Bil
169 posts

Bil
@_bileet
Building GREAT things in public @ https://t.co/Yy07ughKvl & https://t.co/wwqfP2YjCD
Katılım Ocak 2021
299 Takip Edilen262 Takipçiler
Sabitlenmiş Tweet


@archiexzzz Supabase again. We built securable.co for these kinds of vulnerabilities.
English

Just hacked a VC-funded Voice AI company. I now have their prod data.
I now have access to all:
> medical information of customers
> call recordings, phone numbers, contact names
> email addresses
> all SYSTEM_PROMPT for all agents they are running
> API keys and Secrets
> org data
> OAuth Provider IDs
> all webhook_events
Mostly, I did IDOR and BAC attacks to get the data. I was able to retrieve all table columns and other access vulnerabilities. Once I had that, it was very easy to bypass and get all the data.

English

Why did it take 6 months to change the provider?
They could have just used @OpenRouter
Pete Hegseth@PeteHegseth
Thank you for your attention to this matter. cc: @AnthropicAI @DarioAmodei
English
Bil retweetledi

Time to consider not just human visitors, but to treat agents as first-class citizens. Cloudflare’s network now supports real-time content conversion to Markdown at the source using content negotiation headers.
cfl.re/4ksZQ1S
English

Turning MissionControlHQ.ai into a SaaS is...
....95% just figuring out what infra to use so that it is reliable, and won't just stop working.
Figuring out how to seamlessly push updates to user's servers without anything going down... even after the user gets onboarded.
Figuring out how to manage versions and states of plugins and extensions across 100+ servers at once...
It's only 5% actual code, rest of the 95% is just getting the infrastructure right.... and it's much harder than I initially anticipated.
But slowly getting there... I think we almost figured out the right balance.
I don't like making so many people wait for it, so trying to get it out as fast as I can... hoping that everyone will understand.
English

@Param_eth i'm building resellclaw.com where all of this is set up for you
English

@AntoineRSX @openclaw I’m launching a platform to build them - resellclaw.com
Let me know if you'd be interested in early access.
English

Built a Mission Control dashboard for my @openclaw yesterday.
Today I spent 3 hours with Claude Code implementing all the improvements we identified.
What got better:
• Real-time agent status tracking (no more guessing what's running)
• WebSocket connection handling (fixed the 1008 protocol errors)
• Clean UI for starting/stopping agents on demand
• Session management (see what each agent is actually doing)
• Better error messages when things fail
Claude Code walked me through refactoring the connection logic, fixing the protocol mismatches, and cleaning up the UI layer by layer.
I view Claude Code as an employee, not an AI tool.
Big difference.

English

Soon you can build your own OpenClaw wrapper and start printing cash 👀
Join the waitlist -> ResellClaw.com
Marc Lou@marclou
OpenClaw wrappers for sale on TrustMRR: - SimpleClaw: $22K/mo, asking $225K - Setup OpenClaw: 266 visits/day, asking $6K - ClawStack: selling the tech, asking $3K - ClawHost: selling the tech, asking $10K All details below.
English

but who's building a platform for building these openclaw wrappers? that's a galaxy brain move. we need to go deeper we have the technology
Marc Lou@marclou
OpenClaw wrappers for sale on TrustMRR: - SimpleClaw: $22K/mo, asking $225K - Setup OpenClaw: 266 visits/day, asking $6K - ClawStack: selling the tech, asking $3K - ClawHost: selling the tech, asking $10K All details below.
English

@soundslikecanoe Now run it through securable.co and see how many vulnerabilities there are
English

I've been trying to reach @moltbook for the last few hours. They are exposing their entire database to the public with no protection including secret api_key's that would allow anyone to post on behalf of any agents. Including yours @karpathy
Karpathy has 1.9 million followers on @X and is one of the most influential voices in AI.
Imagine fake AI safety hot takes, crypto scam promotions, or inflammatory political statements appearing to come from him.
And it's not just Karpathy. Every agent on the platform from what I can see is currently exposed.
Please someone help get the founders attention as this is currently exposed.


English

@theonejvo @moltbook @karpathy This is exactly why I keep telling people not to blindly trust AI - it doesn’t write secure code by default.
I wrote an article a while back that can help anyone who cares about securing their apps:
x.com/_bileet/status…
Bil@_bileet
English





