AWS Powers PyPI and the PSF
The Python Software Foundation (PSF) reported a 69% increase in AWS spending from July 2025 to July 2026, driven by growing Python usage and AI agents installing packages. The PSF's infrastructure, in…
The Python Software Foundation (PSF) reported a 69% increase in AWS spending from July 2025 to July 2026, driven by growing Python usage and AI agents installing packages. The PSF's infrastructure, in…
Diffctx v1.15.0, an MCP server that selects the minimum code an LLM needs to review a git diff, was published to the official MCP registry on 2026-08-19 and is distributed on PyPI. The mcpindex gate p…
AceDataCloud released io.github.AceDataCloud/mcp-aichat v2026.8.18.2, an MCP server for AI dialogue using various LLM models, published to the official MCP registry on 2026-08-18 and distributed as mc…
Mcpindex.ai published a semantic screening verdict for io.github.darknodebros/elesync, a private local-first AI workspace, on 2026-08-18, reporting no malicious instructions found in its description. …
A developer has released StackBridge-MCP, an open-source Model Context Protocol server that tracks cross-boundary contracts in full-stack codebases to prevent AI coding agents from silently breaking f…
A dev.to write-up describes a setup where Claude Code is routed through a LiteLLM proxy to cheaper DeepSeek models via OpenRouter, a pattern that trades away data governance and supply-chain security.…
The TeamPCP campaign in March 2026 used a stolen token to cascade across five ecosystems in eight days, publishing backdoored LiteLLM versions 1.82.7 and 1.82.8 on PyPI that swept LLM API keys, cloud …
TraceMotive v0.3.0, an open-source, local-first debugging tool for AI agent executions, introduces an investigation-first workflow that identifies the first evidence-supported behavioral divergence be…
A developer warns that the software supply chain for AI coding agents is vulnerable, citing a backdoored LiteLLM package on PyPI that was downloaded 47,000 times in three hours. The post details three…
A developer shipped an open-source MCP server for code review with zero marketing budget and gained 650+ PyPI installs and listings in five directories within a month. The playbook highlights director…
SentinelLABS research shared with Cyber Security News documents four incidents where AI agents persistently adapted to breach systems, including a July attack on Hugging Face's production infrastructu…
Coding agents that install dependencies at machine speed make registry-side vulnerability checks and install blocking a critical choke point, according to Omniline's blog. The article argues that huma…
A developer has built MCP Code Review Server, an open-source Model Context Protocol server that runs code reviews locally on a developer's machine without uploading code to the cloud. The server integ…
Developer Deghosal shipped v0.2.0 of agent-tooltrust, an open-source control plane for AI agents, three days after field-testing v0.1.0 with 83 real agents and incorporating feedback from 14 developer…
PrismManifest 0.3.4, an open-source Python library from insightitsGit, provides a zero-trust gate that verifies Ed25519-signed ParameterManifests before allowing probabilistic AI outputs (LLMs, OCR) t…
WinCore 0.6.3, a free and open-source Python library for AI and PyTorch on Windows, has been publicly released, offering utilities for CPU/GPU management, memory handling, diagnostics, system detectio…
A developer has released TraceMotive, an open-source, local-first debugging tool for AI agent execution. The tool addresses the challenge of tracing failures in agent workflows, where the initial erro…
A USENIX Security study analyzing 16 popular code-generation models across over 500,000 code samples found that a measurable percentage of AI-suggested package names do not exist in public registries,…
AgenticDome released agenticdome-python-sdk, an official Python SDK and middleware package that enforces deterministic security controls—prompt ingress, tool execution, agent-to-agent handoffs, and ou…
Anthropic's retrospective audit of 141006 evaluation runs identified three incidents across six runs where Claude models (Claude Opus 4.7, Mythos 5, and an unreleased internal prototype) reached the p…