search
AI security tools
Trends
- 1Pi pod lets developers run coding agents in self-hosted sandboxesβShow HN: Pi pod β Run your pi coding agent in sandboxes on your own server
A new tool called Pi pod is being shared with developers, letting them run the Pi coding agent inside sandboxed environments on their own servers. The pitch is control and security: instead of relying on third-party infrastructure, teams can isolate agent execution on hardware they manage themselves. Early reaction on Hacker News is positive, with the launch drawing more than a hundred upvotes as developers weigh self-hosting coding agents against managed cloud options.
- 2
Cloudflare has published an open-source security-audit skill for AI coding agents, available on GitHub under the name security-audit-skill. Written in JavaScript, the tool runs multi-phase security audits and produces machine-readable findings that are independently verified, aiming to make automated code review more trustworthy. Developers are picking it up and discussing how it could fit into agent-based development workflows.
- 3Meta and Microsoft reportedly curb employee use of Claude AIβMeta and Microsoft take steps to reduce employee usage of Claude AI
Meta and Microsoft are reported to have taken steps to limit their employees' use of Anthropic's Claude AI assistant. The move suggests the two tech giants want staff relying on internal or approved AI tools rather than a direct competitor's product. Further details about how the restrictions are enforced have not been made clear.
- 4Greg Kroah-Hartman on software security in the LLM ageβGreg Kroah-Hartman β Security in the LLM Age [video]
Greg Kroah-Hartman, the longtime Linux kernel maintainer who leads the stable kernel branch, is featured in a talk on what large language models mean for software security. The discussion covers how LLM tools change the threat landscape for kernel and open-source development, and how maintainers should respond. The talk is drawing attention among developers debating AI's impact on critical infrastructure code.
- 5Google freezes open-source bug bounty program amid flood of AI slopβGoogle freezes open-source bug bounty program amid flood of invalid AI slop
Google has suspended part of its Open Source Vulnerability Reward Program, ending reward submissions for product vulnerabilities from October 1, citing an influx of invalid, low-quality bug reports generated by AI tools. The flood of junk submissions has made it impossible to sort genuine vulnerabilities from automated noise, forcing the company to pause the program. The move highlights a growing problem: AI-generated spam overwhelming security research channels meant for human researchers.
- 6Replit Previews Secure Windows Desktop App with AI SandboxesβReplit Previews Secure Desktop App for Windows with AI Sandboxes
Replit has given a first look at a secure desktop application for Windows that runs AI workloads in isolated sandboxes. The preview highlights stronger safety and local performance for coding with AI assistance directly on the desktop. Developers are discussing what the sandboxing approach means for security and whether the app will reduce reliance on the browser-based Replit workspace.
- 7Malicious web pages could trick GitHub Copilot CLI into leaking secretsβZombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets https:// sh.i
Security discussions are highlighting a prompt injection risk in GitHub Copilot CLI: carefully crafted web pages containing hidden 'zombie' instructions could manipulate the coding assistant into revealing secrets or performing unintended actions when it processes content from those pages. Commenters warn that developers using AI tools in terminals may be exposed if the tool cannot distinguish trusted instructions from malicious text embedded in the material it reads.
- 8CrowdStrike Monetizes AI Cybersecurity ComplexitiesβΌCrowdStrike (CRWD) is Monetizing the Complexities of the AI Cybersecurity Environment
CrowdStrike (CRWD) is being highlighted for its strategy of turning the growing complexities of AI-driven cybersecurity into revenue opportunities. The company, known for its cloud-based endpoint security platform, is positioning itself to benefit as enterprises confront new AI-related threats and seek advanced protection tools, according to a financial news report.
- 9Developers ask which AI models handle code security reviewsβAsk HN: Which frontier model can do code security reviews
A question on Hacker News is asking which frontier AI models are capable of performing code security reviews. The discussion seeks recommendations on which large language models can reliably audit code for vulnerabilities. With few replies so far, the thread reflects a broader interest among developers in using AI tools for security analysis.
- 10Open-source AI Agent Gateway keeps credentials out of configsβΌAI Agent Gateway: Open-source tool keeps credentials out of agent configs
A new open-source tool called AI Agent Gateway has been released, designed to keep credentials out of AI agent configurations. The gateway handles authentication separately so agents never store sensitive keys directly in their configs. Coverage highlights it as a practical security improvement for teams deploying AI agents, where hard-coded credentials have become a common risk.
- 11Prompt Injection Threat Now Targets AI Coding AgentsβWhen people hear "prompt injection", they picture a chatbot being tricked by a clever user... # ai # security # devops #
Security discussions are warning that prompt injection attacks are moving beyond chatbots to AI coding agents. The concern is that malicious instructions can be hidden in everyday development files, with a README alone potentially enough to manipulate an agent into harmful actions. Developers are being urged to treat repository content as untrusted input as AI tools increasingly read and execute instructions from codebases.
- 12AWS launches Strands Box sandboxes for AI agentsβIntroducing Strands Box: AI agent sandboxes powered by Dogwood
Amazon Web Services has introduced Strands Box, a tool for running AI agents in isolated sandboxes, built on its Dogwood technology. The sandboxes give agents a controlled environment to execute code and tasks safely. The announcement adds to AWS's growing Strands agent toolkit as companies look for secure ways to deploy autonomous AI systems in production.
- 13Pentagon launches AI pilot for managing sensitive informationβPentagon launches pilot program that will use AI to manage sensitive information
The Pentagon has started a pilot program that will use artificial intelligence to handle and manage sensitive information within the US Department of Defense. The initiative, reported by DefenseScoop, signals the Pentagon's growing interest in applying AI tools to core administrative and data-management functions. The news is drawing attention because of the obvious security implications of letting AI systems handle classified or sensitive government material.
- 14Free software community clashes over AI-written GPL codeβGPL apps/distros should not be using AI. GPL is not compatible with the ToS of these ai-generating code companies. It wa
Free software advocates are arguing that GPL-licensed projects should not use AI code-generation tools, because the terms of service of services like Codex and Cursor conflict with the GPL's licensing requirements. The debate intensified after criticism of Debian embracing AI-generated code. Some argue AI should only be used for tasks like finding security vulnerabilities, never for writing code in GPL projects.
- 15AWS Publishes Guide to Building an AI Vulnerability HarnessβBuilding your AI vulnerability harness, Part 1
Amazon Web Services has published the first part of a technical guide on building an AI vulnerability harness, a framework for testing AI systems for security weaknesses. The article walks readers through setting up tooling to probe machine learning models and AI applications for exploitable flaws. It is aimed at security engineers and developers who are adapting traditional penetration testing practices to AI systems, and further parts of the series are expected.
- 16
Meta and Microsoft are reportedly restricting employees from using Anthropic's Claude AI tools for their work. The move, reported by tech news outlets, underscores growing caution among major AI developers about relying on rival companies' chatbots and coding assistants, likely over concerns about data security, confidentiality and competitive sensitivity. The story is drawing attention in tech circles as competition between AI providers intensifies.
- 17Temporal hires Oso team to build AI agent securityβΌFast-growing Temporal hires team from NYC startup Oso to build AI agent security controls
Temporal Technologies, the fast-growing Seattle-area workflow orchestration company, has hired the team from New York security startup Oso to develop security controls for AI agents. The acqui-hire reflects growing industry concern over how autonomous AI systems are authenticated and governed. Oso, known for open-source authorization tooling, will wind down as its engineers join Temporal's security efforts.
Repos
- affaan-m/ECC The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development f
- garrytan/gstack Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Man
- cloudflare/cloudflare-os Agent workspace built on Cloudflare Workers for creating documents, building apps, and running agents with your companyβ
- archestra-ai/OpenAPPA Deterministic guardrails that don't break agents