What does "trust remote code" actually approve?
In most local AI tools, the answer is: that repo, indefinitely.
That matters more now. In May, HiddenLayer reported a trending Hugging Face repo whose loader. py downloaded an infostealer on Windows. JFrog counted 495 malicious models that month.
I spent some time with Unsloth Studio's approach. It handles it differently.
Approval is tied to a fingerprint of the scanned code. Change the code, and you're asked again.
Critical findings can't be approved. Code it can't scan is blocked. There's no trusted-org bypass.
Weights are checked on their own. Studio reads Hugging Face's malware verdict without unpickling the file. Flagged files in the loading path are blocked, including weight shards. .bin weights load with weights_only=True on PyTorch 2.6+.
The supply chain gets attention too. PyPI and npm packages are content-scanned. npm packages need to be at least 7 days old. GitHub Actions are pinned, and llama.cpp binaries are checksum-verified. Trivy isn't installed at all, after a compromised Trivy exposed LiteLLM's publishing credentials in March.
Accounts are covered as well. Passwords use PBKDF2-HMAC-SHA256, failed logins are rate-limited, and the first admin password is random. Managed accounts can't run repository code.
For remote access, --secure serves HTTPS through a Cloudflared tunnel. --disable-tools is recommended when exposing Studio.
What it doesn't do: sandbox approved model code. Server-side tools still run as your OS user. Local folders aren't covered by the file check, and a pending scan status doesn't block.
That's a reasonable line to draw, as long as you know where it is.
Read our full analysis on this: https://t.co/t9doA96hVn
Here is the Unsloth's docs: https://t.co/cvG0mi87ZK
@UnslothAI@UnslothLLM
We were there at #DFTS2026 in Rome last week. Here is Chen who presented her paper "Assessing Triple Modular Redundancy for Wide-Link, Low-Latency NoC Routers: Reliability and Physical Design Challenges". Find her slides here: https://t.co/Pl0j5E6yfx
do you see it now, anon? the only "fundamental limitation" that has ever actually mattered was lacking compute or data. everything else can be supplanted by them.
Compositional 3D reconstruction now feeds physics sim, but mostly with rigid bodies.
Real scenes are full of deformable and thin objects like cords & paper.
CoDimRecon reconstructs them as sim-ready curves, surfaces & volumes from multi-view photos 👇
https://t.co/xm31hP5dGu
Building reliable agents is hard. Even when agents have access to tools with the same capabilities, how those capabilities are exposed can significantly change agent behavior (e.g., consistency and efficiency). Stop by and discuss with us at #COLM26!
Little demo of TraceMaker on a real KiCad board (Kitspace Aquarius).
It places first, then routes. 171/171 connected, clean KiCad DRC, wiring about half what the original layout needed.
Just released it as open source.
What would you trust an autorouter with, and what would you still place by hand?
A Physical Review Applied paper demonstrates a way to study individual point defects in semiconductor crystals at the nanometer and nanosecond scale. Understanding these defects could unlock the full potential of optoelectronic devices.
🔗 https://t.co/AIgXz7DGyM
Here are the must-read in my bookmark. From agentic robotics, policy enhancement, data and eval.
1. Comparison between agentic robotics and Code-as-Policy by @paigeinsf from @se3labs https://t.co/dQKHFSLY9a
2. Evaluation on Astra, Fable and Opus for wetLabs tasks by @joshavata from @meckaai https://t.co/11Ag8P6OjS
3. Evaluations of GPT-6 Astra on RoboDojo by @_wenbozhang https://t.co/mYzw8rR6fg
4. Comparison between Astra and Fable on control task by @chooi_jeq from @robocurve https://t.co/usENOSY98t
5. What matters for policy improvement and what doesn't by @DominiqueCAPaul from @dm_robots https://t.co/ZI8lW1TKWy
6. Argus: An Open‑Source Annotator for Robotics Data by @calixo888 from @PantheonInc https://t.co/ozLpyEGKhm
7. Robotics data quality, anomalies in opensource datasets by @calixo888 from @pantheoninc https://t.co/X9NKarQLWz
8. Eval platform for failure analysis by @charleswongzx from @bifrost_ai https://t.co/Cegxef3Utj
Please leave in the comments if you have good sharing. I will bookmark it. Thanks!
Since Skill from Video (2018) and Videomimic (2025) the unspoken challenge has been finding the right videos to teach robots at scale.
Zihan's work changes that with v2v, turning a few good demos into many counterfactual videos.
Another step towards scalable real2sim2real!
OpenVINO just got easier in Ultralytics Inference v0.0.45. ⚡
No custom ONNX Runtime build needed. On Linux/Windows x64, a verified plugin downloads on first use for Intel CPU, GPU, or NPU. Internet is required on first use.
Read more ➡️ https://t.co/tEsrEng65d
#AI#Intel #MachineLearning
FreeCAD Project Association funded three new grants in Q3 2026 for #FreeCAD development.
• Improving real time rendering quality
• TechDraw Toponaming improvements
• #KiCad integration for Ondsel Lens
You can read more in the blog post:
https://t.co/n0evz2Empe
Does forearm EMG actually predict grip force? We tested it - https://t.co/IxgbZv2apY
Explore the egocentric-emg-force dataset in FiftyOne: real wrist EMG + vision-derived finger force across 8 everyday tasks.
We ran our own cross-correlation on all 16 hand-episode pairs. The signals barely agree:
* Best correlation anywhere: r = 0.43
* 13 of 16 pairs below r = 0.3
* Not one pair hit r = 0.5
* Card says 80ms lag. We found -230ms to +200ms.
The takeaway: treat vision-derived force as its own signal, not a proxy for real force.
Why it matters → prosthetics, warehouse ergonomics, teleoperation haptics all lean on this link.
Bonus: the pipeline works on any two MCAP topics. Don't assume zero lag. Measure it.
#PhysicalAI #ComputerVision #MachineLearning #Robotics #EMG #FiftyOne #Voxel51 #MultimodalAI
I realised that one of the biggest problems in taking AI CAD to drawings and manufacturing is the lack of GD&T and manufacturing intent data.
Draftwright Specify makes it easy to add GD&T, call out tolerances, etc. No AI, just deterministic code. STEP in, AP242 out (and 2D drawings as well)
https://t.co/v5phBBvECc
#MechanicalEngineers I'm looking for feedback please