Roey Ben Chaim

153 posts

Roey Ben Chaim banner
Roey Ben Chaim

Roey Ben Chaim

@roeybc

building & securing agents | Staff Engineer @zenitysec | ex msft | climbing, surfing & eating hummus

nyc Katılım Ağustos 2009
492 Takip Edilen117 Takipçiler
Roey Ben Chaim
Roey Ben Chaim@roeybc·
@Teknium I found cloud sandboxes or an isolated box as the safest options
English
0
0
1
47
Lydia Hallie ✨
Lydia Hallie ✨@lydiahallie·
if your skill depends on dynamic content, you can embed !`command` in your SKILL.md to inject shell output directly into the prompt Claude Code runs it when the skill is invoked and swaps the placeholder inline, the model only sees the result!
Lydia Hallie ✨ tweet media
English
125
229
2.8K
773.3K
Founders Inc
Founders Inc@fdotinc·
bros really pulled up to watch jensen huang on a big screen
Founders Inc tweet mediaFounders Inc tweet media
English
10
1
147
8.2K
Roey Ben Chaim
Roey Ben Chaim@roeybc·
@interplato @arvidkahl it's on research mode, you need to be an admin, have a teams/enterprise edition, and not have zero data retention enabled. I don't know about desktop but if you don't wanna handle github you can use claude code on the web and use this - anthropic.com/news/claude-co…
English
0
0
0
76
Arvid Kahl
Arvid Kahl@arvidkahl·
What do you use to have Claude Code do a full security sweep of your codebase? My go-to is “Run a deep OWASP security sweep of the full app, all APIs and any internal services. Report in descending severity and suggest solutions using the AskUserQuestion tool.” in plan mode.
English
74
24
524
53.7K
Nagli
Nagli@galnagli·
RentAHuman -- the platform where "AI Agents" hire real humans for physical tasks - leaked its entire user database. 187,714 personal emails (at the time), all it took was few minutes, some tokens and one Claude Code command. Here's how my AI attacker found it 🧵
Nagli tweet media
English
67
115
819
193.2K
Context7
Context7@Context7AI·
Introducing Context7 CLI! 🎉 The modern, token-friendly way to get up-to-date documentation for AI. 90-second demo 👇
English
26
56
753
71.3K
Roey Ben Chaim
Roey Ben Chaim@roeybc·
For general software tasks? Probably In skillsbench arxiv.org/abs/2602.12670 we saw software was already pretty saturated, and guessing it’ll be the same for other sectors soon. It is a great mechanism for non public data that models are not trained on. From interval apis to undisclosed company ip.
English
0
1
7
2.1K
Roey Ben Chaim
Roey Ben Chaim@roeybc·
@arvidkahl Just giving my take on the tech! 🤠 I’m definitely not trying to gatekeep - it might actually win on developer experience and adoption
English
1
0
2
108
Arvid Kahl
Arvid Kahl@arvidkahl·
This is the Hacker News usage of "just". And that is the enemy of all usability, adoption, and ease of use for folks beyond the most technical. We're entering a phase of hypercompetition, both in what software is written and how it is made. Let's cool it with the gatekeeping.
Roey Ben Chaim@roeybc

@fatih You can just use the api with info from the swagger or wrap it with a cli. mcp means that every service provider has to add abd maintain another layer on top of that with debatable benefits (context rot)

English
8
1
16
4.2K
Roey Ben Chaim
Roey Ben Chaim@roeybc·
@dr we had to replace tabs vs spaces with something :D
English
0
0
0
18
Dan Rowden
Dan Rowden@dr·
I love the MCP vs CLI/API argument. Some people are completely brainwashed either way. It's like Mac vs PC from 20 years ago, or iPhone vs Android. In the end who cares, just use what you want. One is better, one is worse. No amount of debating will change people's opinions
Rhys@RhysSullivan

MCP sucking is a harness problem, not an MCP problem MCP unlocks behavior that is fundamentally impossible to get via CLI or APIs Bad auth, too much context usage, all get solved with an execution layer - your agent writes code to progressively discover and call tools

English
12
1
31
5.9K
Roey Ben Chaim
Roey Ben Chaim@roeybc·
@trq212 We’re still early! I think it’s because a lot of the problems skills solve are manageable (poorly though) in other ways. It’s more under the hood kinda thing.
English
0
0
1
93
Thariq
Thariq@trq212·
somehow skills are still underrated
English
281
67
1.9K
144.9K
Roey Ben Chaim
Roey Ben Chaim@roeybc·
@valhalla_dev I mean, if the VM sits a host you care about. There were vulnerabilities in the past that allowed for vm escape, and also depends on how you do it can have access to mounted volumes.
English
0
0
0
90
developing valhalla - h/acc
developing valhalla - h/acc@valhalla_dev·
@roeybc in what world is an attack surface smaller on another box versus running it on QEMU on a local machine
English
1
0
2
923
Roey Ben Chaim
Roey Ben Chaim@roeybc·
@thisritchie To be fair I’m talking about the merits of using mcp. If it’s here to stay as a standard or not is a separate question. Funny analogy though 🤠
English
0
0
0
17
Mike Ritchie
Mike Ritchie@thisritchie·
MCP is dead the same way dropbox was in 2007
Mike Ritchie tweet media
Roey Ben Chaim@roeybc

@fatih You can just use the api with info from the swagger or wrap it with a cli. mcp means that every service provider has to add abd maintain another layer on top of that with debatable benefits (context rot)

English
1
0
0
445
geoff
geoff@GeoffreyHuntley·
so; what things should i put on my bucket list for nyc? last time i was here was circa 15 years ago.
English
23
0
14
4.3K
Yam Peleg
Yam Peleg@Yampeleg·
Those who claim MCP is dead overlook the usefulness of knowing all LLMs are now overfitted to the MCP format.
English
9
2
52
5.1K