HNHacker News
TopNewBestAskShowJobs

edf13

1,507 karma · joined October 20, 2017

hello at fieldlogic.uk
submissionscomments
edf13··on The Trivy Supply Chain Attack Reached LiteLLM
Author here. The point of this post is not “LiteLLM was compromised” since that was already covered on HN, but the chain behind it.

We tried to connect the February 27, 2026 Trivy CI compromise to the later Trivy release/tag issues, the trivy-action poisoning, the npm/Checkmarx follow-on activity, and finally the LiteLLM 1.82.7/1.82.8 package on March 24 2026!

What made it look like one campaign to us was the repeated overlap in operator attribution, payload structure, and artifacts like tpcp.tar.gz, plus the LiteLLM maintainer saying it appears to have come from Trivy in their CI/CD.

If anyone spots gaps or overreach in the timeline, I’d be interested in corrections.

edf13··on Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
That site is terrible without ads blocked… it’s like a local newspaper site, you had to try and read the content in small snippets wedged between ads!
edf13··on A rogue AI led to a serious security incident at Meta
It’s a nightmare… the problem is it’s far too easy for people to set these agents up - without understanding the security implications.

We’ve covered so many issues already on our blog (grith.ai)

edf13··on Nvidia NemoClaw
Related...

https://news.ycombinator.com/item?id=47430510

edf13··on AI Agent Backdoors Trivy Security Scanner, Weaponizes a VS Code Extension
An autonomous AI agent exploited a CI misconfiguration in Trivy (32k+ stars, 100M+ annual downloads), stole publishing tokens, deleted all 178 releases, and published a weaponized VS Code extension - in 44 minutes.

The extension's payload targeted five AI coding agents (Claude Code, Codex, Cursor, Windsurf, Copilot) with tool-specific flags to bypass their permission systems. First documented case of an AI agent attacking a supply chain and then using the compromised artifact to target other AI agents. CVE-2026-28353, CVSS 10.0.

edf13··on Launching the Claude Partner Network
That is the biggest threat - and likely where things will end up eventually… it’s when that “eventually” is and what the server based providers can pivot to in that time.
edf13··on Show HN: A context-aware permission guard for Claude Code
Nice list!

As you say lots of effort going into this problem at the moment. We launch soon with grith.ai ~ a different take on the problem.

edf13··on Ask HN: What Are You Working On? (March 2026)
It’s fast in terms of a response from a LLM model - but it is part of the system I am quite active on at the moment to ensure it’s performant as possible
edf13··on Ask HN: What Are You Working On? (March 2026)
Building grith — OS-level syscall interception for AI coding agents.

The problem: every agent (Cline, Aider, Codex, Claude Code) has unrestricted access to your filesystem, shell, and network. When they process untrusted content — a cloned repo, a dependency README — they’re prompt injection vectors with full machine access. No existing tool evaluates what the agent actually does at the syscall level.

grith wraps any CLI agent without modification. OS-level interception captures every file open, network call, and process spawn, then runs it through 17 independent security filters in parallel across three phases (~15ms total). Composite score routes each call: auto-allow, auto-deny, or queue for async review. Most will auto approve - which eliminates approval fatigue.

Also does per-session cost tracking and audit trails as a side effect of intercepting everything.

https://grith.ai

edf13··on Agent Safehouse – macOS-native sandboxing for local agents
We are a different approach and are targeting Linux for our first release (Windows & Mac shortly afterwards).

Taking more of an automated supervisor approach with limited manual approval for edge cases.

Grith.ai

edf13··on Ask HN: Is Electronic Data Interchange still used in e-commerce?
Yes - for many legacy systems especially in compliance related areas.
edf13··on Sandboxes won't save you from OpenClaw
https://grith.ai/blog/what-grith-means
edf13··on Sandboxes won't save you from OpenClaw
Every system call, file access, net access etc is forced through a local “proxy” where 17 individual filters check what’s going on.

Everything is done locally via our grith cli tool.

Happy to answer any questions on hello@grith.ai too

edf13··on Sandboxes won't save you from OpenClaw
Agree, that’s why we’re building grith.ai

Sandboxing alone isn’t the right approach… a multi-faceted approach is what works.

What we’ve found that does work is automation on the approval process but only with very strong guards in place… approval fatigue is another growing problem - users simply clicking approve on all requests.

edf13··on Claws are now a new layer on top of LLM agents
Haha - maybe… naming projects is hard!
edf13··on Claws are now a new layer on top of LLM agents
That’s one of the reasons we’re building grith.ai ~ these ‘claw’ tools are getting too easy for use (which is good)… but they need securing!
edf13··on Show HN: Moltbook – A social network for moltbots (clawdbots) to hang out
It’s an interesting experiment… but I expect it to quickly die off as the same type message is posted again and again… their probably won’t be a great deal of difference in “personality” between each agent as they are all using the same base.
edf13··on Show HN: Moltbook – A social network for moltbots (clawdbots) to hang out
AI models have a tendency to like purple and similar shades.
edf13··on Threat actors expand abuse of Microsoft Visual Studio Code
I’d like more granular controls - sometimes I don’t want to trust the entire project but I do want to trust my elements of it
edf13··on Anthropic's original take home assignment open sourced
I think he’s asking rather than giving instructions
edf13··on vLLM large scale serving: DeepSeek 2.2k tok/s/h200 with wide-ep
> let's enjoy the party while VCs are financing it!

The VC money is there until they can solve the optimization problems

edf13··on Sisyphus Now Lives in Oh My Claude
Terrible name…
edf13··on IBM AI ('Bob') Downloads and Executes Malware
Key part of the article../

“if the user configures ‘always allow’ for any command”

edf13··on Stoolap: High-performance embedded SQL database in pure Rust
Sounds very interesting - I’ve used SQLite in a few Rust based projects where performance was the deciding factor… a perf comparison with this would be very useful
edf13··on Writing a good Claude.md
Ah, never knew about this injection…

<system-reminder> IMPORTANT: this context may or may not be relevant to your tasks. You should not respond to this context unless it is highly relevant to your task. </system-reminder>

Perhaps a small proxy between Claude code and the API to enforce following CLAUDE.md may improve things… I may try this

edf13··on Claude Opus 4.5
I’m threw a few hours at Codex the other day and was incredibly disappointed with the outcome…

I’m a heavy Claude code user and similar workloads just didn’t work out well for me on Codex.

One of the areas I think is going to make a big difference to any model soon is speed. We can build error correcting systems into the tools - but the base models need more speed (and obviously with that lower costs)

edf13··on Rebecca Heineman has died
Today I learned...

"Super Fami-Com ("FAMIly COMputer")"

Doh!

edf13··on Simplify your code: Functional core, imperative shell
> In what application would you load all users into memory from database and then filter them with TypeScript functions?

You’d be surprised! I have worked on a legacy PHP service which did something very similar

edf13··on Roc Camera
Can’t I just photo a printed AI generated pic? What use is the proof?
edf13··on Slack's 57MB 404 page
Yes - everyone hates teams
← PreviousPage 2 of 17Next →