Robert Rounsavall

185 posts

Robert Rounsavall banner
Robert Rounsavall

Robert Rounsavall

@robrounsavall

I've been playing in cybersecurity for a bit. Former Navy Chief. Terrible at Jiu-Jitsu and Wrestling.

Northern Virginia Katılım Nisan 2022
475 Takip Edilen134 Takipçiler
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Tried Claude Design on two small landing pages. Burned through all my usage in half an hour, but the output was a great starting point. Give it a reference page to look at if you don't want it to look like a baby Anthropic page out of the box.
English
0
0
0
14
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Needed to update a session through the MCP in my app but no update tool existed, just create new. I added an "update session" to the code, and instead of waiting for a restart, Claude just pulled the Auth0 M2M creds from .env, made a token.txt, and called the API directly, impersonated and bypassed the MCP. The API can't tell the difference. I feel like Wile E. Coyote. Great hardening plan implemented, then another box of TNT blows it up...
English
1
0
0
28
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Used Claude to build a janky thing that pulls in X, YouTube, and vendor sites through the last30days skill. It mostly works but its really bad. Why bother with RSS when you can build some junk that doesn't work and makes it more complicated?
English
0
0
1
26
Robert Rounsavall
Robert Rounsavall@robrounsavall·
No fun AI building stuff today, only GMLE labs today...
English
0
0
0
10
Robert Rounsavall
Robert Rounsavall@robrounsavall·
At the end of February I read some LLM security guidance from OWASP or the Cloud Security Alliance and realized I didn't have a clue what was going on. I've been trying to get a clue every day since. Still don't have a clue, but maybe in a year I will. Have been learning from all of you on this platform, thank you!
English
1
0
2
43
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Thought the MCP setup I did was secure. Any user can run any GraphQL query through it. At least it's M2M authenticated while all the data is stolen then the database destroyed... ugh...
English
0
0
0
19
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Almost took the bait and started playing with another tool in the LM coding space that looked interesting, but managed to pull myself back off the ledge. The focus is to get REALLY good with @cursor_ai and @claudeai. Nice try, but not today Satan!
English
0
0
0
20
Robert Rounsavall
Robert Rounsavall@robrounsavall·
I still haven't quite figured out the Cursor app, I've only been using the IDE, but am getting the sense that I should start figuring that part of it out.
English
0
0
0
17
Jordan Ross
Jordan Ross@jordan_ross_8F·
The agency owners who fix their AI tech stack in the next 90 days are going to look like geniuses in 2027. The problem is every tool markets itself with the same words.. Agents Copilots. Memory. Automation Read about three and you can't tell which one to pick. So my team built a 105-page field manual that does the categorization for you. Inside: — The 8 software roles every modern agency stack collapses into (brand names change, roles don't) — The 5-question decision model that ends every "which tool should we buy" debate in under a minute — Specific picks by revenue band — what to run at $1M, $5M, $10M, and $20M+ — A task-to-tool matrix across marketing, sales, ops, fulfillment, reporting, and exec — 6 setup quickstarts including the $400/mo warehouse you can stand up in a weekend Comment STACK and I'll send it.
GREG ISENBERG@gregisenberg

how to set up hermes agent step by step. built-in memory, 40+ tools, works on your phone, and what to think of hermes vs openclaw: 1. hermes is a personal AI agent that runs in your terminal. think of it like open claw but with built-in memory, 40+ tools out of the box, and 90% cheaper token costs. you install it with one command. 2. the 3 problems with open claw that hermes solves: no memory (you keep repeating yourself), constant gateway restarts, and zero visibility into what you're spending on tokens. 3. hermes remembers everything. every completed task gets saved to memory. it searches through past logs to find solutions. over time it literally gets smarter at your specific workflows. 4. connect it to open router. you see exact costs per model per task. free models rotate weekly. one founder went from $130 every five days on open claw to $10 on hermes. same output. 5. it comes preloaded with skills. apple notes, imessage, find my, browser, web search, image generation, cron jobs. no hunting for plugins. 6. connect it to obsidian so it reads your entire vault. connect it to gstack for your dev environment. create custom skills for your specific workflows. 7. the biggest money saver: have it write code once for recurring tasks. then it runs without burning tokens every time. stop paying an LLM to do the same scrape or report daily. 8. run it on android via telegram. name your agents. talk to them like coworkers. in this episode imran shows you how to set this up. 9. you can run it bare metal, in docker, or serverless on modal. pick your risk level. i begged @imranye to come on @startupideaspod and walk through the full installation live. he made it impossibly clear. if you've heard of Hermes Agent and want the clearest explanation of how to get set up like a pro let me know what you want me to cover on the next ep this is the best personal agent setup video on the internet right now. watch

English
248
13
192
33.3K
Robert Rounsavall
Robert Rounsavall@robrounsavall·
First time using --dangerously-skip-permissions today. Told Claude: "Finish everything in X project directory." It looked one level up, saw eight projects, and started to finish all of them. The plan saved me. Enjoying it so far, but you have to be super careful or bad things will happen...
English
0
0
1
53
Robert Rounsavall
Robert Rounsavall@robrounsavall·
@gadievron May be a dumb question but with regard to cursor, sounds like they were using Opus within cursor. Same thing could have happened with the Claude plugin for vscode? If this happened to me would I be focused on the model I was using rather than Cursor? Nice write up, thank you!
English
1
0
1
36
Gadi Evron
Gadi Evron@gadievron·
Another case where an agent deleted code/production. Coding agents are constructed to have unrestricted access to control plane. We built Knostic not only to detect malicious, but to stop stupid. Prevent destructive actions so that engineers can feel safe using them.
JER@lifeof_jer

x.com/i/article/2048…

English
4
3
14
2.5K
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Who is actually for real coding from their phone? OpenClaw only? I am only productive at my desk, and sometimes not even very productive from my desk. Teach me this dark magic...
English
1
0
1
30
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Every time I say "I'm just going to do 10 or 15 minutes" of messing around with AI tools, it turns into 2-3 hours.
English
0
0
1
10
Robert Rounsavall
Robert Rounsavall@robrounsavall·
There has to be tools that already do this. Just trying to get a little better at securing this junk. MCP logging in place with the LLM Client, User, and Auth method and even session id. It shows up in the UI at the moment but wired to go to a SIEM.
Robert Rounsavall tweet media
English
0
0
1
67
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Spent the evening adding data tagging to my "hardened" app because a friend asked if I had implemented it. I didn't even know what it meant. Now I can see the request ID on each MCP call and have a roadmap full of stuff I didn't know I needed...
Robert Rounsavall tweet media
English
0
0
0
17
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Got audit logging almost working on the MCP for the "learning app" now that Auth0 M2M authentication works. Every tool call sends a security event: who ran, which tool, success/failure, how long. Still only local events. Trying to build the right things rather than add on later.
English
0
0
1
59
Robert Rounsavall
Robert Rounsavall@robrounsavall·
Not much AI today, playing around with the Wazuh SIEM.
English
1
0
1
1.5K