a giant thank you to everyone who joined me as i build buttOS.
today, buttOS detects vulnerabilities by monitoring github repositories, npm libraries, known vulnerability databases, select forums, and the world wide web.
it is, however, still an ongoing build. currently, it is a capable and tireless analyst with access to good data
the goal is bigger. a real intelligence that questions, reasons, infers, experiments, and makes discoveries that nobody else has
i will aim to keep buttOS an open, public tool. data sourced by buttOS will always be free
day 1 is for building (sleep later)
a technical buttOS update:
- hotfixes
- indexing depth improved
- vulnerability scan rate increased by 4x
- SMTP deliverability improved
- BUTT.md @openclaw file was not reachable by some agents - solved
release deploying - should be out in a minute
for those just joining and asking what this is about
this is a public security framework running a continuous vulnerability recon loop on the entire internet. every finding is sourced from public disclosure feeds with CVE IDs, CVSS scores, and attached EPSS data
ButtOS gives a security layer to agents & protocols via the BUTT.md file - resulting in an immediate removal of compromised libraries
To help keep web3 safe, agents will attempt to find owners of compromised repositories and projects and alert them - this is free
Dexscreener:
https://t.co/emoySD2sDO
Streamflow:
https://t.co/wD1CcURA7Z
Token:
4toxTkTuLJvoDjrCFCwUzHpnwQyyjWKZN19E4qM3pump
Give this to your agent:
https://t.co/0EDT19Tysc
someone asked why this name; the only reason is because butts are funny
on a sidenote, buttOS has just processed its 146th recon run
you can watch what it does in realtime:
https://t.co/rmUmUi1kLL
most importantly, buttOS is a live vulnerability harness for agentic workflows
feed the BUTT.md file to any agent - @openclaw, @claudeai or otherwise - and it acts as a real-time CVE feed
npm lib leaked a minute ago? agents remove it instantly
https://t.co/wt8FzfxbfR
fees seem good, so about to do a small @dexscreener boost for some early visibility
will continue to do so on the way up to bonding
portion of the remaining fees will fuel tokens powering 24/7 buttOS indexes and reasoning
in the 4 hours since buttOS launched:
- 73 recon probes performed
- 43 unique vulnerabilities/new exploits identified since deploy
- 3 critical vulnerabilities at CVSS 9.8+
- 2 exploits on the CISA KEV list
most importantly, buttOS is a live vulnerability harness for agentic workflows
feed the BUTT.md file to any agent - @openclaw, @claudeai or otherwise - and it acts as a real-time CVE feed
npm lib leaked a minute ago? agents remove it instantly
https://t.co/wt8FzfxbfR
why?
@claudeai mythos boasts huge vuln detection scores, priced at a 20x markup against most models
finding vulnerabilities isn't hard. a million exploits surface every day. buttOS finds them for free
for what it lacks in reasoning, it makes up for by never stopping
when a site owner contact is found on a page where buttos identifies an exploit, the agents flag it
the owner is anonymized in the logs - then contacted
all anonymity preserves for 45 days at a minimum
buttOS is the underdog cousin of our favorite unreleased anthropic model
buttOS scans the web 24/7 for known vulnerabilities, known exploits and leaks, then sources all vulnerable platforms hosting said exploits
the agents reach out to the owners, as a public service
fees seem good, so about to do a small @dexscreener boost for some early visibility
will continue to do so on the way up to bonding
portion of the remaining fees will fuel tokens powering 24/7 buttOS indexes and reasoning
two autonomous agents - one scans CVE feeds, npm advisories, and disclosure bulletins in real time. the other verifies, triages, and scores each finding. neither ever stop
buttos runs a continuous passive reconnaissance loop against vulnerabilities as they're discovered.
no target is touched.
every finding is sourced from public disclosure feeds with CVE IDs, CVSS scores, and EPSS data attached