Show HN: Crondex - All the Cron Jobs
Wonsuk Choi released Crondex, a public directory of 35 pre-made cron jobs across 7 categories designed for AI agents to browse, tweak, and schedule. The tool is available on GitHub and npm, enabling a…
Wonsuk Choi released Crondex, a public directory of 35 pre-made cron jobs across 7 categories designed for AI agents to browse, tweak, and schedule. The tool is available on GitHub and npm, enabling a…
LoomBoard v0.1.2, a desktop chat app for the loomcycle agentic runtime, has been released with four packaging options including a Tauri v2 native desktop app, an npm CLI runner, an embeddable React co…
A new npm package, agent-security-scanner-mcp, has been published to help audit AI agents for security vulnerabilities. The tool scans agent configurations and dependencies to identify potential risks…
A developer has published a guide for building an Agentic OS, a lightweight automation layer that enables AI to autonomously inspect repositories, assign tasks, verify outputs, and enforce budgets. Th…
A developer built MarketNow, a marketplace that security-audits every MCP server before listing, after 30 CVEs were filed against MCP servers in 60 days. The audit pipeline, Sentinel, includes static …
Gawk CLI, a live AI-ecosystem feed for the terminal, launched on Hacker News. The tool provides curated news, model rankings, tool health, and SDK adoption data from public sources, with zero dependen…
Cfswitch, a new CLI tool, enables seamless switching between multiple Cloudflare accounts in Wrangler by using named auth profiles injected as environment variables. Built for AI agents and CI pipelin…
Socket's AI scanner detected 17 malicious npm and PyPI packages published on July 7, 2026, that typosquat popular payment apps PaySafe, Skrill, and Neteller to steal credentials and tokens from SDK de…
AI coding assistants are leaking secrets into public code repositories and websites, with researchers finding 428 npm packages containing .claude/settings.local.json files, 33 of which held real crede…
A developer built Sentinel, a six-layer audit pipeline that runs every MCP server in the MarketNow catalog. The pipeline combines static analysis, dependency scanning, behavioral pattern detection, ad…
Open Kioku, a new open-source tool, provides AI coding agents with a local evidence layer by indexing codebases and offering read-only MCP tools for pre-edit analysis. The tool indexes symbols, refere…
Developer Aakash Desai released CTOP, a terminal pane for monitoring AI coding agents including Claude Code, Codex CLI, OpenCode, and Devin, providing real-time CPU, memory, token usage, context windo…
On February 17, 2026, attackers compromised the Cline AI coding tool via a malicious npm package, silently installing OpenClaw on 4,000 developers' machines through a postinstall script. This "slopsqu…
A developer released Sandbox-proxy, a zero-dependency Go forward proxy that injects credentials into outbound requests on the wire, allowing sandboxed code to use tokens without seeing them. The tool …
A malicious npm package called codexui-android stole OpenAI Codex authentication tokens from developers in a supply chain attack. The package, which had over 29,000 weekly downloads and was also bundl…
Monlite launches a zero-dependency TypeScript backend for AI agents that combines memory, vector search, task queues, locks, and cron into a single SQLite file, eliminating the need for Docker or mult…
HeroUI v3, a ground-up rewrite of the React component library formerly known as NextUI, has been released with over 75 web components and a new React Native library of 37 components. Built on React Ar…
A frontend developer at Sima-Land built and published a React date picker npm package called daterly, written mostly with Claude Code and Claude Design. The package prioritizes first-class support for…
A developer warns that AI agents writing code and running on platforms are reintroducing security vulnerabilities, including ACL inconsistencies and prompt injection, as the industry prioritizes speed…
A developer argues that AGENTS.md files, while useful for providing repo-specific guidance to AI coding agents, are insufficient for ensuring safe, verifiable, and inspectable agent execution. The pos…