On 29 June, I asked Hermes to produce a personal website for me. Thirteen code files, 900 lines, and it displayed. I looked at it for two minutes and decided that was that. Three months later, only one of those thirteen files is untouched: the stylesheet, because I liked the colours. Every other one has been changed, some almost entirely, some by a few lines, and two have gone. The code now stands at 37 files and 3,435 lines: 58 commits, fifteen of them branch merges, spread over twelve actual working days.
What the demo didn't show
I took the project back on 19 July with Claude Code, and started with a security audit rather than the design. I was right to. The articles API and the admin page were public: anyone could create, edit or delete an article, no password required. Request bodies went straight into the database, so you could overwrite an existing article by guessing its ID, or slip in an image whose URL began with javascript:. And the public pages queried their own API through a localhost address written into the code. It worked on my machine. Only on my machine.
None of that shows on screen. That is precisely the problem. A demo that displays and an application you can put online are two different things, and the generator doesn't tell them apart, because nobody asks it to.
The bug that looked like a typo
The episode that cost me most was a sillier one. The admin password was stored hashed, and the hash used $ as a separator. The tool that reads the configuration file treats $xxx as a variable and replaces it with nothing. The hash went from 168 characters to 6. Result: no login possible, with an error message identical to a wrong password. I looked at my typing before I looked at the code. Bugs that pass themselves off as user error are the expensive ones.
Code ready, site empty
Online on 6 August, on a VPS. On the 15th, npm audit reported six vulnerabilities, five of them high, and the framework itself was among them: an upgrade, and the audit went to zero. Then a month without a single commit, from 16 August to 17 September. The code was well ahead of the content, and content is the one thing you cannot delegate.
Checking rather than believing
Two checks from September are worth mentioning. The privacy page promises that no full IP address is ever written down. I wanted to verify it rather than take it on trust, and I found two: one in the application's log when a bot was detected, one in the system log for requests sent straight to the server's address. Fixed the same day. The other: the text of my article on HORIZON, written with assistance, contained seven false statements once checked against the repository. A factor of ten that was really twenty-five, one Raspberry Pi instead of two, fourteen projects when there are now sixteen. Plausible, fluent, wrong.
What I would do differently
The security audit would come with the very first generated draft, not three weeks after it. Logging would be in place before going live: I lost ten days of traffic because the server wasn't recording anything. And I would test on a real phone from the start, rather than by shrinking the browser window.

The site now says "Real applications, built with AI". It had better be an example of one itself.