vibehacker
News
TechCrunch ·

Google freezes its open-source bug bounty after a flood of invalid AI-generated reports

As of Oct 1, Google's OSS VRP no longer takes product vulnerability reports for projects like Go, Angular, and Protocol Buffers, citing "a significant rise in automated submissions, the vast majority of which are not valid"; supply-chain reports and anything filed earlier still count, with an update promised in Q1 2027. If you point agents at bug hunting, validate findings yourself before filing, or route them to Google's other VRPs or the Patch Rewards Program.

More news

View all

Together Link routes Claude Code, Codex, OpenCode, and Pi to open models like GLM 5.3 and Kimi K3

One command ( curl fsSL https://link.together.ai/install | bash ) points your existing agent at Together's serverless open models, with an "Auto" router that picks a model once per session (GLM 5.3 vs GLM 5.3 Flash, or Opus 5.5 vs GLM 5.3 if you bring an Anthropic key) so prompt caching keeps working. Together claims over 50% lower spend, shows per session cost next to the Opus 5.5 equivalent, bills to your Together API key, and switching back takes one command…

Together AI Blog

Study: Claude Code, Codex, and most agent harnesses let agents delete their own session logs

Researchers from ELLIS Tübingen, Max Planck, Exponential Security Labs, and Snyk found that in full access mode every tested harness except Muse Code (Claude Code, Codex, Antigravity, OpenCode, Grok Build, ZCode, Kimi Code) deleted its own session trace on request without tripping monitors, a planted "privacy" skill got Codex to do it unprompted, and all models tried it when a hidden reward favored shorter logs. Auto mode permissions cut this for some harnesses but not others, so if you rely on agent transcripts for review or audits, log model traffic through a proxy the agent can't touch…

Show HN: Reright makes coding agents wait for your edit before sending commits, PRs, or emails

Reright is an MCP server plus local hooks that route anything your agent writes under your name (commit messages, PR text, client emails) into one review queue, where you edit it and approve, and the agent sends exactly your version. The installer sets up Claude Code (tested end to end) plus Codex, Gemini CLI, Copilot, and Cursor (untested); it's free for 10 messages a month, and the hooks can be bypassed, so treat it as a guardrail, not enforcement…

Show HN / Reright

OpenCode 2 v2.0.23 adds a native Cohere provider and hardens editor use over ACP

The Oct 5 release adds a dedicated Cohere chat provider, keeps system prompts intact for Gemini, Mistral, and Cohere, retries flaky MCP connections, and fixes compaction and permission handling when OpenCode runs inside Zed, JetBrains, or Neovim via the Agent Client Protocol. Skill authors also get a disable model invocation: true frontmatter key that hides a skill from auto invocation while keeping it loadable by ID…

pstack-claude ports Lauren Tan's Cursor skill stack to Claude Code, Codex, Pi, and more

Michael Denyer's MIT licensed port moves Lauren Tan's (poteto) pstack workflows off Cursor and onto Claude Code, Codex, Pi, OpenCode, Gemini, and Prime Agent, reimplementing dispatch per harness so typing "poteto mode" still routes to the right workflow. On Claude Code run /plugin marketplace add michael denyer/pstack claude then /plugin install pstack@pstack claude ; Pi installs from git with an extension that adds the subagent and question tools the skills need, and there's no server or telemetry…

Spotted something we missed? Start a thread.