Guy Vago
38 posts

Guy Vago
@GuyVago
Sales by day, decks by night | Shooting people (with my camera) | Talking love & non-monogamy on the mic | Yoga keeps me sane
Israel Katılım Ekim 2021
46 Takip Edilen7 Takipçiler

Companies already knows that @QodoAI is the best code review platform. Now external benchmarks shows it too.
#onlywayisup

English

There's a section on your resume you're probably ignoring. The skills section. Most people write generic stuff. But if you match the exact keywords from the job posting, your resume jumps the line. jobtailor.work does it for you in two minutes.
English

Stop sending the same resume to every job.
I was applying to 15 jobs a week with the exact same resume. One callback a month.
Then I started tailoring each one. Three callbacks the first week.
Free tool at jobtailor.work
English

@hrprtsingh9 @hellokillian @QodoAI Just found another one 4m yesterday. popular AI coding agent with a global axios interceptor that attaches the auth token to every HTTP request.
Including external URLs!
One third-party call and the token is leaked.
Already opened an issue with the maintainer.
English

@GuyVago @hellokillian @QodoAI 46 issues across 10 PRs and a remote code execution without auth is exactly why open source AI tools need security audits before anyone puts them anywhere near production. Most people skip this step entirely.
English

User scanned @hellokillian's open-interpreter with @QodoAI's AntiSlop Scanner
46 issues across 10 PRs. Including a security finding: OpenAI-compatible endpoint lets any client remotely enable auto_run (automatic code execution) without auth
Full report: qodo.ai/ai-code-review…
English

@mckaywrigley @cole_medin These aren't theoretical. Every finding was verified to still exist on main.
You can scan your repo by tagging QodoAI with the #antislop hashtag and your owner/repo right here on X.
Also via no signup: qodo.ai/ai-code-review…
Not just OSS - private repo's too! all self serve
English

Also noticed @mckaywrigley chatbot-ui: 35 issues, including a file size limit bypass where parseInt returns NaN and silently disables the check.
And @cole_medin's Archon: 21 issues, all confirmed on main. PDF content leaked to INFO logs, missing numpy dep breaks embeddings.
English

An AI coding agent shipping code that an AI code reviewer catches.
@Alibaba_Qwen Code scanned with @QodoAI
10 PRs. 24 issues. 13 critical. Still on main.
Hook trust validation? Dead code. Every hook runs silently.
#antislop
linkedin.com/posts/guyvago_…
English
Guy Vago retweetledi

@QodoAI CEO and co-founder of @QodoAI here 👋
Giving away Qodo (Teams) for 1 month free,
so you can see for yourself
promo code:
UNBIASED
qodo.ai/get-started/
English

