Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Google released a 1MB AI model that quickly catches malware disguised as PDFs. Magika is an open source file detection system. It doesn't trust file extensions. Instead, it reads the actual content to figure out what a file really is. That means malware disguised as a PDF gets caught....

13,216 Aufrufe • vor 5 Monaten •via X (Twitter)

4 Kommentare

Profilbild von AlphaSignal
AlphaSignalvor 5 Monaten

Repo: Check out to get a daily summary of top models, repos, and papers in AI. Read by 280,000+ devs.

Profilbild von Pritesh Damani
Pritesh Damanivor 5 Monaten

This is a really good callout. Very easy to add to any document upload pipeline and eliminate risk early on!

Profilbild von Home
Homevor 5 Monaten

This is basically a security mindset upgrade encoded into software: don’t trust labels, trust evidence. By reading raw file content, the system removes one of the oldest and simplest attack vectors in malware delivery

Profilbild von Max Slinger
Max Slingervor 5 Monaten

1MB is wild for something doing content analysis. most antivirus heuristics are bigger than that and way dumber

Ähnliche Videos

Microsoft spent $13 billion and 3 years building an AI that knows your work context. Every time you open it, it still asks what you're working on. This developer set up a plain text file in 2 minutes. The file is called CLAUDE.md. It loads before every session. Before he types a single word. It already knows his name. It already knows his writing style. It already knows what he's building, who it's for, and what he never wants to see in a response. He doesn't introduce himself anymore. He doesn't explain his preferences anymore. He doesn't correct the same mistakes twice. He just works. No $30/month Copilot subscription. No Microsoft 365. No IT approval. No data sharing agreement. No onboarding. Just a plain text file, a free text editor, and 21 instructions a developer distilled from Andrej Karpathy's research. Those 21 instructions moved Claude's coding accuracy from 65% to 94%. The file hit #1 on GitHub with 82,000 stars. Most people using Claude right now have never heard of it. Microsoft has 221,000 employees, $13 billion invested in OpenAI, and a direct integration into every Windows laptop sold on the planet.. they built an AI assistant most companies pay $30/user/month for that still doesn't know your name. This developer has a laptop, a text file and a 2-minute setup.. he built something that knows more about how he works than any enterprise AI on the market. The $50 billion AI personalization industry just got embarrassed by a .md file. full breakdown down below

Dep

14,179 Aufrufe • vor 5 Monaten

I mentioned previously that I had been working for a couple months now on a system for applying AI to music theory. It's one of my few closed-source projects. It's a combination of a Rust cli tool, mtdt (music_theory_data_tool), which handles all mechanical aspects of importing and exporting and manipulating music in any format (midi, PDF, MusicXML, audio, etc.), and a huge skills library which is based on massive amounts of academic music theory and more. I asked the system to create a Bach fugue using GPT-6 Astra and the mtdt tool and the relevant skills, and it created the following. Notably, this didn't involve any external software other than mtdt, including the creation of the print-ready PDF score. It can do much, much more than this though. It can take a melody and write counterpoint for it, grounded in the theory, and using the mtdt tool to help it mechanically explore the space of "legal" possibilities while using its skills and intelligence to make artistic choices. It can make a ragtime version of a midi file. It can take a piano piece and re-orchestrate it for a brass band or string quartet. It covers a huge amount of stuff across over 300 skills. I'm not sure what I will do with the system ultimately, but I envisioned it as being an AI workstation for professional composers and musicians. You can see in the screenshot that it does a huge amount of intermediate work that is inspectable and legible; it's intentionally NOT a black box. Instead of outsourcing the entire musical process end-to-end like Suno, this system is about augmenting the creative human with as much or as little automation as desired. I continue to work on it with a couple agents every single day and it will keep getting better and better, and then with each new model release it will be better able to leverage the vast amount of expertise and knowledge about music that is already embedded in its cli tool and skills library.

Jeffrey Emanuel

39,555 Aufrufe • vor 25 Tagen

Finally, an open-source runtime security layer for your agent harnesses. AI agents can call tools, run shell commands, modify files, and interact with production systems. But when something goes wrong, teams often have to reconstruct what the agent actually did from scattered logs after the fact. Agent Beacon is built to change that. It runs locally and records agent activity as it happens, including: → Tool calls → Shell commands → File changes → Approval decisions → Session and harness context The useful part is that it normalizes all of this into the same event format across 23+ agent harnesses. So instead of writing different detection logic for Claude Code, Codex, or another harness, security teams can reason about the underlying action itself. A command executed is a command executed, regardless of which harness produced it. Beacon also records how confidently an event was captured. An action can be directly observed from the runtime or inferred from indirect evidence. That matters when you start writing security rules against this data. For example, you can detect when an agent reads an environment variable, modifies a sensitive file, executes a suspicious command, or performs an action without the expected approval. And the detection happens while the session is still unfolding, not days later during incident reconstruction. Everything runs locally by default. You can inspect sessions through the dashboard, write your own detection rules, or forward the same normalized events to tools like Splunk, Datadog, Elastic, Sentinel, or CrowdStrike. Beacon GitHub: (don't forget to star 🌟) I also wrote a detailed article on the same, covering how important runtime security is and how to build it for your agent harnesses. The article is quoted below.

Akshay 🚀

27,859 Aufrufe • vor 24 Tagen

THIS MIGHT BE THE #1 OPEN-SOURCE REPO FOR CLAUDE CODE RIGHT NOW. IT GIVES CLAUDE A MEMORY AND SLASHES YOUR TOKEN COST ON EVERY QUESTION The repo is safishamsi/graphify, a free open-source skill that turns any codebase into a knowledge graph Claude Code can read instantly. Instead of grepping through your files every session, Claude gets a map of how everything connects The problem it fixes: Every time you ask Claude Code about a big repo, it does the same thing, greps through dozens of files like a brute-force Ctrl+F, blows through your context window, and sometimes still misses the answer hiding in a file nobody searched. Claude Code has no memory of how your project is structured. Every session starts from zero What it does: It maps your entire codebase into a knowledge graph, capturing not just which files exist, but which functions depend on which, which modules are central, and which files cluster around the same concern. Claude queries the map instead of scanning files How it works, three passes: 1. Code structure, free and local. Tree-sitter parses your files and pulls out classes, functions, imports and call graphs. No LLM, no tokens, just your actual code mapped deterministically 2. Audio and video, if you have them. Transcribed locally and folded into the graph 3. Docs, papers, images. Here an LLM does semantic analysis, figuring out what each document means and where it fits. Only the meaning gets sent up, never your raw source It saves you money: Normally a question about a big repo makes Claude spawn explore agents that scan file after file, eating your context window and your token budget before you get an answer. With the graph already built, Claude queries the map instead of re-reading the codebase every time. Same answer, a fraction of the tokens. The graph only gets built once, then a hook rebuilds it after each commit for free, so you never pay that scanning cost again. The bigger the repo, the bigger the gap The best parts: it's a skill, so once installed Claude knows when to use it without you memorizing commands. It works on non-code folders too, point it at docs or notes and it can spin up an Obsidian vault How to add it to your Claude: 1. Install Claude Code if you haven't: npm install -g Paul Jankura-ai/claude-code 2. Add the skill: claude skill add safishamsi/graphify 3. Open your project folder and run /graphify . to build the graph 4. Optional, make it automatic: graphify hook install so the graph rebuilds after every commit That's it. Ask Claude about your repo and it reads the map instead of burning tokens on a file hunt Bookmark this

Yarchi

56,502 Aufrufe • vor 3 Monaten