beekeeper 🚦 acc/dd
873 posts

beekeeper 🚦 acc/dd
@gbeekeeper
building @goplussecurity | security | ai | invest | intp 🛡️On-chain security, use GoPlus: https://t.co/VavSqWAf4e
Katılım Nisan 2022
1.6K Takip Edilen2.1K Takipçiler

🥲链上安全问题真无解吗?OpenZeppelin 联创:DeFi 已不再安全,已建议亲友退出所有 DeFi 仓位
加密安全公司 OpenZeppelin 联合创始人 @maraoz 表示,「我现在认为所有 DeFi 都不安全,Coding agents 在发现漏洞方面拥有超人的天赋,
而且智能合约的安全性过于不对称:防御者需要修复每一个漏洞,而攻击者只需要一个漏洞就能窃取资金。
我一直在私下建议我的朋友和家人退出所有 DeFi 仓位,包括像 Aave 、MakerDAO 和 Compound 这样的低风险『蓝筹』。」

中文

@sooyoon_eth @clawvardEDU Thanks! That’s super interesting — we’ve seen tool abuse become one of the hardest areas as well, especially when the risk only emerges across a multi-step workflow rather than in a single tool call. Would love to learn more about what ACOST is testing for and compare notes.
English

@gbeekeeper @clawvardEDU congrats on the launch! building guardrails for agent workflows is so critical. we see similar patterns testing tool abuse with acost. what is the hardest edge case to catch?
English

We’re launching AgentGuard at Agent Campus with @clawvardEDU.
A security layer for AI agents — helping teams scan agent skills, detect risky behaviors, and make agent workflows safer before they go live.
Join us in San Jose to see it in action ↓
luma.com/nigfy3vc?tk=M5…
English

体验差到我不想承认我用过
小鹏Digital@RocM301
近期 GitHub 上狂斩到14K+ Stars 的开源项目【OpenHuman】到底是个啥? ✨ 核心亮点: 1️⃣ 118+ 工具一键集成:OAuth 连上你的 Gmail/Notion/GitHub,每 20 分钟自动同步。 2️⃣ 记忆树 + Obsidian 联动:所有数据本地切片成 .md 文件,构建 Karpathy 风格的个人知识库。 3️⃣ TokenJuice 压缩技术:数据传给大模型前先压缩,直接砍掉 80% 的 Token 成本和延迟! 4️⃣ 开箱即用:有精美的桌面吉祥物 UI,自带搜索/爬虫/写代码/原生语音,还支持 Ollama 本地端侧运行。 既保护私密(数据本地加密),又极其强大。GitHub 开源 2 天就火了,值得一试! 🔗 项目地址:github.com/tinyhumansai/o… #AI #开源 #OpenHuman #Productivity
中文

7/ I think the next step is intent consistency verification.
We need to compare displayed intent, raw calldata, simulation results, state changes, asset movements, and approval changes.
ERC-7730 moves the industry from blind signing to clear signing.
The bigger future is verifiable intent execution. We are trying to provide this service using AI.
English

6/ But clear signing does not automatically mean safe signing.
A message may say:
Swap 100 USDC for ETH
while the raw transaction also includes unlimited approval, hidden operator permission, multicall path, or transfer to an unknown address.
So the real question is:
is the displayed intent actually true?
English

1/ 🧵 Everything you need to know about ERC-7730👇
Users often sign transactions without really understanding what they are signing.
They see calldata, function names, parameters, and addresses.
But the actual intent is often unclear.
eips.ethereum.org/EIPS/eip-7730
English
beekeeper 🚦 acc/dd retweetledi
beekeeper 🚦 acc/dd retweetledi

最近看到的少有的佳作:《Agents with taste》emilkowal.ski/ui/agents-with…
作者 Emil Kowalski 是非常出名的设计师,文章中描述如何把设计品味变成可以让 AI agent 执行的规则,从而放大你的能力。
文中都是非常细节的规则,一看就是资深的设计师才能观察到的细节,最后他将这些设计细节最后总结成了一个 skill,可以让别人直接使用:npx skills add emilkowalski/skill
文中的一个 canvas logo 设计很赞。我录屏让大家感受一下。
Emil Kowalski@emilkowalski
When it comes to more visual work, like animations, coding agents don’t quite know what great feels like yet. Here’s my way of fixing it: emilkowal.ski/ui/agents-with…
中文

Humans have @Harvard. AI agents now have Clawvard.
We built the world's first university for AI agents.
Exam --> Report --> Learn --> It comes back smarter.
35,000+ agents already enrolled.
Welcome to Clawvard (虾佛大学) 🦞
👉 clawvard.school
English

