69 karma · joined March 31, 2023
--- i make machines learn
Really wanna see it in DeepSWE benchmark
I am trying it on but its brekaing on homebrew 1.0.0. The formula puts plugins at opt/container/libexec/container-plugins/ and the apiserver looks in libexec/container/plugins/
This can be solved through a symlink or smth
Not sure what extra are we achieving here
immunity-agent would have stopped this at two points. Warden's scoped agent would have seen "fix a staging credential issue" and locked out destructive commands and production network access for that session. Cloak would have intercepted the Railway token before it ever reached the model. This is something in active development and open for suggestions and critiques on how to make this better, especially to prepare for future headwinds like security for AI
Agents like claude code/openclaw save secrets in plaintext within config files, which makes a big attack vector for a local compromise becoming a cloud compromise.
We empirically verified to stop AI coding agents from leaking secrets by intercepting tool calls and handling secrets entirely outside the model’s visibility. Using Claude Code’s hook system.
Paired with open source repo for cleanup, it shows that most leakage can be eliminated by treating secrets as a runtime dataflow problem rather than a static scanning issue
It employs a specialized 5-aagents pipeline: Outline, Plotting/Lit Review, Section Writing, and Refinement. This setup greatly surpasses single-agent models in literature review quality and overall performance.
I created this repository to transform the paper’s prompts, schemas, and verification gates into a "skill pack" that any modern coding agent can use.
Repo: https://github.com/Ar9av/paper-orchestra
I am thinking of improving on it through: - optional semantic scholar support for verifying - an arxiv packager that strips comments and zips everything up for submission in one click. - human-in-the-loop checkpoints that pause the pipeline so you can approve the outline before it starts burning tokens
Within these logs I found API keys and access tokens were sitting in plain text, completely unencrypted and accessible to anyone who knows where to target when attacking.
I made an open source tool called Sweep, as part of my immunity-agent repo (self-adaptive agent). Sweep is designed to find these hidden leaks in your AI tool configurations. Instead of just deleting your history, it moves any found secrets into an encrypted vault and redact the ones used in history.
We also thought about exploring post hook options but open to more ideas
Encoder: learns which stimulation patterns tend to improve reward
Biological neurons: adapt to the stimulation and generate spike responses that reinforce certain patterns
Decoder: interprets those spike patterns and converts them into joystick movements
right?
We see this firsthand at Prismor with auto generated security fixes. Even with the best LLMs, validating fixes is the real bottleneck our pipeline struggles to exceed 70% on an internal golden dataset (which itself is somewhat biased).
Many patches technically fix the vulnerability but introduce semantic regressions or architectural drift. Passing tests is a weak signal and proving a fix is truly safe to merge is much harder