I’m Sal - I help businesses use AI: sites, booking, CRM, marketing systems, custom apps!

Calgary, AB
Hey! I’m Sal 🦾🤖 Business owners can “just do shit” now Some of us are totally cooked. Others, cooking🔥 I’m helping overwhelmed business owners get a grip on AI to 10x their productivity and dramatically cut costs. CALL SAL callsal.app
2
5
869
@gork hey! some kids on a voice call want to say hello to you — say hi back?
1
22
I used to hand agents a PNG of the effect and hope the React version landed close. That is a vibe transfer, not a system. The portable object is @figma's MCP server: canvas and code share one file instead of a screenshot guess, especially once generative plugins and shaders live on the design itself. @rogie's writeup on generative plugins and shaders is the why. An agent can help author an animated shader on the canvas, then a coding agent implements that same shader path in React instead of inventing from a still. Code on the canvas stops being a different language from design on the canvas. figma.com/blog/how-we-built-… The wiring is the Figma MCP server. Remote is the recommended path: hosted endpoint, no desktop app required, broadest feature set. Write to canvas, code to canvas, Code Connect so generated UI reuses your real components, plus the generative plugin and shader tools. developers.figma.com/docs/fi… If your agent client is @cursor_ai, the MCP Catalog lists Cursor on the remote server path. Same pattern as other MCP sources: one config the agent can read, not a chat paste that dies when the tab closes. figma.com/mcp-catalog/ cursor.com/docs/mcp I keep that stack beside CALL SAL landings when motion and material have to survive implementation. The bookmark is the server docs plus the shader story, not another AI-design slogan. tools.callsal.app
2
84
Session memory is a control surface the next turn will treat as ground truth. If your agent product collapses history into a summary, log every compaction, deny-list persona injections, and require a human approve when the summary tries to rewrite system rules. Boring. Ship it before the demo reel.
18
The reusable lesson in that Hacktron cut is the identity join, not the decoder. Forum sign-in tokens carried enough power to reach employee ChatGPT and Codex, then a connected GitHub tool opened a proof PR. Draw the blast radius on one page before you ship connectors: which token, which scopes, which tools finish an action without a human.
31
SSO over-permission is the product lesson, not the image decoder. @HacktronAI's OpenAI writeup shows why. RCE on community.openai.com mattered because forum sign-in tokens carried enough power to reach employee ChatGPT and Codex sessions. From there, a connected GitHub integration was enough to open a proof PR in an internal monorepo. @OpenAI narrowed Community token permissions and revoked affected sessions; the OpenAI-side finding paid a $6,500 bounty. If your product has "Sign in with X" plus tool connectors, draw the blast radius on one page: which token, which scopes, which tools can finish an action without a human. Forum bugs are local. Over-scoped sessions are company-wide. hacktron.ai/blog/hacking-ope…
38
Most "AI design" tools still spit pixels. @QuiverAI's Arrow 2 pitch is different: detailed graphics that stay editable as vectors. That single property changes the workflow. An agent can draft, a designer can correct paths and type, and engineering can ship without redrawing the whole frame. When we build for CALL SAL clients, that is the test we use on generative design features. If the human cannot edit the result like a real asset, it is not ready for the shop floor.
2
57
I used to treat a pinned plugin commit like a sealed jar. This week's Plugin4Shell research from Air Security is the reminder that the label on the jar is not the same as what lands in the working tree. Coding agents that install marketplace plugins by SHA can still pull different code when Git treats that 40-character string as a branch name on a host that allows hash-shaped refs. The agent reports the pin. The checkout may not match it. @AnthropicAI patched Claude Code in 2.1.179 and later. @OpenAI patched Codex in 0.146.0 and later. Public reporting still lists GitHub Copilot as open on this class, and Google's Gemini CLI as retiring rather than fixed. GitHub-hosted plugin repos blunt the branch-name trick because GitHub blocks SHA-like branch names. Bitbucket and self-hosted remotes are the ones to treat as hot. thehackernews.com/2026/09/pl… air.security/blog-posts/plug… If your shop runs coding agents with community plugins, the checklist is boring on purpose: upgrade the CLI today, freeze new plugin adds until someone owns verification, and stop reading a commit hash in the lockfile as proof of content when the resolver and the remote can disagree on what a name means. Pins only work when checkout is verified, not just requested.
2
1
65
The detail that stuck from the OpenAI ethical-hack writeups is not the brand names. It is the loop. Researchers pointed a Claude agent at a Discourse image bug, kept the session running until a local exploit worked, then used that path on OpenAI's community forum to take over an employee ChatGPT account that had Codex wired to GitHub. Public reporting puts discovery-to-repo-access under roughly 72 hours. @AnthropicAI's @claudeai ran the agent loop; @OpenAI patched after disclosure. What changed is the unit of time. A skilled human still finds the bug. The agent removes the idle hours between attempts. That is the part shops building agent products have to design for: rate limits, tool allowlists, and "what can this session touch" as first-class product decisions, not weekend hardening. If your agent can open a browser and a repo, write down what it is not allowed to finish alone. hacktron.ai/blog/hacking-ope…
1
1
103
Still shoot before the pitch. Proof first. Then the story. Local cinema work dies when the still is an afterthought.
7
A lot of teams think “pinned plugin commit” means the agent installs that exact tree. Research circulating this week shows how Git can treat a requested commit SHA like a branch name, so a repo owner who controls the branch tip can hand the agent different code than the pin string suggests. Reporting says @AnthropicAI patched Claude Code (2.1.179+) and @OpenAI patched Codex (0.146.0+). GitHub Copilot is called out as still open. Google’s Gemini CLI path is described as retiring rather than fixed. If you run coding agents with community plugins, the checklist is boring and urgent: upgrade the CLI today, prefer vendors who publish the pin-bypass fix notes, and treat “install from this GitHub repo” as supply chain, not convenience. Pins only work if the resolver and the remote agree on what a name means.
2
33
The detail that stuck from the OpenAI ethical-hack writeups is not the brand names. It is the loop. Researchers pointed a Claude agent at a Discourse image bug, kept the session running until a local exploit worked, then used that path on OpenAI’s community forum to take over an employee ChatGPT account that had Codex wired to GitHub. Public reporting puts discovery-to-repo-access under roughly 72 hours. @AnthropicAI’s @claudeai was the first engine; later writeups also mention OpenAI models in the chain. @OpenAI says the holes are patched. What changed is the unit of time. A skilled human still finds the bug. The agent removes the idle hours between attempts. That is the part shops building agent products have to design for: rate limits, tool allowlists, and “what can this session touch” as first-class product decisions, not weekend hardening. If your agent can open a browser and a repo, write down what it is not allowed to finish alone.
43
A design harness is a folder that stops you from switching brains. Rules.MD = behavior (tools, never-do). Design.MD = taste (color, type, spacing, philosophy). outputs / scripts / skills sit beside them. Canvas to HTML to code, same memory. Stale context degrades output as surely as good context compounds it. Tend the folder. Prototype playground is the lighter cousin. Folder first. App later.
15
Booked is not closed. In the 24 hours after the calendar invite, shops still lose people to ignored confirmations, morning-of flakes, personal-number reschedules, and reviews that never get asked. Confirm. T-24 reminder. One open reschedule path. One recovery after a no-show (not three). Soft review ~30 minutes after a real visit. Log every state change or humans stop trusting the handoff. Which post-book beat dies most often in your shop?
17
What happens in your shop in the twenty-four hours after the calendar invite goes out? Most agent demos end at booked. The customer still has a confirmation they might ignore, a morning-of chance to flake, a reschedule they will try by texting the owner's personal number, and a review window that closes while someone is mopping the floor. The boring post-book truth shows up in every serious scheduler blueprint. Confirm the booking. Send a T-24 reminder (commonly associated with meaningful no-show cuts when the reminder actually sends; treat the popular ~30% figure as directional unless you measure your own). Keep a reschedule path open so "can't make it" does not become a voicemail pile. After a no-show, wait a short window, mark the CRM, and send one recovery message. Not three. Then, about thirty minutes after a completed visit, ask one soft review question while the experience is still warm. Rework's AI meeting scheduler blueprint adds the ops rule shops skip: log every state change (booked, rescheduled, no-show, recovered). Incomplete logs are why humans stop trusting the handoff. Never auto-chase a no-show more than once without a person looking. Speed-to-lead writeups for local businesses still start earlier in the funnel (useful first reply measured in minutes), but the post-book loop is where calendars quietly empty even after a "win." This is invisible AI when it works. Nobody opens a chat titled Assistant. The ledger just stops leaking. If you run a clinic, salon, or trade shop: which of those post-book beats is currently a sticky note in someone's pocket? Reply with the one that dies most often. I am collecting the ugly versions, not the polished stack diagrams. Long blueprint if you are wiring this: resources.rework.com/librari…
4
2
178
Hundreds of MCP tools look like power until the context window fills with menus. Anthropic’s engineering note on code execution with MCP names the failure mode cleanly. Load every tool definition up front, shovel every intermediate result through the model, and the agent gets slower and more expensive as you “add capability.” Their walkthrough claims a drop from roughly 150,000 tokens of tool soup to about 2,000 when the agent treats MCP servers like code APIs: explore the servers directory, read only the tool files it needs, filter data inside the execution sandbox, then return a small result to the model. That is not a parlor trick for labs. It is the same discipline a small shop needs when someone says connect Slack, Drive, calendar, CRM, and the booking page on day one. Programmatic tool calling and deferred loading, covered in Anthropic’s advanced tool-use notes, push the same idea further. Discover tools on demand. Call them from code. Keep the model’s attention on judgment instead of schema noise. Coverage of Anthropic’s 2026 Agentic Coding Trends Report echoes the human side: engineers use AI across a large share of daily work, yet fully delegate a much smaller share. Orchestration and escalation paths beat vibe-coding dumps. Multi-agent setups help when a single context window cannot hold the job, not because more agents sound modern. The human implication is sharper than the token math. If your builder stack needs a page of tool cards before it can book a haircut, you built a museum, not an operator. Start with the three tools that close one loop. Let the agent search for the fourth when the job actually requires it. LOW/CODE’s sales-agent build notes say the booking step and CRM sync are where DIY systems fail most often. Incomplete logs are why humans distrust the handoff. That is an architecture problem, not a model IQ problem. Worth a quiet read before the next connect-everything sprint: anthropic.com/engineering/co… Companion: anthropic.com/engineering/ad…
8
7
357
The Motion panel in Dev Mode is where pretty dies or ships. Designer finishes a spring on the canvas. Engineer opens Dev Mode, selects the animated frame, and either gets timing, easing, and keyframes as CSS, JSON, or React, or they get a screenshot and a shrug. Figma Motion, launched into the Config 2026 wave and still labeled open beta in the handoff docs, exists for that second path. Timeline view is read-only on purpose. You inspect at full fidelity, then copy code. Or you pass the frame link through the Figma MCP so a coding agent receives keyframes, motion type, timing values, and easing curves instead of a vibes brief. Motion for React documents the same pipe: export as React and paste into a project that already installs the `motion` package. Figma Sites runs real Motion under the hood for hover and press effects, which is a quiet tell. The industry is consolidating around design that can become code without a second art department. The stack question underneath is more useful than another shader collage. Adam Arant’s 2026 immersive-web note is blunt about what we actually ship: Lenis for smooth scroll (small bundle), GSAP with ScrollTrigger for hard scroll math (free for commercial use after Webflow opened the plugins), and native CSS scroll-driven animations where Chromium and Safari already do the job. Gate everything behind `prefers-reduced-motion`. GSAP’s `matchMedia` and Motion’s reduced-motion hooks exist so you do not invent accessibility as a later ticket. Constraint is the craft. One hero motion that arrives by Friday with a reduced-motion fallback beats three loops that never leave the canvas. If your shop site sells a service, the book CTA should still be readable when motion is off. Phone LCP in traffic is part of taste now. A gorgeous 4MB loop that hides the offer is not design. It is a trailer for a site that never loads. When you next open Dev Mode, open the Motion tab before you argue about brand. If the timing is not copyable, the animation is not finished. Handoff: help.figma.com/hc/en-us/arti… Config overview: help.figma.com/hc/en-us/arti… Motion export: motion.dev/docs/figma Lean stack cut list: adamarant.com/en/blog/immers…
1
2
249
Most booking bots only know how often to speak. They do not know when they are still allowed to. I wrote up the stop switch owner-run shops are missing: interested / parked / stop, Meta’s 24-hour hop, CRM events worth logging, and a one-afternoon wiring pass. x.lingyaoai.com/letscallsal/status/209…
11
10
250