1,507 karma · joined October 20, 2017
PR content:
``` Lots of AI slop.... .... .... Note: this will not build due to XYZ .... .... More AI slop .... .... End of PR ```
So the dev hadn't even read the PR comment himself and had blindly posted it!
So I built this simple tool to show my current session status.
I'm Dan and I staarted building grith AI earlier this year after getting annoyed with constant permission prompts from Claude Code and Codex.
I had previously built an email security service which relied on a pipeline of multiple filters, each one building up a score of an incoming message - allowing the system to auto approve or deny an message in almost all cases and if it was unsure it would add it to an email digest/report letting the user choose to allow or block.
This process is the basis for grith - we currently have 18 filters and 1617 patterns which build a score for every action a agent takes - everything <= 3.0 is automaticialy approved, everything > 8.0 is automatically blocked... the ones inbetween we prompt the user.
What this means in practice is that the user sees very little prompts - in a records 120 claude code session a user only ever had to respond to 0.27% of prompts... not 40 or so an hour you'd see in normal use and not the dangerously blind approval --dangerously-skip-permissions or auto mode would give you!
Grith is free with no account needed, no phone-home and open source. Paid tiers bring teams, online dashboards, centralised policies, verificable analytics and more.
Linux first with Windows and Mac launching soon.
A comparison of a dumb 4k panel vs the equivalent "smart" tv for example>
You also need to manage the authority of each skill too. Signed skills is a step in the right direction, but it only proves provenance and doesn't prove behavior.
Website Not Allowed “prismml.com” is a restricted website.
I reviewed a colleague's vibe-coded internal tool last week, found 28 security issues, and none of them were that kind of bug - they were the same classic stuff juniors have always shipped, just produced at much higher throughput.
Wrote it up because the "senior engineer review" step quietly disappeared from a lot of AI-assisted workflows, and the bugs that step used to catch are still there (We are still needed!).
Feedback accepted, thanks!
Claude Code returning: API Error: 500 {"type":"error","error":{"type":"api_error","message":"Internal server error"},"request_id":"---"}
Over and over again!
The problem: agents like Claude Code, Codex, and Aider execute file reads, shell commands, and network requests with your full system privileges.
For example, when a malicious README tells the agent to read ~/.ssh/id_rsa and POST it somewhere, nothing in the agent's own trust model catches it. Auto Mode makes this worse - it asks the model to audit its own actions, so a prompt injection that corrupts the reasoning also corrupts the permission layer.
grith wraps any CLI agent with `grith exec -- <agent>`. Every syscall passes through a multi-filter scoring engine before it executes. Deterministic, ~15ms overhead, no LLM reasoning in the permission path. Linux now, macOS/Windows coming. AGPL, open-core.
Two weeks ago a DPRK-linked attacker backdoored axios on npm (400M monthly downloads). The RAT executed 1.1 seconds into npm install. AI agents run npm install autonomously, without human review. If yours ran it during the 3-hour window, you're compromised and nobody told you.
That's the threat model grith is built for.
Readership, clicks and views
I do find Codex very good at reviewing work marked as completed by Claude, especially when I get Claude to write up its work with a why,where & how doc.
It’s very rare Claude has fully completed the task successfully and Codex doesn’t find issues.
I’ve found Claude in particular to be very good at this sort of thing. As for whether it’s a good thing, I’d say it’s a net positive - your own reporting of this probably saved a bigger issue!
We wrote up the why/what happened on our blog twice… the second based on the LiteLLM issue:
https://grith.ai/blog/litellm-compromised-trivy-attack-chain
It’s really interesting to read how you’ve captured and created these images… will follow your work!