uses tools — some from MCP.
// 05 · Building blocks
One request, all four at work
web embed
// 05 · Cheat sheet
Which building block do I need?
I want to…
Use
Loaded
Set rules for every session
Instructions file
Always
Repeat a task I trigger myself
Prompt file / slash command
When you call it
Give the agent reusable know-how
Skill
When the task matches
A specialist with limited powers
Custom agent / subagent
When picked or delegated
Reach GitHub, Jira, a database…
MCP server
Tools called as needed
Run a check after every edit, always
Hook (where supported)
On events, automatically
// Live demo · ~8 min
Let's build something.
From a GitHub issue to a reviewed pull request — with an AI agent doing the typing.
01
Explore — “explain this repo”
02
Plan — agree on the approach
03
Build — code plus tests
04
Verify — run it, read the diff
05
Ship — small commit, clear message
// 06 · The workflow
The workflow that works
01
Explore
Have it read and explain the code. No edits yet.
02
Plan
Agree on the approach. Challenge it. Edit the plan.
03
Code
Small steps, one task at a time. Let it run the tests.
04
Verify
Read the diff. Run it. Try to break it.
05
Commit
Small commits, clear messages. You own it.
Skip steps 1–2 and you'll pay for it in step 4.
Verify fails? Go back to Code — or all the way back to Plan.
// 06 · Spec-driven development
Write the spec. Then let it build.
VIBE CODING
prompt → code → “hmm, not quite” → prompt → code → …
SPEC-DRIVEN
spec → plan → tasks → code + tests → review
1 · spec.md
What & why
Users, goals, acceptance criteria. No tech yet.
2 · plan.md
How
Architecture, data model, stack, risks.
3 · tasks.md
Steps
Small, ordered, each one testable.
4 · implement
Build
Agent works task by task; you review.
The spec is the source of truth — code is its output.
// 06 · Spec-driven development
What a good spec contains
Problem and users — who needs this, and why
Acceptance criteria — testable, Given / When / Then
Constraints — security, performance, rules
Out of scope — what we are not building
Open questions — flagged, never guessed
specs/password-reset/spec.md
# Feature: Password reset ## Why Locked-out users contact support (~40/week). ## Acceptance criteria - GIVEN a registered email, WHEN I request   a reset, THEN I get a link valid 30 min - Links work once; old links are rejected - Unknown emails get the same message ## Constraints - Max 3 requests per hour per account ## Out of scope - SMS reset, security questions ## Open questions - [NEEDS CLARIFICATION] Log users out   of other devices after a reset?
Tip: ask the AI to draft the spec and to list what's unclear — then you decide.
// 06 · Spec-driven development · example
From spec to plan to tasks
specs/password-reset/plan.md
# Plan: Password reset - Stack: existing Express API + Postgres - New table password_reset_tokens   (token_hash, user_id, expires_at, used_at) - Store only a SHA-256 hash of the token - Email via the existing mailer service - Rate limit: reuse middleware/rateLimit.ts - Risk: email enumeration → same reply
specs/password-reset/tasks.md
# Tasks - [x] T1 Migration: password_reset_tokens - [x] T2 POST /auth/reset-request + tests - [ ] T3 POST /auth/reset-confirm + tests - [ ] T4 Expiry + single-use checks + tests - [ ] T5 Rate limit 3/hour + test - [ ] T6 Email template + docs Each task: one PR, tests first.
DRIVING IT WITH ANY AGENT
1 › “Read specs/password-reset/spec.md. Draft plan.md. Don't write code.” 2 › “Split plan.md into small tasks, each with its tests. Save as tasks.md.” 3 › “Implement T3 only. Run the tests. Tick it off in tasks.md.”
// 06 · Spec-driven development
SDD in practice
GitHub Spec Kit
Open source. Works with Copilot, Claude Code, Codex and more.
/speckit.specify /speckit.plan /speckit.tasks /speckit.implement
Spec-first IDEs
e.g. Kiro: generates requirements, design and tasks files.
requirements.md design.md tasks.md
Do it yourself
Any agent + plan mode + a few markdown files in the repo.
specs/<feature>/spec.md specs/<feature>/plan.md specs/<feature>/tasks.md
USE IT FOR
Multi-file features, unclear requirements, team work, anything that takes more than a day.
SKIP IT FOR
One-line fixes, quick spikes, throwaway prototypes. Watch for spec drift.
// 06 · Tests
Tests keep the AI honest
1
Describe the behaviour as a failing test.
2
Review the test yourself — it is the spec.
3
“Make it pass. Don't change the test.”
4
Run the whole suite, not just the new test.
web embed
// 06 · Review
Review it like a stranger's PR
Do I understand every line?
If not, ask it to explain — or don't merge it.
Does it actually run?
Run the tests and the app yourself. Don't trust “Done!”.
What about edge cases?
Empty, null, huge, unicode, slow network, two users at once.
Is it secure?
Input validation, auth checks, SQL injection, leaked secrets.
Are the packages real?
AI can invent package names. Check the registry and maintainers.
Did it stay in scope?
Look for changes you didn't ask for: config, deps, deletions.
// 07 · Guardrails
The do's
Start small
One function, one bug, one test at a time.
Give context
Files, errors, goals, constraints, examples.
Ask “why?”
Make it explain its choices and alternatives.
Keep tests green
Run them after every change, not at the end.
Commit often
Easy to roll back when it goes sideways.
Write it down
Keep your instructions file up to date.
// 07 · Guardrails
The don'ts
Don't paste secrets
API keys, passwords, customer data.
Don't merge the unknown
Can't explain it? You'll debug it at 2 a.m.
Don't “yes to all”
Read what it wants to run before approving.
Don't argue for an hour
Reset, re-scope — or write it yourself.
Don't skip review
AI code needs more scrutiny, not less.
Don't skip learning
Struggle first, then compare with the AI.
// 07 · Security
Security: the non-negotiables
Follow your company's policy
Only approved tools and plans for work code.
Keep secrets out
.env in .gitignore, secret scanning on, no keys in prompts.
Watch for prompt injection
Files, web pages and issues can hide instructions aimed at the AI.
Least privilege
Start agents in ask or read-only mode. No production credentials.
Verify every new package
Attackers register names that AIs hallucinate (“slopsquatting”).
You are accountable
“The AI wrote it” won't work in a post-mortem.
// 08 · For juniors
Learn with it, not instead of it
The 15-minute rule
1
Try it yourself first, for about 15 minutes.
2
Then ask the AI for a hint or an explanation.
3
Rewrite the solution in your own words.
LEARNING-MODE PROMPTS
“Explain this function line by line, like I'm new to TypeScript.”
“Give me a hint — not the answer.”
“What would a senior reviewer criticise in my code?”
“Quiz me with 3 questions to check I understood.”
“Why this approach? What are the alternatives?”
// 08 · For experienced devs
Multiply, don't abdicate
Delegate the tedious
Boilerplate, test scaffolding, migrations, docs, one-off scripts.
Run agents in parallel
Separate, well-scoped tasks in git worktrees or cloud sandboxes.
Use it as a reviewer
A tireless first pass on every PR catches the boring bugs.
Codify team knowledge
Shared instruction files, prompts and skills lift the whole team.
Measure honestly
Track rework and bugs, not just speed. Feeling faster isn't being faster.
// 08 · Wrap-up
Your 30-day starter plan
WEEK 1
Autocomplete
Turn on inline suggestions. Accept only what you'd have written.
WEEK 2
Chat to learn
Have it explain unfamiliar code and errors. Hints, not answers.
WEEK 3
First agent tasks
Small bug fixes with a test. Plan, code, then review every line.
WEEK 4
Make it yours
Write your instructions file. Save the prompts that worked.
Then share it: what worked, what didn't, with your friends.
// If you remember one thing
The AI types. You engineer.
Context in
Plan first
Tests as proof
Review everything
The tools will change next month. These habits won't.
Keep learning
GitHub Copilot docs
Claude Code docs
AGENTS.md format
Model Context Protocol
// Thank you
Questions?
No question is too basic — somebody else is wondering the same thing.
Kaveh Bakhtiyari · www.kaveh.ai