Prismor

1.3K posts

Prismor banner
Prismor

Prismor

@prismor_dev

Security & Compliance Autopilot for your code

San Francisco, CA Katılım Ekim 2025
371 Takip Edilen201 Takipçiler
Sabitlenmiş Tweet
Prismor
Prismor@prismor_dev·
We built an easy security solution that even grandmas can understand Introducing Prismor which not just flags developers for security vulnerabilities but also fixes it! Not just limited to fixing but also validating to ensure developers get what they expect without manually upgrading packages Out now prismor.dev Secure vibe coding let's go! #cybersecurity #demo
English
7
3
24
5.1K
Prismor
Prismor@prismor_dev·
Is anyone still using Devin?
English
0
0
3
40
Junaid ✧
Junaid ✧@whosjunaidd·
bet on yourself.
English
7
1
22
513
Morgan
Morgan@morganlinton·
@Dan_Jeffries1 Possibly the best framing I've seen, it really is a Napster moment. And I'm old enough to remember that moment, and it changed everything, forever.
English
2
0
10
331
Daniel Jeffries
Daniel Jeffries@Dan_Jeffries1·
I think I finally figured out why OpenClaw is amazing and took off like wild fire and why Peter is a genius, as Altman called him. And it's actually a different way of looking at it. It's not a DeepSeek moment for agents. It's a Napster moment. And just like Napster it will eventually force the industry to change. In essence when Napster came out the entire world told the music industry we don't want to buy CDs anymore and if you don't provide us a digital download experience we are just going to take it until you do. It forced the industry to create Apple Music and eventually Spotify. Both essentially killed most music piracy by making it ubiquitous and cheap and good. But it forced change. The same will now happen to software. Here's why: In essence OpenClaw lets you take what vendors don't want to give you: Unified access to countless applications. We all want a personal assistant that can talk to freaking everything and do anything for us in the digital world. But vendors don't want this. They want you locked into their bullshit. For example, none of the messaging platforms want bots on there. None. They all have explicit policies against them and make it hard to do this. WhatsApp doesn't want you on there. Signal. Telegram's bot father is garbage. It's all designed to keep bots out. They were designed for a pre-agentic era when bot = spam. Many other things are like this. The API layers are gated, hoop-jumping bullshit. Go get an enterprise account and wait for approval and yada yada. Want access to WhatsApp? Get a business account and attach a number (what small business has a real number anymore 😂) and messages can't come from a person, etc. Google ads? It's not just an auth, it's go get a special manager account and create an enterprise key and blah blah blah. It's a horrible experience because it was all designed for corporations to control access. Now people are saying, make your app easy to access and accessible to me and my machine avatars and do it in a headless way or you will be dead. Peter hacked around all this by making everything command line in the classic Linux style and using things like an open source library that reverse engineered the web version of WhatsApp. It's all a bit house-of-cards-y because he had no choice. At my company we had a similar idea early (and failed). Basically we wanted to make the best multimodal/computer using model because then it doesn't need an API or access hoops. You just go through the human interface layer and ain't nobody going to stop you. We failed because we weren't big enough and it's really a job for the mega-labs to solve because it is a hard problem and costs a shit ton of money. Peter was much smarter. Make it all command line because that is ready now. Use any reverse engineered library or project or proxy available come Hell or high water and make it work by any means necessary even if it is hacky. In short, he signaled to the software world that they better change and change fast or we are going to do this anyway and you can't stop us. Of course some are foolishly trying. Meta is banning Claws on WhatsApp, etc. They will all try to build their own gated, controlled, enshittified version of this thing. They will fail. And eventually everyone will offer a clear, easy way to get access via API for agents or they will be gone. In essence OpenClaw gave people what they wanted, which was an app connected to everything, even when most of the vendors don't want you to have this.
Daniel Jeffries tweet media
English
131
136
929
120.5K
Zack Korman
Zack Korman@ZackKorman·
@prismor_dev Yea there’s actually a lot of wilder stuff I’m working on here
English
1
0
4
159
Prismor
Prismor@prismor_dev·
Trivy was compromised. They just avoided massive blast-radius attack: compromise one security tool’s distribution path, and potentially compromise thousands of downstream customers. HackerBotClaw changed the trusted GitHub Action/release tags to point to malicious code, so when companies ran their normal trivy GitHub Action in CI, they unknowingly pulled the attacker’s version first which would steal secrets then still run the real scan so it looked normal. If you rely on Trivy, stop using the compromised version/tags immediately, pin to a known-good commit/SHA, rotate any secrets exposed in CI
English
1
0
2
106
Abbaas
Abbaas@asamassekou10·
Just checked my GitHub analytics to see where the 200 star spike came from. Ship Safe got featured on a Ukrainian dev portal and is being passed around in corporate Microsoft Teams chats. Over 500 clones in the last two weeks. The developer community is officially tired of AI writing vulnerable code
Abbaas tweet media
English
1
1
3
125
Prismor
Prismor@prismor_dev·
@jondalgir that's fine, happens seems the page is stuck :/ Feel free to give us a try as well :)
Prismor tweet media
English
1
0
1
7
Jon Dalgir
Jon Dalgir@jondalgir·
Shipped: Email report delivery in Seevora. Now scan a homepage, get the clarity/discoverability/AI visibility report, and send it straight to your inbox, no login needed. Built directly from early user feedback. Try it free: seevora.com What's the most useful homepage insight you've gotten from AI scans? #BuildInPublic #AI #ProductDesign
English
2
0
2
51
Millie Marconi
Millie Marconi@MillieMarconnni·
Holy shit...AI search is eating Google's traffic and most websites have zero idea why they're invisible to ChatGPT and Perplexity. A developer just built geo-seo-claude to fix that. Point it at any URL. It runs a full GEO audit, scores your AI citation readiness, checks which AI crawlers can even access your site, and generates a client-ready PDF report. AI-referred traffic converts 4.4x higher than organic. Traditional SEO agencies haven't figured this out yet. This repo has. 100% Opensource. MIT License. Link in comments.
Millie Marconi tweet media
English
81
197
2.4K
290.9K
Prismor
Prismor@prismor_dev·
Quickly audit and fix security vulnerabilities in your repository, just dump your GitHub repo URL
English
1
0
2
55
Prismor
Prismor@prismor_dev·
@PatrickHaede We love the attention to detail and user experience! Congrats on the launch
English
1
0
2
202
Patrick Haede
Patrick Haede@PatrickHaede·
We just mass automated social marketing. Introducing Superscale Agent - the first advanced AI agent for social marketing. What used to take 1000s of hours now takes minutes: → Brainstorm & execute full marketing strategies instantly → Deep-dive competitor & trend reports (connected to the entire web, TikTok trends, Meta Ad Library) → Analyze your own Meta & TikTok ad accounts directly → Generate 100s of ads for TikTok, FB, IG, or Google from a single prompt → Iterate on creatives at insane speed → Build e-commerce store & ad assets on autopilot You give instructions. The agent does the work. Software engineering went agentic. Today, social marketing follows. This is the most complex product we have ever built, and our most advanced update to @superscale_ai - ever. Early customers have been using it for months. The results have been transformative. To celebrate: comment "Agent" and get our 100 most powerful prompts + 3,000 free credits (= 3 videos or 50 static ads). It only gets crazier from here 🚀
English
443
58
591
72K
Prismor
Prismor@prismor_dev·
Compliance is sensitive where trust can be eroded easily. We're committed to transparency for our users
Ryan@ohryansbelt

Delve, a YC-backed compliance startup that raised $32 million, has been accused of systematically faking SOC 2, ISO 27001, HIPAA, and GDPR compliance reports for hundreds of clients. According to a detailed Substack investigation by DeepDelver, a leaked Google spreadsheet containing links to hundreds of confidential draft audit reports revealed that Delve generates auditor conclusions before any auditor reviews evidence, uses the same template across 99.8% of reports, and relies on Indian certification mills operating through empty US shells instead of the "US-based CPA firms" they advertise. Here's the breakdown: > 493 out of 494 leaked SOC 2 reports allegedly contain identical boilerplate text, including the same grammatical errors and nonsensical sentences, with only a company name, logo, org chart, and signature swapped in > Auditor conclusions and test procedures are reportedly pre-written in draft reports before clients even provide their company description, which would violate AICPA independence rules requiring auditors to independently design tests and form conclusions > All 259 Type II reports claim zero security incidents, zero personnel changes, zero customer terminations, and zero cyber incidents during the observation period, with identical "unable to test" conclusions across every client > Delve's "US-based auditors" are actually Accorp and Gradient, described as Indian certification mills operating through US shell entities. 99%+ of clients reportedly went through one of these two firms over the past 6 months > The platform allegedly publishes fully populated trust pages claiming vulnerability scanning, pentesting, and data recovery simulations before any compliance work has been done > Delve pre-fabricates board meeting minutes, risk assessments, security incident simulations, and employee evidence that clients can adopt with a single click, according to the author > Most "integrations" are just containers for manual screenshots with no actual API connections. The author describes the platform as a "SOC 2 template pack with a thin SaaS wrapper" > When the leak was exposed, CEO Karun Kaushik emailed clients calling the allegations "falsified claims" from an "AI-generated email" and stated no sensitive data was accessed, while the reports themselves contained private signatures and confidential architecture diagrams > Companies relying on these reports could face criminal liability under HIPAA and fines up to 4% of global revenue under GDPR for compliance violations they believed were resolved > When clients threaten to leave, Delve reportedly pairs them with an external vCISO for manual off-platform work, which the author argues proves their own platform can't deliver real compliance > Delve's sales price dropped from $15,000 to $6,000 with ISO 27001 and a penetration test thrown in when a client mentioned considering a competitor

English
0
0
3
61
Morgan
Morgan@morganlinton·
@prismor_dev I’ll be tweeting until I’m well into my hundreds
English
1
0
2
22
Morgan
Morgan@morganlinton·
Tweets like this really make my day. The only thing I’ve changed over the last few months is just sharing more about things I’m curious about, without being afraid to sound silly. Getting some really good feedback, and now I wonder why I was so afraid to post what was on my mind for so long. Sometimes the hardest step to take is the first one. Thanks to everyone who has supported me as I’ve opened up more, and just started to really be myself on here 🙏
Rob_801@801Rob

@morganlinton Bro, you were my best discovery in a long time. I love your content, so, so, SO informative and useful!

English
4
0
30
1.5K
Prismor
Prismor@prismor_dev·
Anyone know any great GTM tools for personalized outreach? We're looking for prismor style simplicity
English
1
0
4
97
Morgan
Morgan@morganlinton·
Wild, woke up to see my post from last night got an RT from @elonmusk. I guess we’re both bullish on small models, special purpose models 🤩
Morgan tweet media
English
8
2
36
1.1K