We’re already halfway through 2026, so I went back through everything I bought on Amazon this year. 75 orders total. Lined up like that, most of it turned out to be recurring supplement subscriptions, cat food, and ingredients for cooking at home — 10kg of soybeans, koji, kombu, dried shiitake, natto spores. Even I have to admit it’s a pretty plain lineup.
Once I set aside all the consumables and kept only the things I can genuinely say I’m glad I bought, it came down to four. The prices and categories are all over the place, but each one actually changed something about how I live. Here they are, in order.
This continues the story of switching my external brain’s search to semantic search. Last time, I noticed that keyword search on my vault was missing things, so I added local embeddings via Ollama for semantic search. Now even a vague query like “how did I set up gitleaks again” pulls up the right daily log.
That made pulling specifics much better. But as I kept using it, I noticed a different gap. There was no entry point for grasping the whole picture broadly.
I’d known for a long time that I needed to deal with duplicate and leaked passwords. It was just too tedious, so I kept looking away. When I finally braced myself and opened Chrome’s password checkup, this is what came back:
Compromised passwords: 40
Reused passwords: 132
Weak passwords: 109
329 in total. A number that makes you dizzy just looking at it. For a second I thought, I should’ve just left it alone. And going through the list, some of these were for services I’d already stopped using, or accounts I’d closed ages ago. So what’s the efficient, safe way to handle this? Here’s a record of the day I spent cleaning this up, and what I thought about along the way.
A while back I wrote about turning Obsidian into an external brain for Claude Code. The idea: Claude Code loses its memory across sessions, so I have it read and write a Markdown vault to carry knowledge forward. It’s still running fine.
But the more I used it, the more one weak spot stood out: recall was keyword search, full stop.
Step two of the read procedure I described in that post was “search the vault for keywords related to the question.” That step misses more than I expected. Daily logs, for instance, are named like メモ/2026-06-23.md — the date is the filename — so if I don’t remember when something happened, I can’t find it. “What did I do that one time” is exactly the query I most want to work, and it doesn’t, unless I remember the date. It’s also fragile to word choice. Search for “don’t grant too much permission” and it won’t match a note that says “許可” (permission) and “射程” (scope) instead — even though they’re saying the same thing.
Last time, I wrote about how I let Claude Code back up my dotfiles and it leaked a GCP key to GitHub. I closed that post by saying: assume mistakes will happen, put the safety net at the git layer, and carve the lesson into an external memory called mistakes.md so it gets ahead of the next one. Cheap tuition, I said.
The very next day, it pulled the same stunt again. Not the key leak this time — the unconfirmed push.
I built and use a tool that automatically turns YouTube videos, web articles, and local voice memos into Obsidian notes. It’s called obsidian-import, and what it does is simple: you hand it a URL or an audio file, it transcribes or extracts the body text, has claude -p (Claude Code’s one-shot execution mode) summarize and tag it, and writes the result out as a Markdown note.
I’d been using it happily, until one day it hit me: this tool ingests external content, feeds it to an AI, and writes files to disk. From entry to exit, untrusted input runs straight through the whole pipeline. As an attack surface, that’s about as exposed as it gets — not a great design. I decided to sit down and put it through a proper security review.
Last time, I wrote about turning Obsidian into Claude Code’s external memory. Riding that momentum, I decided to back up Claude Code’s own scattered settings next — the global config under ~/.claude/, each project’s .claude/, and my own scripts in ~/scripts/. None of it was under version control, so it would all vanish if the machine died.
I consolidated it into dotfiles and had Claude Code automate the whole thing. It promptly leaked a GCP service account key to my own GitHub repo. Here’s the screwup, the recovery I did on the spot, and the guardrails I built so it never happens again.
The most wasteful thing about using Claude Code, in my opinion, is that it loses all its memory the moment a session ends. Whatever tripped it up last time, whatever preferences I mentioned, whatever assumptions the project runs on — the second I start a new conversation, I’m explaining everything from scratch again. It’s brilliant, but it feels like calling a call center where you’re a stranger every single time.
In a previous post I wrote about youtube-to-obsidian. Since then I’ve wanted to turn PDFs and slide decks into notes the same way, so I wired in Microsoft’s MarkItDown to handle them. It’s no longer YouTube-only, so I renamed the repo to obsidian-import.
Now I can pull long academic PDFs, 100-plus-slide decks, lengthy blog posts, and TED talks into Obsidian as summary notes without reading or watching the whole thing. Instead of sitting through a one-hour video, I can skim a well-organized note in a few minutes. The input efficiency is on a different level.
Last time, I built a pipeline that automatically converts YouTube cooking videos into Obsidian recipe notes. It was just two scripts dropped straight into ~/scripts/, but it got me through 43 cooking videos. Since then I worked with Claude Code on a code review, added tests, set up CI, published it on GitHub, and eventually rebuilt it from a recipe-only tool into a general-purpose one. Here’s how that went.