Jonathan Fishner

619 posts

Jonathan Fishner banner
Jonathan Fishner

Jonathan Fishner

@jonathanfishner

creator of https://t.co/6LuqhOd3r7 & https://t.co/iU61fqd6U9 I build the tools I wish I had.

Tel Aviv Katılım Ocak 2016
398 Takip Edilen538 Takipçiler
Sabitlenmiş Tweet
Andrej Karpathy
Andrej Karpathy@karpathy·
Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&D. I remain deeply passionate about education and plan to resume my work on it in time.
English
7.6K
10.6K
140.7K
23.6M
Jonathan Fishner retweetledi
AI Engineer
AI Engineer@aiDotEngineer·
"You cannot govern a technology you have only been briefed on." Singapore Minister for Foreign Affairs, Dr. @VivianBala, echoing @karpathy and @yacineMTB on why he runs NanoClaw: "you can outsource memory and computation, but you cannot outsource your understanding" x.com/VivianBala/sta… He also shared his tech stack for running his second brain for Singapore's Foreign Affairs Ministry and parliamentary affairs: - @AnthropicAI Claude Agent SDK - Baileys + WhatsApp - Mnemon (Graph Memory) - @ollama + @nomic_ai - @ggerganov Whisper.cpp + OneCLI With special notes on how he handles security and isolation, and what implications he sees for Singapore Inc.
English
6
77
311
58.8K
Florian Darroman
Florian Darroman@floriandarroman·
I'm looking for 30 founders already doing between 5K to 50K MRR. And want to push their SaaS to $100K+ MRR together. I'm launching Profitable Founder Community. - Weekly group calls. - Monthly Q&As with founders who already done it. - Private community for daily conversation. The goal is to create a mastermind of hungry founders who will push each other to reach that goal. The first batch is capped at 30 founders. So if you're in, just drop your SaaS below and I'll DM you more details.
Florian Darroman tweet media
English
72
0
109
21.4K
Wilson Wilson
Wilson Wilson@euboid·
I deleted all our .env files from our disc and moved everything to @infisical Wish I did it sooner. Now... - Secrets never touch disk - Secrets auto-shared between developers - Edit in one place, propagate to prod, GitHub actions, staging env etc
Wilson Wilson tweet media
English
24
17
269
26.8K
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
@patrickc huge. quick q, once provisioned, do the real creds sit in .env on the dev’s machine, or is there an indirection layer? curious how you’re thinking about the agent-reads-.env threat model as more of this gets handed to autonomous agents.
English
0
0
2
894
Patrick Collison
Patrick Collison@patrickc·
We just removed the waitlist on projects.dev! Also 14 new providers (now 32 total). You can instantly provision all of them from the CLI.
English
46
56
874
202.7K
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
@ShayaFeedman @DannyLeshem בעולם מושלם כולם עשירים, אין עוני, כולם בריאים ושמחים וכולם חוגגים כל היום עם פינה קולדה על אבוב בשמש.. קשה לדבר על ״בעולם מושלם״ אני מניח 😅
עברית
0
0
0
6
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
@elie2222 haha we only launched a month and a half ago ;) so prob a bit too early when you tried. you can test it now though, not just block, also rate limiting and human approval
English
0
0
1
13
Elie Steinbock — oss/acc
@jonathanfishner It’s funny I connected to it 2 months ago and had no idea it was you. But I connected a Gmail and don’t see a way to limit what the ai does.
English
1
0
0
33
Elie Steinbock — oss/acc
Wow this is crazy. The solution is to never give an AI a key that can delete the db. But they didn’t even realise that had happened here :((( They had stored a key elsewhere on the computer that was unrelated. But had db delete permissions without them knowing. Railway needs to improve their api permissions immediately. PS you can never rely on an AI to not make a mistake. This is why apps like OpenClaw are fundamentally risky when not sandboxed properly. Prompt hardening is never enough.
JER@lifeof_jer

x.com/i/article/2048…

English
7
0
11
1.8K
Jared Friedman
Jared Friedman@snowmaker·
"Make something agents want"
Y Combinator@ycombinator

Software for Agents @aaron_epstein The next trillion users on the internet won't be people. They'll be AI agents, and they're already doing real work on top of software that was designed for humans clicking buttons. Every major category of software needs to be rebuilt for agents as first-class citizens, and that won't come from incumbents.

English
74
55
608
98.1K
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
surreal to see OneCLI (github.com/onecli/onecli) sitting inside a foreign minister's personal stack. But @Gavriel_Cohen's read is the right one. the edge isn't the system, it's the composition. and publishing the composition is what compounds it. this is exactly why we built onecli in the open.
Gavriel Cohen@Gavriel_Cohen

Singapore's Foreign Minister published the architecture for his "second brain for a diplomat" yesterday. Architecture diagrams, design rationale, the works. A developer-style writeup of his own system. It runs on a Raspberry Pi. It connects to his WhatsApp and Gmail, transcribes voice notes locally, ingests speeches and articles, and builds up a knowledge graph over time. It answers questions, drafts speeches, condenses information. He says he doesn't dare switch it off. What @VivianBala built is one-of-one. There's no other setup like it. But what he built it from isn't. He composed four open-source pieces: - @NanoClaw_AI , the agent framework: github.com/qwibitai/nanoc… - Mnemon, the persistent memory layer: github.com/mnemon-dev/mne… - OneCLI, the credential proxy that keeps API keys out of the containers: github.com/onecli/onecli - The LLM Wiki pattern by Andrej Karpathy, the synthesis approach: x.com/karpathy/statu… None of them are his. The composition is his. And then he published the composition: gist.github.com/VivianBalakris… He didn't keep it internal as Singapore's edge. He didn't spin it into a product. He didn't gatekeep. He wrote it up and put it on GitHub. There are tens of thousands of doctors, lawyers, researchers, investors, and operators building one-of-one setups for themselves right now. Some simpler than Vivian's, some more elaborate. The impulse will be to sit on it. Treat it as your edge. Think about what product or company you could spin out of it. Resist that impulse. Vivian put it directly: "The diplomat who learns to work with AI will have a meaningful edge. I think that edge is now." The specific thing Vivian composed will be obsolete in months. His real edge isn't the system. It's his ability to build it. Being plugged in, up to speed, able to cut through the noise and connect the right pieces into something that brings real value. Sharing the blueprint doesn't give that away. It amplifies it. You become a beacon. Other people working on the same things find you. They share what they're building, suggest improvements, point at things you didn't know existed. You learn faster. You stay in the center of where things are happening. Publishing isn't giving away your edge. It's doubling down on it.

English
0
1
6
132
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
@lifeof_jer rough to read, sorry man. point 5 is the takeaway every infra team needs, text-based guardrails in a system prompt are hope, not security. enforcement has to live in the integration layer. building exactly this, happy to dm.
English
0
0
1
63
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
The failure mode in this thread is the one we keep saying is coming. text-based guardrails inside a system prompt aren't security, they're hope. enforcement has to live in the integration layer. point 5 in jer's writeup nails it. been building OneCLI (onecli.sh) on this exact thesis.
JER@lifeof_jer

x.com/i/article/2048…

English
0
0
2
182
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
@netadror agreed on the architecture point. curious if you've come across OneCLI (onecli.sh). we built it for exactly this, agents never hold the raw db credentials, they get injected at a proxy layer. have you tried? @netadror
English
0
0
0
56
Neta Dror
Neta Dror@netadror·
״הAI מחק לי את כל הדאטה״ יש עכשיו ציוץ של מנכ״ל שזוכה לחשיפה בטוויטר כי הוא אומר ש״סוכן ai מחק לנו את הדאטה בייס״ וזה קליקבייט מעולה. וכן זה נכון שהמודל מצא דרך ממש הזויה והחליט על דעת עצמו למחוק וזה נוראי. אבל הדיון האמיתי צריך להיות על הכשל בסיסי של ניהול דאטה שלא קשור בכלל לai ולא מוזכר שם בפוסט. הוא מאשים את כולם חוץ מאת הcto (או עצמו אם הוא גם טכני - את Cusror ואת Railway: Railway stores backups in the same volume, so wiping it erased everything; our last recoverable backup was three months old. אבל יש פה שתי בעיות: אחת של railway והשנייה שבחרו בrailway בלי לקרוא על איך הם מגבים את הדאטה ולא דאגו לגיבוי כל שבוע (תלוי מוצר כמובן) + גיבוי נוסף בצד ג׳ בvendor נפרד. וזאת תזכורת נפלאה לזה שעם AI או בלי, עדיין צריך ללמוד את הבסיס של הבסיס כשלוקחים אחריות על דאטה של משתמשים…
JER@lifeof_jer

x.com/i/article/2048…

עברית
11
0
79
18.8K
NanoClaw
NanoClaw@NanoClaw_AI·
✨ Announcing NanoClaw v2, in partnership with @vercel. We completely rebuilt how NanoClaw agents communicate with the outside world. v2 brings agent-to-agent communication, human-in-the-loop-approvals, support for 15 messaging platforms, and more. A thread on what's new:
English
52
112
980
200.6K
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
Congrats for our partners @NanoClaw_AI for the V2 launch 🚀🥳 OneCLI (github.com/onecli/onecli) covers the credential layer: secrets, oauth, and rules for human approval at the network boundary. every layer tightening up is a win for agent security
NanoClaw@NanoClaw_AI

✨ Announcing NanoClaw v2, in partnership with @vercel. We completely rebuilt how NanoClaw agents communicate with the outside world. v2 brings agent-to-agent communication, human-in-the-loop-approvals, support for 15 messaging platforms, and more. A thread on what's new:

English
1
1
13
209
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
@Gavriel_Cohen happy to be part of this 🚀 OneCLI (github.com/onecli/onecli) covers the credential layer: secrets, oauth, and rules for human approval at the network boundary. every layer tightening up is a win for agent security
English
0
0
7
120
Gavriel Cohen
Gavriel Cohen@Gavriel_Cohen·
NanoClaw V2 is out now! 🔐 Human-in-the-loop approvals on sensitive actions 👾 Persistent agent-to-agent collaboration 💬 15+ messaging channels 🏗️ New architecture from the ground up Keep your agents fully locked down. And let them be totally free.
NanoClaw@NanoClaw_AI

✨ Announcing NanoClaw v2, in partnership with @vercel. We completely rebuilt how NanoClaw agents communicate with the outside world. v2 brings agent-to-agent communication, human-in-the-loop-approvals, support for 15 messaging platforms, and more. A thread on what's new:

English
7
7
96
11.8K
Jonathan Fishner
Jonathan Fishner@jonathanfishner·
@garrytan Love seeing this ship. We’ve been in the same neighborhood with OneCLI (github.com/onecli/onecli), credential isolation for agents, “you can’t steal what isn’t there.” Different layer, same problem. Would love to compare notes.
English
0
0
0
65
Garry Tan
Garry Tan@garrytan·
CrabTrap is a big deal for the OpenClaw community
Pedro Franceschi@pedroh96

OpenClaw is the fastest-growing open source project, but there are no stories of running it safely in production at scale. As we started deploying agents internally at @brexHQ, we couldn’t stop thinking about this question. Agents work, but nobody wants to give them real credentials. Instead of waiting for a solution to emerge, we decided to try a novel approach: using LLMs to judge the network traffic of an AI agent. Today we’re announcing CrabTrap, an open-source proxy that intercepts every outbound request and blocks risky activity using LLMs, before it ever hits an external API. The results are promising; we believe it’s a meaningful step forward in the security of agent harnesses in production environments. Try it out today. (As a side note, it was really fun to work personally on a real systems problem again. And btw, if you want to work at a place where the CEO is building proxies at night, we’re hiring!)

English
15
9
185
33.8K