gm legends, happy Monday.
Today: a desktop dinosaur pet that grew into a full agent platform, a serial founder scrubs the gibberish brands out of Amazon, and a security startup pays you to talk a chatbot out of its secrets.
Is this your brand on Milled? Claim it.
|
|||
|
gm legends, happy Monday.
Today: a desktop dinosaur pet that grew into a full agent platform, a serial founder scrubs the gibberish brands out of Amazon, and a security startup pays you to talk a chatbot out of its secrets.
Terence (@tpae) spent 20 years shipping software at Netflix, Tesla, and Zillow, then went all in on a 5MB desktop dinosaur. Osaurus is what it became: an open source AI agent platform that runs entirely on your Mac. MIT licensed, native Swift, no account, no subscription, no Electron.
🔥 Our Take: Osaurus started as Dinoki, a desktop pet, and the open source community pulled it into a full agent platform: 7K GitHub stars and 175K downloads, all word of mouth. Ollama and LM Studio hand you a local model and stop there. This one gives agents a sandboxed Linux VM where they build slide decks, deploy websites, and in one case Terence watched an agent write itself a new skill to finish a task, all without your files ever leaving the machine. Local AI keeps getting dismissed as a hobbyist niche. 175,000 downloads is a lot of people quietly disagreeing.
Search Amazon for anything and half the results are brands nobody has ever heard of, with names like SZHLUX and HORUSDY that exist to squat a trademark and rent a search slot. Knockoff is Josh Pigford's (@shpigford) open source Chrome extension that removes them, leaving only brands with a reputation to lose.
🔥 Our Take: Fakespot spent years flagging fake reviews, got bought by Mozilla, and still got shut down last summer, because catching lies one review at a time is a treadmill. Pigford's cut is simpler: ignore the reviews and remove the sellers with nothing to lose. Amazon could ship this filter tomorrow and never will, since those sellers buy the ads. So it has to live in your browser instead. Pigford has started fifty-odd companies, sold Baremetrics, open sourced Maybe, and this is the kind of thing he builds between things: small, pointed, and aimed at a problem the platform profits from not solving.
Playground puts a live AI agent in front of you, publishes its full system prompt, and pays you to break it. First challenge: Kai, an assistant guarding a classified access code, with real web search and browser access. Zach (@zachx0) and Ibrahim Abdu (@ibrahim_abdu1) of Fabraix review every submitted break by hand, and the weekly leaderboard pays out of a pot they say runs past $100K.
🔥 Our Take: Every AI company insists its agent can't be talked into anything. Fabraix red-teams those agents for a living, and Playground turns the day job into a public sport with the defenses shown face up. Bug bounties did this for software twenty years ago, and hackers went from lawsuit targets to a line item in every security budget. Prompt injection is getting the same upgrade, which tells you it stopped being a party trick and became a profession. Publishing the system prompt is the honest part: if your agent's security depends on nobody reading its instructions, it was never secure.
Luke (@lukem121) builds an API that pulls data from 13 social platforms, and posted that the scraping was never the hard part. It's how differently every platform breaks: rate limits that change without notice, auth that expires silently, structured data one week and a wall of JavaScript the next. He asked which platform has burned people worst.
The war stories came fast. Mukesh Kumar rebuilt his entire workflow from scratch after Reddit changed its API rules. Narek Keshishyan (@narek_keshishyan) mapped the whole spread from running one consumer app across three platforms: Bluesky does everything through the public API and it just works, Threads hides every useful read behind another OAuth re-consent, and Instagram offers a human in a browser or nothing. His fix: automate discovery everywhere, act by hand where the platform demands a human.
Sharpest point goes to Akbar B (@akbar_b): the failure that hurts isn't a clean 403 you can catch and escalate, it's the shadow-block, a 200 response carrying quietly degraded data that poisons your dataset for days before anyone notices. His rule: "Status lies; the payload doesn't." Watch the shape of the response, not the code on it.
We send this email daily.
Feel free to switch to weekly or unsubscribe from these emails at any time.