last year i won $25k in @OpenAI credits. now, I want you to spend them checking for supply-chain attacks in your PRs.
try out our new @github action released today, which scans any new dependencies or versions in a PR on our ghost agent
entirely free to use & open source :)
ai offers a ton of benefits to security researchers - but at a cost. There's been a big rise in slop reports, making it difficult for teams to effectively prioritize more important vulns being reported. We wanted to solve this by gamifying vuln validation, specifically for our supply-chain detections from ghost.
try it out daily on ghost! leaderboard coming soon...
i can imagine adversaries building a version of @openclaw that could "self-destruct" and trigger a rebuild of itself with context and memory saved to evade detection.
imagine an agent that could effectively determine it was likely to be detected and mobilize itself dynamically.
fantastic day at our first, Personalized Agents Hackathon hosted with @LightningAI, @Newlab, and @validia_ai
We brought together 125+ engineers here in NYC to work on building personalized & secure use-cases around @openclaw
Check out some of the winning projects below!
open sourced this and setup MCP server for @AnthropicAI Claude Code, and @OpenAI Codex to pull critical updates when leveraging one of our tracked dependencies
Security is solved as a community -> check out the repo here: https://t.co/wDk46hjYB8
last year i won $25k in @OpenAI credits, and figured I’d put them to a good cause. With supply chain attacks becoming much more common, the frequency and speed at which we vet new software versions becomes critical.
sharing ghost, by Validia. Ghost detects changes every 30-seconds to 545 different packages, passing their diff to an agent built on the OpenAI agents SDK each time there’s a change.
Check out the link below