惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
N
Netflix TechBlog - Medium
罗磊的独立博客
博客园 - 聂微东
美团技术团队
GbyAI
GbyAI
Microsoft Security Blog
Microsoft Security Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
博客园_首页
宝玉的分享
宝玉的分享
G
GRAHAM CLULEY
Microsoft Azure Blog
Microsoft Azure Blog
量子位
SecWiki News
SecWiki News
F
Fortinet All Blogs
J
Java Code Geeks
S
SegmentFault 最新的问题
V
V2EX
Martin Fowler
Martin Fowler
F
Full Disclosure
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
P
Proofpoint News Feed
S
Security Affairs
Application and Cybersecurity Blog
Application and Cybersecurity Blog
K
Kaspersky official blog
S
Secure Thoughts
S
Schneier on Security
MongoDB | Blog
MongoDB | Blog
博客园 - 三生石上(FineUI控件)
Cloudbric
Cloudbric
雷峰网
雷峰网
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Cloudflare Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
爱范儿
爱范儿
V2EX - 技术
V2EX - 技术
H
Hackread – Cybersecurity News, Data Breaches, AI and More
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
Apple Machine Learning Research
Apple Machine Learning Research
H
Help Net Security
C
Check Point Blog
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
Hacker News - Newest:
Hacker News - Newest: "LLM"
G
Google Developers Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
T
Tenable Blog
博客园 - 【当耐特】

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor GitHub - GenAI-Gurus/awesome-eu-ai-act: Curated tools, official sources, OSS, templates, and guides for EU AI Act compliance. Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders How to Switch AI Chatbots and Why You Might Want To GitHub - MattMessinger1/agentic_refund_guardrail: Safe refund policy layer for AI agents — Python + TypeScript. Same behavior, shared tests. Adam/papers/emergent_values_whitepaper.md at master · strangeadvancedmarketing/Adam Ask HN: How do you stop playing 20 questions with your AI coding tools How far can automation and AI support psychotherapy? - @theU GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits A Mac Studio for Local AI — 6 Months Later A History of the Early Years of AI at the University of Edinburgh Why AI Coding Tools Still Feel Stuck on Localhost MSN AI Datacenters Are Becoming Strategic Targets twitter.com Penn Researchers Use AI to Surface Unreported GLP-1 Side Effects in Reddit Posts Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 AI models are terrible at betting on soccer—especially xAI Grok GitHub - xialeistudio/echoic GitHub - HimashaHerath/github-dev-wrapped: AI-powered weekly GitHub activity reports deployed to GitHub Pages GitHub - alejandrobalderas/claude-code-from-source: Architecture, patterns & internals of Anthropic's AI coding agent — reverse-engineered from source maps AI and Tech brief: Ireland ascendant GitHub - Titovilal/context0: Context0 - Never Surrender Training for a Marathon with an AI Coach: What Worked and What Didn't Cyber Pulse: Agentic Intel - Apps on Google Play I Built an AI PR Reviewer That Catches Bugs by Not Looking for Bugs Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout | Fortune How AI Is Reimagining the Game of Golf–For Both Players and Courses GitHub - nattergabriel/reseed: A CLI tool for managing and distributing agent skills across projects Is SVG the final frontier? My AI workflow evolved from prompts to a near-autonomous workflow MLSharp Help - 3DGS Viewer & Generator I put my cognitive field based AI's runtime on GitHub Is Numble the first AI-proof game? A3: Kubernetes for autonomous AI agent fleets | Emergent Principles Deepali Vyas ("The Elite Recruiter") GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Unionized ProPublica staff are on strike over AI, layoffs, and wages Unleashing the Advantage of Quantum AI We're heading for an AI-fueled 'dementia crisis,' brain scientist warns The AI-Assisted Breach of Mexico's Government Infrastructure [pdf] GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. MSN GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs AI Code is Hollowing Out Open Source, and Maintainers are Looking the Other Way What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI AI is the boss at this retail store. What could go wrong? GitHub - Wuzu11517/agentic-proxy: Local proxy meant to help reduce With Drones, Geophysics and ArtificiaI Intelligence, Researchers Prepare to Do Battle Against Land Mines A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - inevolin/resume-cli: Hit Claude usage limits? Resume any AI coding session elsewhere. Switch tools at zero friction. GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. How to Build a Secure AI PR Reviewer with Claude, GitHub Actions, and JavaScript This Startup Wants You to Pay Up to Talk With AI Versions of Human Experts Intel Arc Pro B70 Brings 32GB VRAM to Local AI for $949 WordPress 7.0: The Good, the AI, and the Still Missing AI on the couch: Anthropic gives Claude 20 hours of psychiatry IatroBench: Pre-Registered Evidence of Iatrogenic Harm from AI Safety Measures AI Agents Know About Supabase. They Don't Always Use It Right. The history and future of AI at Google, with Sundar Pichai Inside an AI‑enabled device code phishing campaign How Meta Used AI to Map Tribal Knowledge in Large-Scale Data Pipelines AI for Systems: Using LLMs to Optimize Database Query Execution Forecasting the Economic Effects of AI Introducing Tinker: Play with AI, bring your ideas to life AI sheds light on an ancient gaming mystery People really hate AI but not as much as Iran—or Democrats | Fortune What is an AI Product Engineer? Phoebe Gates wants her $185 million AI startup to succeed with 'no ties to my privilege or my last name': 'I have a chip on my shoulder' | Fortune
GitHub - coproduct-opensource/nucleus: Enforced permissions for AI agents - policy + enforcement in one stack
weitzj · 2026-05-20 · via Hacker News - Newest: "AI"

CI Security Audit OpenSSF Scorecard

Nucleus prevents AI coding agents from combining untrusted input with privileged actions, and proves what was and wasn't allowed.

Two primitives — join and flows_to — enforce information flow control with four algebraic laws. Once web content enters a session, it cannot silently reach git push. That property is machine-checked, not hoped.

let mut state = FlowState::bottom();          // clean session
state.join_operation(Operation::WebFetch);     // tainted by web content
assert!(!state.flows_to(SinkClass::GitPush));  // can't push tainted data

Quick Start

cargo install --git https://github.com/coproduct-opensource/nucleus nucleus-cli
nucleus audit                       # scan agent configs (Tier 0, no runtime)
nucleus run --local "your task"     # run with enforced permissions (Tier 1)

Every tool call flows through the permission kernel. nucleus run tracks data provenance and blocks dangerous combinations — like writing code derived from untrusted web content. The hook for AI coding assistants previously bundled here (nucleus-claude-hook) is now part of nucleus-code, the private orchestrator built on this runtime.

What Gets Proved

Claim What it means for you Evidence Known gap
Taint is monotone Once web content contaminates a session, the agent cannot silently regain trusted status Lean 4 + Kani Depends on correct labeling at integration boundaries
Adversarial integrity absorbs One drop of adversarial input contaminates the entire result — no dilution Lean 4 Content must be labeled adversarial at source
Obligation bypass is a type error Side effects require a DischargedBundle that can only come from a passed policy check Compile-fail test 146 call sites still bypass the effect layer (#1216)
Permissions are a Heyting algebra Restricting permissions always produces a valid, less-permissive result Kani + Lean 13 dimensions may not cover every use case
Secret data cannot flow to public sinks Session-level confidentiality ceiling prevents laundering through intermediaries 21 unit tests + compile-fail Mislabeled data bypasses the check
Receipt chains detect tampering Hash-chained, signed audit trail for every agent action Tests Append-only property not formally proved

Full inventory: 165 Lean 4 theorems (zero sorry), 112 Kani BMC proofs, 297 Verus VCs, ~2,850 tests. Verified Claims | Formal Methods | Production Delta

The Flow Algebra

Law What it means What it enables
a ⊔ b = b ⊔ a Join is commutative Safe parallel execution
a ⊔ (b ⊔ c) = (a ⊔ b) ⊔ c Join is associative Order-independent ratchet
a ⊔ a = a Join is idempotent Provably safe caching
a ≤ a ⊔ b Join is monotone Taint never decreases

Per-Call SPIFFE Provenance (preview)

Status: alpha. The crate ships a per-call SPIFFE-ID derivation library, an in-process Ed25519 demo issuer, an append-mode JSONL log, and a nucleus lineage walker. The demo is not yet wired into the runtime, edges are not yet signed, and no SPIRE-backed IdentityFetcher impl exists in this repo. See crates/nucleus-lineage/README.md for the honest scope and the audit findings for what's still missing.

nucleus-lineage extends SPIFFE workload identity from the pod level down to the individual call level. Each tool invocation, LLM call, or derived artifact mints a child SPIFFE ID whose path encodes its lineage and whose suffix is a content hash:

spiffe://<trust>/ns/<ns>/sa/<sa>                                   ← pod (root)
  /call/<uuid>/tool/<tool>                                         ← tool call
  /call/<uuid>/llm/<provider>/prompt/sha256:<hex>                  ← LLM input
  /call/<uuid>/llm/<provider>/response/sha256:<hex>                ← LLM output
  /call/<uuid>/derived/sha256:<hex>                                ← downstream artifact

Identical content → identical content-hash suffix, regardless of derivation path. The full path is a human-readable witness of the derivation chain.

Try it end-to-end (Bash → Write → mock-LLM with self-loop JWT verification — the mock LLM uses the same in-process key the issuer minted with, so this proves the JWT format, not cross-trust federation):

cargo run -p nucleus-lineage --example three_step_demo
nucleus lineage <leaf-spiffe-id> --log ./nucleus-lineage.jsonl

Output formats: --format tree (default), json, or dot (for Graphviz).

Today Roadmap
SPIFFE-format ID per call, content-addressed Edge signing + hash chain so the JSONL log is tamper-evident
LocalIssuer (in-process Ed25519, demo-only) SPIRE Workload API IdentityFetcher impl
nucleus lineage walker (graph traversal) Walker verifies edge signatures + JWKS-backed federation
Composes with portcullis IFC labels (does not replace them) nucleus-tool-proxy auto-emits edges per HTTP handler

Treat the categorical framing — "per-call SPIFFE IDs lift the workload category to a bicategory; cocycle condition becomes verifiable" — as a roadmap, not as currently load-bearing. See crates/nucleus-lineage/README.md for the longer story and the explicit limitations.

How Nucleus Stops Real Exploits

CVE Attack Why it worked Nucleus defense
CVE-2025-53773 Copilot RCE via prompt injection Security was a JSON config flag the agent could edit Security is compiled types (Discharged<O>), not config
CVE-2025-32711 EchoLeak — zero-click exfiltration via hidden prompt in Word doc No concept of "internal data cannot leave" Bidirectional IFC blocks internal→public flow
MCP Tool Poisoning Malicious MCP server injects hidden instructions Tool responses treated as trusted MCP responses labeled Adversarial at the type level

Three Deployment Tiers

Tier What Isolation Status
0 — Scan nucleus-audit scan in CI Static analysis, no runtime Usable today
1 — Enforce nucleus run --local / Claude hook Tool-proxy lattice enforcement Working in CI
2 — Isolate nucleus run with Firecracker microVM + netns + default-deny egress Linux+KVM only

Architecture

Agent → MCP → tool-proxy (inside VM) → portcullis check → OS operation
┌──────────────────────────────────────────────┐
│  nucleus-cli / nucleus-audit scan            │
├──────────────────────────────────────────────┤
│  nucleus (Sandbox + Executor + AtomicBudget) │
├──────────────────────────────────────────────┤
│  portcullis (7 control planes)               │
│  Capabilities × Obligations × Paths ×        │
│  Commands × Budget × Time + DPI              │
├──────────────────────────────────────────────┤
│  nucleus-identity (SPIFFE + mTLS)            │
│  nucleus-lineage  (per-call SPIFFE DAG)      │
├──────────────────────────────────────────────┤
│  Firecracker microVM / seccomp / netns       │
└──────────────────────────────────────────────┘

Crates

User-facing tools (4 crates)
Crate Purpose
nucleus-cli Run AI agents under enforced permissions; ships the nucleus binary
nucleus-audit Scan agent configs, verify audit trails, inspect provenance
nucleus-sdk Rust SDK for building sandboxed AI agents
exposure-playground Interactive TUI for exploring the permission lattice
Core libraries (14 crates)
Crate Purpose
portcullis Permission lattice: algebraic modules, attenuation tokens, egress policy, DPI
portcullis-core Core types: CapabilityLevel, IFC labels, flow graph, witness bundles
ck-kernel Constitutional kernel: admission engine + lineage
ck-types Constitutional kernel core types and manifests
ck-policy Constitutional kernel policy monotonicity checks
nucleus Enforcement: cap-std sandbox, executor, budget tracking
nucleus-tool-proxy MCP tool proxy (permission enforcement gateway)
nucleus-mcp MCP server bridging to tool-proxy
nucleus-identity SPIFFE workload identity, mTLS, certificate management
nucleus-lineage Per-call SPIFFE-derived data lineage: CallSpiffeId, LineageEdge, IdentityFetcher
nucleus-ifc Standalone IFC library for AI agents
nucleus-memory Governed memory with per-entry IFC labels
nucleus-spec PodSpec definitions (policy, network, credentials)
nucleus-proto Generated gRPC/Protobuf types
nucleus-client Client signing utilities + drand anchoring
Infrastructure (5 crates)
Crate Purpose
nucleus-node Node daemon managing Firecracker microVMs + containers
nucleus-permission-market Lagrangian pricing oracle for capability constraints
nucleus-guest-init Guest init for Firecracker rootfs
ctf-engine Formally verified sandbox CTF challenge engine
ctf-server HTTP API server for The Vault CTF

Total: ~2,850 tests across the workspace (162K LOC Rust).

Known Gaps

Documented in SECURITY_TODO.md and docs/production-delta.md. Key items:

  • bash -c bypasses command-level checks. Firecracker network policy is the real defense.
  • Path sandboxing is string-based. cap-std provides defense-in-depth.
  • Budget enforcement is partial. Pre-execution reservation works; post-execution accounting is not.
  • Formal verification covers the lattice, not the full runtime. See FORMAL_METHODS.md.
  • Hook I/O boundary is unverified. JSON parsing is a trusted edge.

Threat Model

Protects against: prompt injection side effects, invisible Unicode injection, misconfigured permissions, network policy drift, budget exhaustion, privilege escalation via delegation, audit log tampering.

Does not protect against: compromised host/kernel, malicious human approvals, side-channel attacks, VM kernel escapes.

Versioning: v1.0 means the interface contract is stable (see STABILITY.md), not "production-secure by default." The lattice is heavily verified; the runtime is tested but not yet battle-hardened.

Development

cargo build --workspace
cargo test --workspace
make demo              # taint → block → receipt → compartment switch

License

Licensed under either of Apache License, Version 2.0 or MIT license at your option.

References