Andrej Karpathy 指出 npm axios 供应链攻击Andrej Karpathy Highlights npm Axios Supply Chain Attack
AI 研究员、前 Tesla AI 总监以及 OpenAI 创始团队成员 Andrej Karpathy 指出了 npm axios 库面临的新供应链攻击,该库是热门 HTTP 客户端,每周下载量达 3 亿次。他在自己系统中发现了一个来自 googleworkspace/cli 的易受攻击导入,并指出未固定依赖版本可能会在时机不当的情况下让他中招。他认为像 pip 和 npm 这样的包管理器默认设置需要改变,例如加入发布年龄约束,以避免临时恶意包通过未固定依赖随机大规模感染用户。他附上了该问题的详细文章链接。
Andrej Karpathy, AI researcher and former Director of AI at Tesla and founding team member at OpenAI, highlighted a new supply chain attack on the npm axios library, the most popular HTTP client with 300M weekly downloads. He personally found a vulnerable import from googleworkspace/cli in his system, noting that unpinned dependencies could have exposed him if timed poorly. He argued that package managers like pip and npm need default changes such as release-age constraints to prevent random, large-scale infections from temporary malicious packages. A comprehensive article on the issue is linked.
查看原文 →
Vercel CEO Guillermo Rauch 谈负责任的 Agent 使用Vercel CEO Guillermo Rauch on Responsible Agent Use
Vercel CEO Guillermo Rauch 表示,Opus 4.5 的发布开启了通往 Agent 驱动工程的新时代,现在 Agent 负责大部分编码工作。意识到 LLM 的过度自信和缺陷,他的团队严格区分随意“vibing”和关键基础设施。他们分享了早期内部指导,强调在“负责任地使用 Agent”时始终优先考虑安全、耐用性和可用性。
Vercel CEO Guillermo Rauch described the release of Opus 4.5 as opening a one-way door to agent-driven engineering, where agents now handle most coding. Aware of LLMs' over-confidence and flaws, his team enforces strict separation of casual 'vibing' from mission-critical infrastructure. He shared early internal guidance on 'agenting responsibly' with emphasis on security, durability, and availability at all times.
查看原文 →
Ryo Lu 谈 AI Agent 时代软件的灵魂Ryo Lu on Software Soul in the AI Agent Era
Cursor AI 设计师 Ryo Lu 曾任职 Notion 和 Stripe,他回忆起 2005 年左右软件充满灵魂的时代,那时 Mac 的 dock 会弹跳,genie 效果流畅,Exposé 像摊牌一样散开窗口,这些细节并非必要,却让人感受到设计者的用心。软件那时有质感、有哲学,你能感受到背后的人性化决策。如今增长优化让个性被抹平,所有界面变得一致而乏味。他警告说,AI Agent 的速度虽然让产品生成飞快,但也容易产生大量“slop”——功能正常却毫无灵魂的产品。他坚信人类的品味和关怀是不可替代的,AI 其实让这种特质更珍贵,有望带来一场注重个人化和有主见的软件复兴。他提醒大家,我们做这一切都是为了人类,而非相反。
Ryo Lu, Designer at Cursor AI with prior experience at Notion and Stripe, reminisced about an era around 2005 when software felt alive with soulful details like bouncing docks and thoughtful animations, crafted by people passionate about user experience. He critiqued how growth optimization has stripped away personality, resulting in bland, uniform interfaces, and warned that AI agents' speed risks flooding the world with 'slop'—functional but soulless products. He believes true taste and caring remain human strengths that AI amplifies for a potential renaissance of personal, opinionated software, reminding us that all development is ultimately for humans.
查看原文 →
Nikunj Kothari 谈 AI 助力人类协作Nikunj Kothari on AI Enabling Human Collaboration
FPV Ventures 合伙人 Nikunj Kothari 回忆起 12 年前与 Ivan Zhao 的会面,对他致力于构建能凝聚人心的工具印象深刻。他对比了当前 AI 取代人类的末日叙事,提出一种丰盛时代的愿景:AI 处理所有琐碎工作,让人类有更多时间一起构建和思考那些尘封已久的梦想。他呼吁更多地宣扬这种积极转变,强调人类将共同完成更多事情。
Nikunj Kothari, partner at FPV Ventures, reflected on his meeting with Ivan Zhao 12 years ago, impressed by his dedication to tools that unite people. He contrasted AI doomerism focused on replacement with a vision of abundance where AI handles mundane tasks, allowing humans to collaborate more creatively on long-held dreams. He urged emphasizing this positive shift toward collective building.
查看原文 →
Box CEO Aaron Levie 谈企业中的 Agent 工作流Box CEO Aaron Levie on Agent Workflows in Enterprises
Box CEO Aaron Levie 指出,组织内有资源和创业精神的 人才有巨大机会去重新构想 Agent 时代的 工作流。这需要切实投入:将非结构化数据整理成 Agent 易于访问的形式,深入了解工作流以创建技能和计划,连接不同系统,并可能调整流程本身,同时设计人类监督和验证的角色。与编码任务不同,知识工作无法 shortcuts,必须由团队成员完成。他预测企业将出现大量此类专业角色,这些人才将在经济中极具价值,对早期职业人士来说也是快速产生影响的好途径。
Box CEO Aaron Levie outlined a major opportunity for resourceful talent inside organizations to reimagine workflows in the age of agents. This requires real effort: structuring unstructured data for agent access, mastering workflows to build skills and plans, connecting systems, and adapting processes—plus designing human oversight and validation roles. Unlike coding tasks where agents excel with context, broader knowledge work demands this investment, leading to new specialized roles that will be highly valuable, especially benefiting early-career professionals.
查看原文 →
Dan Shipper 批评数据隐私漏洞的回应Dan Shipper Criticizes Data Privacy Bug Response
Every CEO Dan Shipper 批评某公司对一个 bug 的回应含糊其辞,该 bug 导致用户私人数据被推送给应用的其他用户。他称这种表述是“mealy mouthed”的方式来承认问题,并认为这非常糟糕。
Dan Shipper, CEO at Every, called out a company's poor handling of a data breach bug that inadvertently served users' private data to other app users. He described the admission as a 'mealy mouthed way' to confess the issue and deemed it really bad.
查看原文 →