@bindureddy Not the strongest sales pitch from CEO advertising a powerful AI Agent and SuperComputer, which is basically proposing to use abacus instead of Codex / Claude Desktop )
Fail-open by default
Ten agent and MCP vulnerabilities in a single day's findings batch this weekend. Session hijacking through another user's run_id. Prompt injection into other people's running agents. And my personal favorite: AWS's API MCP Server silently disables its own...
Default-deny costs you one bad hour of debugging a service that won't start. Default-allow costs you the incident you never see. Every system picks one of these. Most pick by accident.
CLAUDE HAS A SERIOUS PRIVACY PROBLEM RIGHT NOW, A HUGE NUMBER OF SHARED CONVERSATIONS ARE PUBLICLY INDEXED ON GOOGLE FOR ANYONE TO FIND
when you use claude's share feature it makes a public link. it turns out those links got indexed by search engines, so "share with anyone who has the link" actually became "anyone can find this by searching"
and people are pulling up genuinely alarming stuff:
> api keys, credentials and crypto wallets
> personal resumes with real names, addresses and phone numbers
> a lawyer working through a potential ethics violation
> an engineers internal company project details
> what appear to be peoples social security numbers
> and a crazy number of deeply personal chats people never imagined another human would read
anthropic never added a noindex tag to those shared pages, so search engines were free to crawl and list them
one line of code would have prevented the whole thing
this already happened to chatgpt about a year ago, same exact issue, but openai patched it fast
if you have EVER hit share on a claude chat, assume it could be public
go to settings > privacy > your data > shared chats > manage
delete anything you dont want the whole internet to see, especially anything personal or financial
@TryDirect Container isolation covers the runtime but misses the semantic layer. The model can still issue valid-but-wrong actions. HELM adds policy enforcement before execution: action proposed, policy checked, signed receipt. gVisor + HELM = both layers covered. https://t.co/3g0HGjMffe
@corixpartners The risk is real but it's not the model - it's the gap between what the model proposes and what actually runs. We built HELM to close that gap. Every agent action gets matched to a policy before execution. No match, no run. Open source: https://t.co/3g0HGjMffe
@InfomlyLab "The security war is just starting" - exactly what we're building for.
MCP gives agents reach. But who governs what they do with it?
HELM sits between MCP tool calls and execution. No policy match = blocked. Policy + evidence + signed receipts.
https://t.co/3g0HGjMffe
Looking for early contributors and testers.
If you're building:
• AI agents in production
• MCP server integrations
• Enterprise AI workflows
• LLM automation
HELM is built for your stack.
Star the repo. Try the CLI. Open an issue.
Let's make AI agents safe.
AI agents are executing real actions in your company right now.
Approving payments. Deploying code. Changing access controls.
Most have zero enforcement layer between "model decides" and "action happens."
This is the problem I've been building against. 🧵
@sobedominik Apple featuring you once is luck. Twice is signal — they clearly see product quality and retention that makes Juicy stand out. That's the kind of distribution you can't buy. Congrats, well deserved. Worth a post-mortem on what changed between the first feature and now.