Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
edf13
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
61.
▲
by
edf13
7mo ago
That site is terrible without ads blocked… it’s like a local newspaper site, you had to try and read the content in small snippets wedged between ads!
62.
▲
Google's A2A Protocol Has Zero Defenses Against Prompt Injection
(grith.ai)
4 points
by
edf13
7mo ago
|
1 comments
63.
▲
Claude Code Channels
(twitter.com)
2 points
by
edf13
7mo ago
|
1 comments
64.
▲
by
edf13
7mo ago
It’s a nightmare… the problem is it’s far too easy for people to set these agents up - without understanding the security implications. We’ve covered so many issues already on our blog (grith.ai)
65.
▲
Permission Fatigue Is Not a UX Problem. It Is a Security Failure
(grith.ai)
3 points
by
edf13
7mo ago
|
1 comments
66.
▲
by
edf13
7mo ago
Related... https://news.ycombinator.com/item?id=47430510
67.
▲
NemoClaw vs. Grith: Sandbox for One Agent vs. Security for All
(grith.ai)
3 points
by
edf13
7mo ago
|
0 comments
68.
▲
AI Agent Backdoors Trivy Security Scanner, Weaponizes a VS Code Extension
(grith.ai)
2 points
by
edf13
7mo ago
|
0 comments
69.
▲
by
edf13
7mo ago
An autonomous AI agent exploited a CI misconfiguration in Trivy (32k+ stars, 100M+ annual downloads), stole publishing tokens, deleted all 178 releases, and published a weaponized VS Code extension - in 44 minutes. The extension's payl
70.
▲
AI Agent Backdoors Trivy Security Scanner, Weaponizes a VS Code Extension
(grith.ai)
2 points
by
edf13
7mo ago
|
1 comments
71.
▲
87% of AI-Generated Pull Requests Ship Security Vulnerabilities
(grith.ai)
6 points
by
edf13
7mo ago
|
0 comments
72.
▲
Custom AI Smart Speaker
(openhome.com)
2 points
by
edf13
7mo ago
|
0 comments
73.
▲
by
edf13
7mo ago
That is the biggest threat - and likely where things will end up eventually… it’s when that “eventually” is and what the server based providers can pivot to in that time.
74.
▲
Claude Code Auto Mode Lets the Agent Approve Its Actions – That's the Problem
(grith.ai)
3 points
by
edf13
7mo ago
|
0 comments
75.
▲
Lloyds, Bank of Scotland and Halifax apps showed other users transactions
(apple.news)
3 points
by
edf13
7mo ago
|
0 comments
76.
▲
by
edf13
7mo ago
Nice list! As you say lots of effort going into this problem at the moment. We launch soon with grith.ai ~ a different take on the problem.
77.
▲
Claude Code Attempted 752 /proc/*/environ Reads. 256 Succeeded. Codex: 0
(grith.ai)
4 points
by
edf13
7mo ago
|
0 comments
78.
▲
I checked every syscall Claude and Codex made for a simple task
(twitter.com)
4 points
by
edf13
7mo ago
|
0 comments
79.
▲
Claude Code Attempted 752 /proc/*/environ Reads. 256 Succeeded. Codex: 0
(grith.ai)
3 points
by
edf13
7mo ago
|
0 comments
80.
▲
by
edf13
7mo ago
It’s fast in terms of a response from a LLM model - but it is part of the system I am quite active on at the moment to ensure it’s performant as possible
81.
▲
by
edf13
7mo ago
Building grith — OS-level syscall interception for AI coding agents. The problem: every agent (Cline, Aider, Codex, Claude Code) has unrestricted access to your filesystem, shell, and network. When they process untrusted content — a cloned
82.
▲
by
edf13
7mo ago
We are a different approach and are targeting Linux for our first release (Windows & Mac shortly afterwards). Taking more of an automated supervisor approach with limited manual approval for edge cases. Grith.ai
83.
▲
A GitHub Issue Title Compromised 4k Developer Machines
(grith.ai)
632 points
by
edf13
7mo ago
|
195 comments
84.
▲
Vibe Coding Is Killing Open Source, and the Data Proves It
(grith.ai)
5 points
by
edf13
7mo ago
|
0 comments
85.
▲
We Audited 2,857 Agent Skills. 12% Were Malicious
(grith.ai)
2 points
by
edf13
7mo ago
|
0 comments
86.
▲
We Audited 2,857 Agent Skills. 12% Were Malicious
(grith.ai)
2 points
by
edf13
7mo ago
|
0 comments
87.
▲
MCP Servers Are the New npm Packages
(grith.ai)
4 points
by
edf13
7mo ago
|
1 comments
88.
▲
by
edf13
7mo ago
Yes - for many legacy systems especially in compliance related areas.
89.
▲
We Audited the Security of 7 Open-Source AI Agents – Here Is What We Found
(twitter.com)
1 points
by
edf13
7mo ago
|
0 comments
90.
▲
We Audited the Security of 7 Open-Source AI Agents – Here Is What We Found
(grith.ai)
2 points
by
edf13
7mo ago
|
0 comments
More ›