AI 资讯
Your MCP servers can read your SSH keys. Anthropic just fixed that.
Every MCP server you run locally executes with your full filesystem and network permissions. That means the GitHub MCP server, the Slack one, that third-party tool you installed from npm last week — all of them can read your SSH keys, .env files, and credential stores by default. Anthropic just open-sourced the fix: sandbox-runtime , the sandboxing layer they built for Claude Code. One-line wrap, no Docker, OS-level enforcement. What actually changed srt (the Sandbox Runtime CLI) enforces filesystem and network restrictions on any process using native OS primitives: macOS : Uses sandbox-exec with dynamically generated Seatbelt profiles Linux : Uses bubblewrap for containerization + network namespace isolation Network filtering : HTTP/HTTPS traffic routes through an HTTP proxy; other TCP goes through SOCKS5 — both enforce your domain allowlists Install it: npm install -g @anthropic-ai/sandbox-runtime Wrap an MCP server in your .mcp.json — change command from npx to srt , move the rest to args : { "mcpServers" : { "filesystem" : { "command" : "srt" , "args" : [ "npx" , "-y" , "@modelcontextprotocol/server-filesystem" ] } } } Then configure what the process is actually allowed to touch in ~/.srt-settings.json : { "filesystem" : { "denyRead" : [ "~/.ssh" ], "allowWrite" : [ "." ], "denyWrite" : [ "~/sensitive-folder" ] }, "network" : { "allowedDomains" : [ "api.github.com" , "*.npmjs.org" ] } } The result: the MCP server can work in your project directory, talk to the domains it needs, and nothing else. Why this matters The threat model is real. An MCP server running compromised code — or simply a server with more ambient access than it needs — can exfiltrate your SSH keys, read your .env files, or phone home to arbitrary hosts. This isn't theoretical; it's the same class of supply-chain risk that exists for any untrusted npm package, except MCP servers are typically long-running processes with broad system access. srt is designed secure-by-default : processes start wit
AI 资讯
I Built an Autonomous RBI Regulatory Digest Agent with Hermes Agent
This is a submission for the Hermes Agent Challenge : Build With Hermes Agent The Problem Nobody Talks About Every time the Reserve Bank of India publishes a circular, somewhere inside an Indian bank, a compliance officer opens a PDF. They read it. They try to figure out what it means for their institution specifically. They write a summary email. They forward it to five department heads. They chase those department heads for two weeks to confirm it's been actioned. They build a spreadsheet to track all of this. And then the next circular drops and the cycle starts again. RBI publishes hundreds of circulars a year. SEBI publishes more. MCA publishes more still. Compliance teams at Indian banks are drowning — not because they're incompetent, but because the volume of regulatory output has outpaced any reasonable human ability to track it manually. The fine for missing a deadline isn't a polite reminder. It's a penalty notice. This is the problem I built for. What I Built RBI Regulatory Digest Agent — an autonomous multi-step agent powered by Hermes Agent that monitors RBI and SEBI publication feeds, reads every new circular, extracts structured action points from the regulatory text, and delivers a formatted intelligence report to compliance teams automatically. No human reads the circular first. No human decides what's important. No human routes it to the right department. The agent does all of that. The pipeline RBI/SEBI feeds → new circular detected → full text extracted → LLM analysis → structured action points → risk classification → HTML dashboard generated → email delivered Every action point extracted contains: What needs to be done — specific and actionable, not a vague summary Deadline — parsed from the circular text Responsible department — Credit, Compliance, Treasury, Operations, IT, Legal Evidence required — what documentation confirms completion Priority — Critical (overdue or <7 days), High, Medium, Low From a new circular to a structured compliance b
AI 资讯
CareSync: A Local Health Memory Agent for Family Caregivers
This is a submission for the * Hermes Agent Challenge * : Build With Hermes Agent What I Built CareSync is a local health memory agent for student caregivers. I'm Naomi, a 21-year-old engineering student. Between classes I help care for my grandma Kamala (78, high blood pressure, type 2 diabetes). I often forgot details from previous doctor visits, missed symptom patterns, and struggled to hand over care information to family members. CareSync solves that with longitudinal memory. Symptoms, meals, vitals, medications, and reports are stored in a local SQLite database. The CLI can search history, identify patterns, and generate appointment summaries. Hermes Agent exposes the same capabilities through natural language. What you get: One-line logging: ./caresync add "dizzy spell after lunch" Pattern search across weeks of history Medication tracking and report imports Doctor questions, appointment briefs, and handoff notes Full audit log of agent actions 7 Hermes skills mapped to real terminal commands Local-first design with no cloud storage CareSync is not medical advice. It helps caregivers observe, organize, and prepare. Demo The demo walks through: Logging a new symptom Searching health history for recurring patterns Generating doctor questions and appointment briefs Using Hermes in natural language to query past events Reviewing the audit trail of actions taken Example commands shown in the demo: ./caresync search --person Kamala --query dizziness ./caresync timeline --person Kamala ./caresync questions --person Kamala ./caresync brief --person Kamala --days 14 ./caresync chat "has grandma been dizzy before?" Code Repository: https://github.com/Byte-Sized-Brain/caresync Architecture My Tech Stack Hermes Agent Python 3.12 SQLite agentskills.io skill framework Terminal-based CLI Nous Portal How I Used Hermes Agent CareSync uses Hermes Agent as the orchestration layer between natural language and real caregiving workflows. I created 7 Hermes skills that map directly
AI 资讯
I built a global VC heatmap with their public email addresses.
And before you ask, yes, it's free. always will be. I built it in 48 hours. planning to release it tonight or tomorrow. submitted by /u/West_Subject_8780 [link] [留言]
产品设计
What are some old web features? Or quirks?
I saw someone mentioned a guest book and I had to look it up. Apparently people would leave public messages on a dedicated page and you can reply to them. Guess spam ruined that. Any thing else, didn't really get to experience it being young and all. Maybe some could make a comeback and one of us could implement it. submitted by /u/Successful-Title5403 [link] [留言]
AI 资讯
How do you securely verify musicians on your platform without expensive APIs?
I’m building a web app called EccoMuse, it’s a music discovery platform that lets listeners blend their music tastes with the tastes of artists, with features to monetize these unique playlist blends. Right now, I'm tackling the classic marketplace problem: distinguishing regular users/listeners from the actual artists. I need to make sure that if someone claims to be JPEGMAFIA or a small indie artist, they are actually that person (or their manager), and not an impersonator trying to hijack the profile. I want to avoid scraping Spotify bios (against ToS/fragile) and I can't rely on OAuth for X/Twitter because their new API pricing is too expensive for a bootstrapped summer project. Here is the manual verification system I currently have planned: Standard Login: User logs in as a listener (SSO/Email). Claim Profile: They paste their Spotify/Apple Music URL and their primary social handle (IG/X), then declare if they are the Artist, a Faceless Artist, or a Manager. The Challenge: The app generates a unique 6-digit code. The Proof: Public Artists take a webcam selfie holding the code, AND DM the code to our official Instagram from their verified/established artist account. Managers / Faceless Artists skip the selfie but must DM the code from the official artist account OR email us from the public booking email listed on their Spotify/socials. Manual Review: I look at the DM/Email, verify the account authority, cross-reference the selfie (if applicable), and manually approve the claim. Why it doesn’t feel fully fortified: While this works and costs $0 in API fees, it feels like it has some friction and potential holes. What if the manager doesn't have access to the artist's Instagram to send a DM? Is a webcam selfie too much friction for onboarding? How can I make sure an impersonator doesn't get through, I dont want someone to pretend to be an artist. I initially thought about asking them to put the code in their public IG or SoundCloud bio, but artists hate defacing
AI 资讯
Feeble Little Horse leans into digital weirdness on bitknot
From the opening moments of bitknot, it's obvious that Feeble Little Horse has found an entirely new gear. Where on Girl with Fish the blown-out textures were more '90s indie rock and shoegaze, on their latest LP, there's a more modern edge to the distortion and the riffs cut cleaner. Similarly, where the digital glitchiness […]
AI 资讯
Can I survive as a fullstack dev without upskilling after hours? Honest answers please
I'm 22, working as a fullstack developer at a startup. 9 hour days, decent enough at my job, but completely switched off after work hours. I don't want to leetcode after work. I don't want to learn new frameworks at night. I want to write, play guitar, and just exist peacefully. I'm not trying to become a senior dev or a tech lead. I just need the salary to sustain while I build something on the side that actually excites me. My question is — how long can someone realistically coast on existing skills without getting fired or becoming unemployable? And what's the bare minimum to stay relevant without burning out? Not looking for "passion for tech" lectures. Just honest experiences from people who've been there. submitted by /u/Available_Guess_7344 [link] [留言]
AI 资讯
The Fastest Part of Your Stack Is Already Installed: Rethinking Web IDEs
There is a fascinating psychological phenomenon in modern software engineering: the relentless pursuit of the upgrade. As frontend developers, we are conditioned to believe that speed and efficiency come from adopting the newest technologies. We migrate from Webpack to Vite to shave seconds off our build times. We transition between UI libraries in search of better reconciliation algorithms. We constantly audit our CI/CD pipelines. We treat performance as a destination we must reach by continuously adding or swapping out the moving parts of our toolchain. Yet, amidst this endless cycle of optimization, we consistently overlook the most sophisticated, highly optimized piece of software in our entire stack. It is the software you are using to read this article right now: the web browser. The Underappreciated Engine The modern browser is an absolute marvel of engineering. Over the past decade, teams of the world's most talented systems engineers have engaged in a fierce arms race to optimize browser engines like V8, SpiderMonkey, and JavaScriptCore. Today’s browsers feature Just-In-Time (JIT) compilation, sophisticated garbage collection, and massively parallelized rendering pipelines. They are capable of executing highly complex, interactive applications with a level of fluidity that was unimaginable a few years ago. However, when we evaluate developer tools—specifically the online IDE or the browser-based code editor—there is a stark contrast. The environments we use to write and test our code rarely reflect the speed of the engine they run inside. Why the Standard Web IDE Misses the Mark If you want to quickly prototype a component or isolate a bug, you will likely reach for a frontend playground or a popular Replit alternative. What happens next is often a masterclass in friction. The environment feels heavy. The interface is cluttered with features you didn't ask for. As you type, the live code editor experiences micro-stutters. The instant live preview isn't actu
AI 资讯
Making sense of the debate over AI psychosis
On the latest episode of Equity, we debate whether tech CEOs are "uniquely prone to AI psychosis."
AI 资讯
From Specs to Tickets: Automating Jira Setup with Node.js and the Jira API
The plan was simple Take the specs we'd written, turn them into Jira epics, stories and subtasks, and start sprinting. It took longer than expected. Here's what actually happened — and what I learned. Why automate Jira setup at all? HandyFEM has 8 epics, 37 stories and ~160 subtasks. Creating that manually would take a full day and be error-prone. More importantly: the specs were already written in a structured format. Translating structured data into Jira issues is exactly the kind of repetitive task that should be automated. So I wrote a Node.js script to do it via the Jira REST API. Problem 1 — Jira Spaces ≠ Jira Classic My account uses Jira Spaces — Atlassian's newer interface. The classic Jira has CSV import built in. Jira Spaces doesn't. This isn't documented anywhere obviously. You discover it by looking for the import option and not finding it. Lesson: always check which version of Jira you have before planning your workflow. The API still works, but some endpoints behave differently. Problem 2 — The API token wasn't the issue (until it was) First attempt: connection error. I assumed it was the token. It wasn't — it was an expired token from a previous session. Regenerating it fixed the connection. The real lesson: curl -u email:token https://your-domain.atlassian.net/rest/api/3/myself is the fastest way to verify auth before running any script. Problem 3 — customfield_10014 doesn't exist in team-managed projects In classic Jira, linking a story to an epic uses a field called customfield_10014 (Epic Link). In team-managed projects (Jira Spaces), this field doesn't exist. You use parent instead. The error was clear once I saw it: "customfield_10014" : "Field cannot be set. It is not on the appropriate screen, or unknown." Fix: remove customfield_10014 , keep only parent: { id: epicId } . Problem 4 — Board search doesn't work for team-managed projects The Agile API endpoint /rest/agile/1.0/board?projectKeyOrId=HFM returns empty for team-managed projects, even
AI 资讯
JWT Explained: What's Actually Inside That Token (with a free decoder)
If you've ever worked with auth, you've seen a JWT — a long string like eyJhbGci... split into three parts by dots. It looks cryptic, but it's surprisingly simple once you see inside. A JWT has three parts header.payload.signature Header – tells you the signing algorithm, e.g. {"alg":"HS256","typ":"JWT"} Payload – the claims (the actual data), e.g. {"sub":"123","name":"John","iat":1516239022} Signature – verifies the token wasn't tampered with (needs the secret/key) The header and payload are just Base64url-encoded JSON — not encrypted. That means anyone can read them. So: ⚠️ Never put secrets in a JWT payload. It's signed, not hidden. Decoding one yourself You can decode the payload in the browser console: const [, payload ] = token . split ( " . " ); console . log ( JSON . parse ( atob ( payload ))); Or, if you just want to paste a token and instantly see the header + payload (without sending it to a server), I built a free decoder that runs entirely in your browser: https://forgly.dev/tools/jwt-decoder Decoding ≠ verifying Reading a JWT is trivial. Trusting it is not — you must verify the signature on your server with the secret/public key before relying on any claim. Decoding just lets you inspect what's there. That's the whole mental model: a JWT is a readable, signed envelope — not a locked box.
开发者
The Unsolved Mystery of Lorem Ipsum
https://youtu.be/kL1PDqzqhM4 This video has corrected information on the history of Lorem Ipsum! submitted by /u/GreatRedditorThracc [link] [留言]
AI 资讯
Didn’t expect build asteroids to turn into a performance problem lol.
I added a few more asteroids to my build asteroids project and suddenly my FPS just tanked. Like completely unusable. Now I’m looking at my code and realizing my build asteroids loop is basically just redrawing everything every frame with no real optimization. I assumed request animation frame would kinda handle it automatically but yeah… that was me being naive. Is there a normal pattern people use when building asteroids so it doesn’t just fall apart as soon as you add more objects? submitted by /u/Tricky-Highway-7099 [link] [留言]
AI 资讯
Isn’t the internet breaking?
Maybe it’s just me, but I’ve been running into more and more half-working products lately. Buttons that do nothing. Checkouts that fail silently. Forms that throw errors with no explanation. And not from random small sites either, from companies that should absolutely know better. I think it’s the result of AI + fast shipping + less quality control. Teams are pushing out features at a speed that wasn’t possible 2 years ago, but the QA, testing, and ownership of quality hasn’t scaled with it. AI didn’t break the web. It just made it easier to ship things that were never properly checked. The other thing I’ve noticed: when something breaks now, you can’t even get to a real person. Support bots loop you in circles, and the actual humans who could fix it are buried somewhere behind 5 layers of auto-responses. Curious if others are seeing the same thing, or if I’m just unlucky lately. submitted by /u/Good-Locksmith-4978 [link] [留言]
AI 资讯
How I Built Hidden Collector Game in Unity
As part of my game development journey, I recently created Hidden Collector , a Unity-based game where players explore levels and collect hidden items while progressing through different challenges. This project started as a way for me to improve my Unity and C# skills, but it quickly became an opportunity to learn about game design, UI systems, audio management, scene transitions, and player experience. What I Worked On While building Hidden Collector, I implemented: Player movement and interactions Collectible item systems Multiple game levels UI menus and game screens Audio and sound effects Progress tracking Game flow and scene management Challenges During Development One of the biggest challenges was making different game systems work together smoothly. Something as simple as collecting an item often required updates to UI elements, game state management, and progression systems. Debugging these interactions taught me a lot about organizing Unity projects and writing maintainable code. What I Learned This project helped me gain experience with: Unity Engine C# scripting Game architecture UI implementation Audio management Debugging and testing Most importantly, I learned that building complete projects teaches far more than following tutorials. Play the Game You can try Hidden Collector here: https://sinxcos07.itch.io/hiddencollector Screenshots What's Next? I'm continuing to improve my game development skills by building new projects, experimenting with different mechanics, and learning more about creating engaging player experiences. If you try the game, I'd love to hear your feedback. By Suryansh Sinha (sinxcos07) Connect With Me GitHub: https://github.com/sinxcos07 LinkedIn: https://www.linkedin.com/in/suryansh-sinha/ Play Hidden Collector: https://sinxcos07.itch.io/hiddencollector
AI 资讯
🚀 Building an open-source email blast tool — free, self-hosted, no Mailchimp needed. Looking for contributors to help add: 📊 Open & click tracking 🐳 Docker support All issues are open. Jump in 👇 https://github.com/nikhilt101/email-blast-tool
GitHub - nikhilt101/email-blast-tool: Open source HTML email sender tool using CSV/XLSX + Gmail SMTP · GitHub Open source HTML email sender tool using CSV/XLSX + Gmail SMTP - nikhilt101/email-blast-tool github.com
AI 资讯
Why your React tournament bracket breaks in Safari (and a 4 KB pure-CSS fix)
You build a tournament bracket with a popular React library. In Chrome it's perfect — neat columns, clean connector lines. Then you open it on an iPhone, or in Safari, or inside your Capacitor app… and every match is crammed into the top-left corner, stacked on top of the round headers. If you've ever shipped a bracket to iOS, you've probably seen this exact bug. Here's why it happens — and a tiny library that fixes it for good. The symptom It looks fine everywhere Chromium runs (Chrome, Edge, Android WebView) and completely broken everywhere WebKit runs: Safari (macOS and iOS) iOS WKWebView Capacitor / Cordova apps Electron-on-WebKit The matches don't just shift a little — they all render at coordinate (0,0) of the bracket, piling on top of each other and the headers. The cause: SVG <foreignObject> in WebKit Most React bracket libraries — @g-loot/react-tournament-brackets , react-tournament-bracket , and friends — render the bracket as an SVG and place each match's HTML inside a <foreignObject> positioned with x / y attributes. WebKit has a long-standing bug: it ignores x , y , and transform on <foreignObject> and positions the content relative to the top-level <svg> instead of the foreignObject's own coordinates. Every match therefore collapses to the origin. And there's no CSS escape hatch — x , y , and transform are all ignored on foreignObject in Safari, so you can't nudge the content back into place. I even tried patching a library to wrap each match in a <g transform="translate(x,y)"> instead of a nested <svg x y> ; WebKit ignores ancestor transforms for foreignObject positioning too. The SVG approach is simply a dead end on WebKit. The fix: don't use SVG at all A bracket is really just columns of cards joined by connector lines — and both are expressible in plain CSS. Here's the key insight. Put each round in a flex column where every match sits in an equal flex: 1 slot. Because each round has half the matches of the previous one, a match's slot spans exactl
开发者
AstroFit – My Fitness Tracking Web Application
By Suryansh Sinha (sinxcos07) Introduction Recently, I built AstroFit , a fitness-focused web application as a personal project to learn more about modern web development, deployment, databases, and building complete applications from idea to production. This project helped me understand how different parts of a web application work together, from the user interface to backend functionality and deployment. Why I Built AstroFit I wanted to work on a project that felt practical and useful while also helping me improve my development skills. Instead of creating a simple clone project, I decided to build a fitness application where I could experiment with real-world features and deployment workflows. Development Journey Building AstroFit involved much more than just creating pages and connecting them together. Some of the areas I explored while working on this project included: Frontend development Backend integration Database management Authentication systems Deployment and hosting Debugging production issues One of the biggest learning experiences was understanding how different technologies communicate with each other in a complete application. Future Plans I plan to continue improving AstroFit by adding more features, refining the user experience, and expanding its capabilities over time. This project is still evolving, and I'm excited to keep working on it. Project Links Live Demo: astrofit-fitness.vercel.app GitHub: sinxcos07 / astrofit-frontend Fitness platform combining workout tracking and astrology-inspired personalization. AstroFit AstroFit is a modern fitness web application that combines workout tracking with astrology-inspired personalization to create a unique and engaging fitness experience. Features Modern responsive UI Astrology-inspired fitness experience Workout tracking interface User authentication system Backend integration Smooth and interactive design Mobile-friendly layout Tech Stack Frontend HTML5 CSS3 JavaScript Backend Node.js Express.js SQL
AI 资讯
Why Most AI Agents Forget Everything — And Why Hermes Agent Changes the Game
This is a submission for the Hermes Agent Challenge : Write About Hermes Agent What if the biggest limitation in AI today isn't reasoning, model size, or context windows? What if it's memory? Every morning, millions of people open ChatGPT, Claude, Gemini, or another AI assistant and start a conversation. The AI seems intelligent. It writes code. It explains concepts. It helps brainstorm ideas. It can even help design an entire software architecture. Then the conversation ends. Tomorrow? It remembers nothing. Imagine hiring a senior engineer who forgets everything at the end of every workday. Every morning you would need to explain: What your company does How your product works Which technologies you use Why certain decisions were made What happened yesterday Nobody would call that employee productive. Yet this is exactly how most AI systems operate. And it reveals something important: Most AI agents aren't actually learning from experience. They're simply reasoning over whatever context happens to be available right now. That distinction may define the future of agentic AI. Because the next generation of AI won't just need better reasoning. It will need memory. And that's where Hermes Agent becomes interesting. The Strange Reality of Modern AI The public perception of AI often looks like this: User → AI → Intelligence But the reality is closer to this: User → Context Window → AI → Response The AI only knows what exists inside its current context. Once that context disappears, so does most of its understanding. This is why many AI experiences feel surprisingly repetitive. You spend 30 minutes explaining your project. The AI finally understands your goals. The answers become better. The recommendations become more relevant. Then the session ends. The next conversation starts from scratch. Not because the model isn't powerful. But because the knowledge never became persistent. Context Windows Are Not Memory A context window is not memory. It is temporary working space.