Skip to content

#OpenAI

0 items today
6/7Sun
  1. Permission Protocol · AI Agent Incident Tracker87

    Hades 攻击通过污染 AI 工具配置文件和 PyPI 启动钩子窃取 294,842 条凭据

    Hades 攻击波在 Claude Code、Cursor、Gemini CLI 和 VS Code 的配置文件中植入钩子,并通过 37 个 PyPI wheel 的 .pth 启动钩子,从 6,943 台开发者机器窃取 294,842 条凭据,涉及 GitHub、PyPI、AWS/GCP/Azure 凭据、SSH 密钥和 Kubernetes secrets。

    Awaiting translation

    Why it matters: 复盘攻击如何借 AI 工具配置文件与 Python 启动钩子在开发者机器上窃取凭据,并指出授权边界缺口。

6/5Fri
  1. Permission Protocol · AI Agent Incident Tracker88

    Miasma 供应链蠕虫通过 Agent 配置注入禁用 73 个微软 GitHub 仓库并窃取凭据

    Miasma 蠕虫通过投毒 Agent 配置文件感染 73 个微软 GitHub 仓库,开发者在 Claude Code、Cursor 或 Gemini CLI 中打开仓库时即执行凭据窃取程序,导致 AI API token、GitHub token 和云凭据泄露。

    Awaiting translation

    Why it matters: 复盘 Miasma 蠕虫如何借 Claude Code、Cursor、Gemini CLI 的会话初始化配置实现零点击窃取凭据,可迁移到仓库配置来源校验。

6/3Wed
  1. Permission Protocol · AI Agent Incident Tracker76

    仿冒 Claude Code 与 Codex 安装页经 Google Sites 投递无文件内存窃密程序

    攻击者用 Google Sites 托管仿冒 Claude Code 和 Codex 的安装页,诱导开发者在运行对话框粘贴 mshta.exe 命令,投递无文件内存窃密程序,窃取 AI API key、浏览器凭据和开发者环境密钥。

    Awaiting translation

    Why it matters: 梳理了仿冒 Claude Code 与 Codex 安装页的 ClickFix 攻击链,可了解针对 AI 开发者凭据的窃取手法。

6/1Mon
5/26Tue
  1. Hacker News · AI Code Review 讨论88

    How Cloudflare Uses OpenCode to Orchestrate Large-Scale AI Code Reviews

    Cloudflare built a CI-native AI code review system on top of the open-source coding agent OpenCode. A coordinating agent dispatches up to 7 dedicated review agents, split by security, performance, code quality, documentation, release, and internal standards, then deduplicates their output and posts a single structured review comment.

    Why it matters: Cloudflare has published the plugin architecture, risk grading, and cost data behind its multi-agent code review in CI, and the setup can be ported to your own review pipeline.

5/24Sun
  1. Thorsten Ball · Register Spill15

    Amp Labs 成立,Amp 联合创始人谈软件的未来

    Amp 本周宣布成立 Amp Labs,团队已与多家公司合作,新阶段从澳大利亚悉尼起步。Amp 官网同期发布《Software After Software》,阐述其对软件未来的判断以及 Amp 与 Amp Labs 的存在理由。联合创始人还做客 Mayank Gupta 播客,聊了自己如何进入编程、从练 Vim 到成为 Amp 联合创始人的经历。

    Awaiting translation

5/23Sat
  1. 陈与小金 · AI Coding 博客62

    卡帕西加入 Anthropic:用 Claude 造下一个 Claude,套壳才是产品

    OpenAI 创始成员卡帕西于 2026 年 5 月 19 日加入 Anthropic 预训练团队,Anthropic 为他新建了一个子团队。据预训练团队负责人 Joseph 在 X 上的说法,卡帕西将带领新团队用 Claude 加速预训练研究本身,即让 Claude 帮研究员提代码方案、写预训练代码、跑消融实验、生成并筛选训练数据,卡帕西负责把关。

    Awaiting translation

5/22Fri
  1. Permission Protocol · AI Agent Incident Tracker85

    GitHub confirms 3800 internal repositories were leaked after an employee installed a poisoned Nx Console VS Code extension

    GitHub confirms that roughly 3800 internal repositories were leaked, including Copilot's internal code and GitHub Actions workflow source code, after an employee installed an Nx Console 18.95.0 VS Code extension poisoned by TeamPCP.

    Why it matters: The timeline and technical chain are complete, showing how a VS Code extension supply-chain poisoning attack stole credentials and leaked internal repositories.

5/20Wed
  1. 宝玉76

    The official Codex team shares how to get the most out of Codex

    Codex team member jason (@jxnlco) shares how to get the most out of Codex, the key being to combine persistent conversation threads, voice input, task intervention and queuing, MCP servers and connectors, conversation thread automation, goal setting, and the sidebar.

    Why it matters: A member of the official Codex team breaks down how to use persistent conversation threads, task intervention, automation, and goal setting—approaches you can carry over into everyday agent workflows.

5/18Mon
5/15Fri
5/14Thu
5/11Mon
  1. Drew Breunig38

    过度拟合 Harness 的代价:OpenAI 收缩微调后,前沿模型会变成"家电"吗

    OpenAI 正在收缩微调业务,Drew Breunig 认为这会让前沿模型越来越像为自家 Harness 定制的"家电"而非通用平台。他指出,大实验室把 Harness 设计训练进模型,第三方 Harness 搭配前沿模型的价值将下降,而微调这条泛化退路也随之中断。对企业而言,应用构建可能更简单,代价是锁定。

    Awaiting translation

5/10Sun
5/9Sat
  1. OpenAI · Codex Cookbook72

    OpenAI brings persistent Goals to Codex

    Starting with Codex 0.128.0, OpenAI offers Goals, turning one-off prompts into persistent objectives within a thread. Codex keeps checking evidence such as tests, benchmarks, or deliverables to decide whether the goal is done.

    Why it matters: The official docs lay out where Goals fits, how to write its six elements, and the lifecycle commands, so you can tell when a persistent objective should replace a one-off prompt.

5/7Thu
  1. Permission Protocol · AI Agent Incident Tracker74

    TrustFall 披露编码智能体安全漏洞:仓库配置可触发一键 RCE

    Adversa AI 发布 TrustFall 研究,指出恶意仓库配置可让编码智能体在通过一次笼统的信任授权后启动攻击者控制的 MCP 服务器,从而在开发者工作站和 CI 环境中造成一键远程代码执行,可能访问本地凭据、仓库内容和工作流密钥。

    Awaiting translation

  2. Permission Protocol · AI Agent Incident Tracker80

    仿冒 OpenAI 仓库在 Hugging Face 登顶热门榜并获 24.4 万次下载后投递窃密木马

    Hugging Face 上一个仿冒 OpenAI Privacy Filter 的仓库登上热门榜第一、获得 244,000 次下载,随后在安装该模型的 Windows 机器上执行窃取凭据的 infostealer。

    Awaiting translation

    Why it matters: 复盘 Hugging Face 上仿冒 OpenAI 仓库的投毒链条,展示热门榜如何被当作信任信号利用。

5/6Wed
5/5Tue
  1. DevAgentStack · Field Notes80

    如何让仓库对 AI 智能体友好:一份实用审计清单

    作者提出让仓库对 AI 智能体友好的实用审计清单,核心是让智能体能快速回答行为在哪、什么不能改、怎么测、如何证明完成。清单包括在根目录放仓库地图、明确高风险区域、写出验证命令、用 AGENTS.md 提供跨工具通用说明,以及用 Zod schema、TypeScript 接口和测试名把契约变成可执行边界。

    Awaiting translation

    Why it matters: 作者给出一份可逐条落地的仓库审计清单,说明如何让智能体快速找到模块、边界和验证命令。

5/4Mon
5/2Sat
5/1Fri
  1. Jesse Vincent62

    作者分享让 AI 智能体对抗式评审自己工作的提示词

    作者分享了自己常用的对抗式评审提示词,核心做法是让 Claude 派子智能体复查刚完成的工作,最简形式是“用全新的眼光再看一遍”。他指出让智能体自评存在目标冲突,因此对抗式评审更有效,不少人会用 Codex 等不同模型来评审 Claude 的工作。即使没有多模型环境,也可以让两个子智能体互相竞争,比如告诉它们找出严重问题最多的一方得五分,或得一块饼干,效果相近。

    Awaiting translation

4/30Thu
  1. Augment Code · Blog71

    Augment Code put Karpathy-style rules to the test: the coding agent didn’t write better code, but it was cheaper and faster

    In AGENTS.md, Augment Code front-loads roughly 2.5k characters of Karpathy-style coding rules, then runs 40 OpenClaw PRs through Auggie, Claude Code, and Codex for comparison.

    Why it matters: A head-to-head test of three coding agents on the same set of PRs shows that prompt constraints mainly cut costs rather than improve quality, and it also surfaces differences between the harnesses.

4/29Wed
4/28Tue
4/27Mon
  1. Permission Protocol · AI Agent Incident Tracker83

    AI 编程智能体 9 秒删除 PocketOS 生产数据库及备份

    PocketOS 据报在一次 Railway API 调用中丢失生产数据库和卷级备份,整个过程仅 9 秒,人类来不及介入。事故分析指出危险能力不在代码生成,而在于智能体持有具备生产破坏权限的云厂商令牌;仅靠 PR 门禁看不到绕过代码仓库的直接 Railway API 删除,授权检查应前置到删除生产数据或备份的云厂商 API 调用之前,并要求签名回执写明生产环境、资源、动作和签署人。

    Awaiting translation

    Why it matters: 复盘一次智能体凭令牌直接删除生产库与备份的事故,指出授权检查应放在云厂商 API 调用之前。

4/26Sun
4/24Fri
  1. Lovable · Blog38

    Lovable 早期测试 GPT-5.5:最难任务通过率 41.6%,比 GPT-5.4 提升 12.5%

    Lovable 在早期访问中测试 GPT-5.5,其内部基准显示最难任务通过率从 GPT-5.4 的 36.9% 升至 41.6%,每次请求工具调用减少 23.1%,用户卡住的消息占比下降 9.9%。GPT-5.5 每请求输出 token 减少 33%,日常任务成本效率提升约 15%,将很快向 Lovable 构建者开放。

    Awaiting translation

4/22Wed
  1. Permission Protocol · AI Agent Incident Tracker80

    Bitwarden CLI 遭 Shai-Hulud 供应链攻击,定向窃取 Claude Code、Cursor、Codex CLI 的 API Key

    攻击者劫持 Bitwarden 的 CI/CD 流水线,向 npm 发布恶意 @bitwarden/[email protected],在 2026 年 4 月 22 日 5:57–7:30 PM ET 的 90 分钟窗口内被 334 名开发者安装。

    Awaiting translation

    Why it matters: 复盘了恶意 npm 包如何定向窃取 AI 编程工具凭证,并给出 90 分钟窗口与影响范围等可核查细节。

4/15Wed
  1. Permission Protocol · AI Agent Incident Tracker87

    约翰霍普金斯研究者通过 PR 标题注入从 Claude Code、Gemini CLI 和 GitHub Copilot 窃取 API 密钥

    约翰霍普金斯研究者 Aonan Guan 利用 PR 标题提示词注入,从 Claude Code Security Review、Gemini CLI Action 和 GitHub Copilot 中窃取 API 密钥与 GitHub token。

    Awaiting translation

    Why it matters: 约翰霍普金斯研究者用 PR 标题注入从三个 AI 编程智能体中窃取凭据,三家厂商均静默修复并支付漏洞赏金。

4/10Fri
  1. Ryan Lopopolo65

    怎样才算把活干好:写清非功能性需求才能让 AI 智能体收敛

    Ryan Lopopolo 认为,AI 让验证问题变得明显,因为每个真实任务都依赖一个我们几乎从不写下来的问题,即怎样才算把活干好。产出和评审都涉及语气、品味、风险容忍度、打磨程度、可接受的捷径和完成标准等大量非功能性决策,过去团队靠组织设计、社交规范、招聘和入职把这些隐含规则传递给人,而模型无法走招聘流程,因此交给它的任务基本都欠规范。

    Awaiting translation

    Why it matters: 作者以在 OpenAI 做代码智能体的经历说明,非功能性需求不写下来,评审智能体就会陷入无休止的拉扯。

4/9Thu
4/6Mon
4/1Wed
3/31Tue
  1. Martin Alderson74

    Telnyx、LiteLLM 与 axios 供应链攻击:作者主张用移动端式沙箱重构操作系统

    过去一周有攻击者接连投毒多个开源包,从 Trivy 开始,波及 Telnyx(受影响包约 15 万次/周下载)、LiteLLM(约 2200 万次/周)以及 3 月 31 日被攻击的 axios npm 包(至少 1 亿次/周下载),恶意版本会植入木马窃取安装机器的敏感数据。

    Awaiting translation