Matt Shumer says OpenAI gave him early access to a report on how its agents hacked Hugging Face, and links to his plain-English breakdown of the attack and what it means for internet users.
Malte Ubl of Vercel announces deepsec, an open-source tool that uses coding agents to scan an entire repository for vulnerabilities and revalidate each finding before reporting it. The linked page describes the tool.
Ammaar Reshi announces Gemini 3.5 Transcribe, a speech-to-text model supporting over 85 languages with smart correction and custom vocabulary. He says he built a Wispr Flow-style app on the model and is open-sourcing it, with a demo in the attached video.
Eric Zakariasson describes a Grok Bot feature that stores credentials in a vault and injects them at the host when a tool call is executed, so the model never sees the plain-text key. He gives a Linear bug-filing example and shares a diagram of the flow.
this card allows grok bot to store credentials securely in a vault! when the credential is needed, it goes through a special access path where its never exposed to the model in plain text
later when you say "file a bug that login is broken", the bot turns that into a linear call with just the title (no token). the host knows that tool call is linear's, looks up this agent's linear api key, and builds the real http request. linear creates it, and the bot gets back "sent it, we're good". the host where the final tool call is constructed is also the only place the credential shows up
Micky introduces Bezalel, a free alpha capability plane that gives agents such as Claude and Codex computer, sandbox, iMessage, email, memory and connector access through a single MCP, built on services from Orgo, Vercel, Composio and others.