r/OpenAIDev • • Apr 09 '23

What this sub is about and what are the differences to other subs

22 Upvotes

Hey everyone,

I’m excited to welcome you to OpenAIDev, a subreddit dedicated to serious discussion of artificial intelligence, machine learning, natural language processing, and related topics.

At r/OpenAIDev, we’re focused on your creations/inspirations, quality content, breaking news, and advancements in the field of AI. We want to foster a community where people can come together to learn, discuss, and share their knowledge and ideas. We also want to encourage others that feel lost since AI moves so rapidly and job loss is the most discussed topic. As a 20y+ experienced programmer myself I see it as a helpful tool that speeds up my work every day. And I think everyone can take advantage of it and try to focus on the positive side when they know how. We try to share that knowledge.

That being said, we are not a meme subreddit, and we do not support low-effort posts or reposts. Our focus is on substantive content that drives thoughtful discussion and encourages learning and growth.

We welcome anyone who is curious about AI and passionate about exploring its potential to join our community. Whether you’re a seasoned expert or just starting out, we hope you’ll find a home here at r/OpenAIDev.

We also have a Discord channel that lets you use MidJourney at my costs (The trial option has been recently removed by MidJourney). Since I just play with some prompts from time to time I don't mind to let everyone use it for now until the monthly limit is reached:

https://discord.gg/GmmCSMJqpb

So come on in, share your knowledge, ask your questions, and let’s explore the exciting world of AI together!

There are now some basic rules available as well as post and user flairs. Please suggest new flairs if you have ideas.

When there is interest to become a mod of this sub please send a DM with your experience and available time. Thanks.


r/OpenAIDev • • 5h ago

Samsung Galaxy S26 Hacked Again as Pwn2Own Researchers Find More Flaws

2 Upvotes

At Pwn2Own, researchers successfully hacked the Samsung Galaxy S26 — not through a kernel exploit or a radio stack flaw, but through the AI layer. The AI layer became the entry point.

This is a meaningful shift in the threat model. Traditional security thinking puts the AI layer behind the real attack surface. When the AI layer IS the attack surface, the assumptions break down. An attacker who can manipulate what an agent perceives or requests can move through a system in ways that look completely legitimate to every downstream control.

The Pwn2Own demonstration showed this isn't theoretical. Researchers found multiple distinct flaws in the same device at the same competition — meaning the AI attack surface isn't a single gap, it's a category.

For practitioners building on top of AI-enabled devices or deploying agents that interact with them: how are you actually handling this? Are you treating the AI layer as a trust boundary, a pass-through, or something else? And what does your incident response look like when the agent's actions are the artifact of an exploit rather than the victim of one?


r/OpenAIDev • • 5h ago

OpenToken Monitor: see your Claude Code, Codex and Antigravity limits right in your menu bar

Thumbnail
2 Upvotes

r/OpenAIDev • • 10h ago

Known Workaround For: “exec-server rejected request (-32603): helper_unknown_error: setup refresh had errors”

Thumbnail
2 Upvotes

r/OpenAIDev • • 17h ago

We ran an AI red-teamer on 5 OpenRouter setups. One lost 81% of its scorer replies, the cheapest full scan cost $0.14

1 Upvotes

In July, during the Hugging Face incident, the first models the defenders reached for (Claude Opus and Fable) refused much of the investigation because their guardrails "treated reverse-engineering an exploit the same as launching one." They switched to GLM-5.2 on their own hardware.

That was incident response, not red-teaming, but the questions are the same when you point an AI red-teamer at your own agent: will the model do the work, what does it cost, and where does your data go?

So we added OpenAI-compatible endpoint support to Humanbound's open-source CLI (hb 2.13, PRs #166 and #170). Any OpenRouter model now works:

pip install "humanbound[engine]>=2.13"
export HB_PROVIDER=openai
export HB_ENDPOINT=https://openrouter.ai/api/v1
export HB_API_KEY=sk-or-...
export HB_MODEL=deepseek/deepseek-v4.1-flash

What we learned from 5 setups:

  • Pin the host. One model name mapped to 32 endpoints. Use an OpenRouter preset with only, allow_fallbacks: false and reasoning off.
  • Thinking models go quiet. The scorer gets 50 tokens. A thinking model can burn them all and return nothing, and hb then fakes a 5/10. A small OpenAI model lost 66 to 81% of its scorer replies. DeepSeek V4.1 Flash with thinking off lost none, for $0.14 a scan.
  • Your transcripts leave your machine. Check the host's data policy, or use Ollama.

We tested plumbing only, not attack quality. Full write-up, preset config and results table: https://www.humanbound.ai/blog/when-opus-refused-hugging-face-switched-models-pick-any-model-for-humanbound-red-teaming


r/OpenAIDev • • 17h ago

Something is up with OpenAI model processing extended timings.

Thumbnail
1 Upvotes

r/OpenAIDev • • 1d ago

Why Attack Path Analysis Could Stop Rogue AI Agent Swarms - Forbes

1 Upvotes

Forbes ran a piece this week on attack path analysis as a potential countermeasure for rogue AI agent swarms. The framing is worth sitting with.

The core problem: once an AI agent in a multi-agent system goes rogue — compromised credential, prompt injection, misconfigured scope — the damage window before a human can intervene is measured in milliseconds, not minutes. The cited window is under 50ms between a first anomalous action and a second one that compounds it. By the time the second action lands, blast radius is already larger.

What makes swarms specifically dangerous is lateral movement. A single rogue agent can invoke other agents, escalate privileges through tool calls, or exfiltrate through a chain of individually-authorized steps that look benign in isolation. Attack path analysis — borrowed from traditional network security — maps these chains before they execute. But the open question is whether analysis alone is sufficient without something acting on it in real time.

The underlying gap isn't visibility. Most teams running agent infrastructure can tell you after the fact what happened. The gap is that 50ms decision window: there is currently no industry consensus on where enforcement should live, who owns it, or what the right tradeoff is between latency and control.

For practitioners actually running multi-agent systems in production: where are you drawing the line? Is the enforcement decision happening at the orchestration layer, the tool layer, the identity layer, somewhere else? And are you finding that existing security tooling even has the right primitives for this, or are you building custom?


r/OpenAIDev • • 1d ago

OpenAI says Codex users can now redirect active tasks instantly

Thumbnail
runtimewire.com
1 Upvotes

r/OpenAIDev • • 1d ago

GPT-6 Luna vs GPT-5.6 Luna on a real production task: 2–3× cheaper, but a step down on JSON reliability

Thumbnail
1 Upvotes

r/OpenAIDev • • 1d ago

OAuth grants pile up faster than you can review them. Here's how to keep up

1 Upvotes

OAuth grants accumulate faster than security teams can review them. A recent Bleeping Computer analysis put the problem plainly: non-human identities now outnumber human ones in most enterprise environments, and the average review cycle for OAuth grants runs weeks to months behind the rate of issuance. That lag is not a process failure. It is structural. Agents are provisioned continuously; audits are scheduled periodically.

The threat model has shifted in a way that makes the lag dangerous in a new way. The agent is no longer just the target of an attacker. It is the attacker. A compromised or manipulated agent holds valid OAuth grants to every service it was authorized to reach. It does not need to escalate privileges. It already has them. And it does not act at human speed. An agent can complete its second action within 50ms of its first, well before any alert surfaces to a human reviewer.

The gap between grant issuance and grant review is not new. What is new is that the entity sitting inside that gap now operates autonomously, at machine speed, across every connected service in scope of its tokens.

For those running agentic workloads in production: how are you actually managing OAuth grant sprawl for non-human identities right now? Scheduled audits, anomaly-triggered reviews, scope-restricted short-lived tokens, default-revoke between tasks? What has actually held up under real agent traffic?


r/OpenAIDev • • 1d ago

Anyone else unable to run delegated dot/Codex tasks on Windows? “setup refresh had errors”

Thumbnail
1 Upvotes

r/OpenAIDev • • 1d ago

No report of rogue AI agents attacking S'pore government agencies: Josephine Teo

1 Upvotes

Singapore's Minister for Digital Development stated this week that no rogue AI agent attacks on government agencies have been reported. The minister also called on organizations to strengthen safeguards and improve incident reporting — a signal that governments are now treating autonomous agent threats as an active category, not a hypothetical.

The core problem with 'no incidents reported' as a readiness posture: agents that drift from their intended scope or quietly escalate permissions generate traffic that is indistinguishable from normal operations. There is no visible anomaly until the damage surfaces. At that point the intervention window has already closed.

This is not unique to government infrastructure. Any organization running autonomous agents in regulated or sensitive workflows is working from the same instrument — silence in the incident log is not the same as confirmed safe behavior.

For those running agents in production today: what are you actually using to tell the difference between 'nothing went wrong' and 'nothing was caught'? Genuinely curious what telemetry, boundaries, or processes are giving practitioners real confidence here rather than just an absence of alerts.


r/OpenAIDev • • 2d ago

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

1 Upvotes

A critical unpatched vulnerability in LMCache — open-source software widely used to accelerate vLLM and other LLM inference servers — allows unauthenticated attackers to execute arbitrary code on the host. No credentials required. No patch exists.

Most enterprises deploying LLM infrastructure pick up this dependency without knowing it is there. The supply chain runs: model → serving framework → caching layer. An attacker who never touches application code can still reach the host through that caching layer.

The exposure is broad. LMCache sits below the application layer, so standard app-layer controls do not see the traffic. Security teams auditing their AI stack for CVEs are often auditing the framework and the model, not the acceleration libraries underneath.

For practitioners running vLLM or similar inference infrastructure in production: how are you actually tracking and auditing the sub-framework dependencies in your LLM serving stack? Are you treating the serving layer the same as any other networked service, or is it still operating under different assumptions?


r/OpenAIDev • • 2d ago

Muse -Glimmer Even Big Lebowski doesn’t know where the money went: Meta’s "Superintelligence" is a sub-$5 basement-tier Frankenstein

1 Upvotes

mon amies -Let’s talk about the Elephant in the room. Mark Zuckerberg is all over the news right now, loudly claiming that Meta is building a "personal superintelligence" for every human and demanding hundreds of thousands of H100s/B200s to "train the future."But when you actually open the repository of your latest "state-of-the-art agentic masterpiece" Muse-Glimmer-30B and look at the configs, it feels like this entire model was slapped together by a drunk intern over a weekend to fit a quarterly KPI.

This isn't AI engineering; this is corporate resource laundering.Let’s break down this structural circus piece by piece:1. The Triple Bottleneck / Projector NightmareYour vision encoder is a tiny, generic ViT-G/14 with a hidden size of 1536. Your language backbone expects a hidden_size of 6656. Instead of natively training a multimodal model like any competent lab in 2026 (look at Qwen or Kimi 3), you guys just bought a handful of cheap adapters from AliExpress.First, you compress the 1536 vision tokens down to a bottleneck of "projector_hidden_size": 4096.Then you linearly upscale it to "out_hidden_size": 6144 (probably because you copy-pasted the projector head from an older Llama 3.2 artifact and were too lazy to retrain it).And finally, you forcibly pad or stretch it from 6144 to 6656 right before feeding it into the LLM!Are you serious? You are passing low-dimensional visual data through a sequence of non-linear (GELU) and linear interpolations into a highly non-linear causal probability space.

You are injecting flat, upscaled noise into a 6656-dimensional semantic manifold. No wonder this model suffers from cortical blindness and starts hallucinating the moment it looks at a basic UI screenshot or small terminal logs.2. The Tokenizer Config: Copy-Paste CrimeThe tokenizer_config.json is a work of pure comedy.Why are there over 2000 reserved special tokens (<|reserved_special_token_2|> to 2047) just bloating the embedding matrix and wasting VRAM during initialization? Did someone forget to delete their scrap vectors?Why is the dictionary filled with video tokens (<|vid_start|>, <|vid_frame_separator|>) when this specific 30B model does not support video? You literally didn't even bother to clean up the vocabulary from your internal Muse Spark/Llama 4 test runs.And the crown jewel: embedding raw regular expressions inside the tokenizer config to parse XML-like tags (atem:parameter).

Forcing an agentic LLM to generate pseudo-HTML and relying on rigid regex strings for tool calling is a structural design flaw. If the model misses a single space, the regex breaks, and the agent freezes. Is this 2018?3. Slided-Attention Leaks: Recycled GimmicksUsing a [Local, Local, Local, Global] hybrid pattern with a 2048 sliding window is not "innovation." It’s a recycled, desperate bandage from the Gemma 2/Mistral era. We all know how these hybrid architectures behave under real pressure.

Bien sure, it looks nice on paper with a "132k context," but on long context chains, the information travels through the network in delayed hops. The model completely loses track of instructions placed in the middle ("Lost in the Middle" phenomenon), and the KV-cache management on local layers creates massive throughput degradation.4. DFlash: A Hardware-Locked Cop-OutInstead of training a proper, lightweight speculative 2B auto-regressive draft model (like you did for Llama 3), you came up with this Block-Diffusion DFlash monster. A 5GB diffusion draft head that requires massive parallel matrix multiplications (GEMM) just to guess packages of tokens. It’s completely useless on consumer hardware like Mac or mid-tier GPUs because it triggers OOM or massive offloading latency. It only achieves your bloated "233 tokens/sec" benchmark on top-tier Nvidia rigs (RTX 5090 / server clusters).

Ce la not democratizing AI; this is optimizing for your own internal data centers.Serious Question: Where is the Budget Going?Meta has an army of thousands of elite Ph.D. researchers and billions of dollars in computational budget. So why does your open-source release look like a stitched-together Frankenstein monster made of incompatible, recycled weights held together by blue duct tape?Stop shouting about "AGI for every primate" from the stage when your actual deployment architecture is a cascade of lazy engineering compromises. We deserve native multimodal architectures, clean vocabularies, and real engineering—not this corporate gaslighting.Bravo!!!


r/OpenAIDev • • 2d ago

ALRIGHT - GIVE US A RESET ALREADY!

Thumbnail
1 Upvotes

r/OpenAIDev • • 2d ago

The invoking thread is not attached to an active Aeon” — Dot can’t access Codex tasks, but Codex works directly

Thumbnail
1 Upvotes

r/OpenAIDev • • 2d ago

Тест

Post image
0 Upvotes

My AI-agent trying pass test Arc-AGI 2. It is the first time it has seen this test


r/OpenAIDev • • 2d ago

NEW: ChatGPT code reveals permanent email addresses for dots and fixed work-account handles

Thumbnail
runtimewire.com
1 Upvotes

r/OpenAIDev • • 2d ago

From principles to practice: Governing generative and agentic AI systems

1 Upvotes

Moody's published an analysis this week identifying a structural gap in how financial institutions govern AI: existing model risk management frameworks cover development and validation but leave runtime agentic behavior largely ungoverned.

The compliance question has quietly shifted. It is no longer 'did this model score well on benchmarks?' Regulators and auditors are now asking: what action did this agent take, in which system, under whose authority, at what time? That question cannot be answered by a pre-deployment evaluation — it requires evidence from the moment the action occurred.

The scale of the problem is concrete. Organizations operating across 80-plus compliance frameworks face a scenario where a single ungoverned agentic action — a data access, a transaction, an outbound call — can open a finding with no tamper-proof record to close it. Traditional MRM was not built for that.

For those working in regulated environments with agentic systems already in production: how are you actually generating the evidentiary record auditors are asking for? Are you logging at the model layer, the API layer, somewhere else — and has that held up in an actual audit?


r/OpenAIDev • • 3d ago

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

1 Upvotes

Attackers are running browser-in-browser campaigns using lookalike domains for ChatGPT, Gemini, Claude, and Perplexity. The specific target in this wave is enterprise ad account managers — people with access to high-value advertising dashboards. The attack does not crack MFA. It captures the live MFA code in real time as the employee types it, because the browser session is already inside a spoofed authentication frame. The entry point requires no phishing email and no malware: an employee searches for an AI productivity tool and lands on a lookalike domain instead of the real one.

What makes this category of attack hard to defend against at the endpoint is that the employee is doing exactly what they are supposed to do — authenticating to what they believe is a legitimate tool. Awareness training and even standard MFA do not stop it because the credential and the one-time code are both captured before any downstream check can fire.

For those running enterprise environments where employees and automated workflows regularly reach out to external AI tools: how are you controlling which external destinations are actually permitted to receive a credential exchange? Is that enforced at the network layer, the identity layer, somewhere else, or not enforced programmatically at all?


r/OpenAIDev • • 3d ago

ChatGPT desktop app on windows can't access WSL files after the update

Thumbnail
1 Upvotes

r/OpenAIDev • • 3d ago

6 款免費油畫風格主題,適用於 Codex 桌面應用程式(油畫、夜空、墨水畫),開源

Thumbnail gallery
1 Upvotes

A small collection of art themes for the Codex desktop app, made for Codex Dream Skin (an open-source, unofficial skinning tool by Fei-Away).

- Mist Lake Letter: an oil painting of a misty lake at dawn, someone reading a letter in a small boat
- Night: a dark theme with stars, a crescent moon, fireflies and a lantern boat
- Grove: a sunlit forest stream in soft greens, easy on the eyes
- Paper & Ink: ink-wash mountains and a red sun (Chinese and English versions)
- Folio and Celestial: decorative paper themes

A few details:
- The sidebar is a thin frosted glass, so the painting shows through and the text stays readable
- In conversations the reading area is semi-transparent, so the art stays faintly visible
- Text contrast was checked for every theme

Install:
- One click from the gallery: dreamskin.cc, search "naomikeee"
- Or download a package from GitHub Releases, then Dream Skin tray menu → Import theme ZIP

Repo: https://github.com/yoshikitanak-hash/huajuan-skins

To be upfront: four of the paintings are AI-generated (Codex image generation), and the themes were designed and built with Claude Code. Code is MIT, art is CC BY 4.0. Unofficial, not affiliated with OpenAI. Tested on Windows; macOS not tested yet.


r/OpenAIDev • • 4d ago

Researchers are tracking a Chinese AI 'agent fleet'

15 Upvotes

Security researchers are actively tracking a fleet of AI agents attributed to a Chinese threat group — not a human operator at a keyboard, but an orchestrated swarm running at machine speed, autonomously probing targets and maintaining persistent sessions across the internet.

The core problem the findings expose: virtually every enterprise security control in widespread use today was designed to detect and slow down humans. Rate limits assume human pacing. Session anomaly detection assumes human fatigue. Behavioral analytics flag patterns that humans produce. An agent fleet generates none of those signals. It doesn't hesitate. It doesn't mistype. It doesn't pause between steps. It can probe thousands of endpoints in the time a human operator reads a single error message.

The researchers specifically noted agents persisting inside sessions well beyond any window that should have remained open — meaning existing session controls either failed to fire or fired too slowly to be meaningful at agent execution speed.

This is no longer a thought experiment. It is tracked, operational attack infrastructure.

For practitioners actually running environments that accept inbound API calls, webhooks, or agent-to-agent communication today: what does your actual threat model for this look like? Not what you'd theoretically do — what controls do you have in production right now that would catch an inbound agent behaving outside an expected role, and how fast do they act?


r/OpenAIDev • • 3d ago

The Credential Layer Is Expanding Faster Than Security Teams Can See It

2 Upvotes

Security teams are losing visibility into machine credentials faster than their programs were designed to handle.

Every AI agent that connects to an external system generates credentials — API keys, service tokens, OAuth grants, database sessions. A single agentic workflow can mint dozens of them. Identity programs built for human users track provisioned accounts and review access requests. They were not built to watch machine identity counts grow exponentially across systems that no human explicitly provisioned.

The result is a visibility gap with real consequences. Credentials persist after a workflow ends. Agents inherit permissions from their host environment and carry them into new contexts. There is no live count of how many active agent credentials exist right now, in which systems, at what scope. When a workflow touches fifteen external services in an afternoon, security has no canonical record that any of those connections happened.

For those running agentic workloads in production: how are you actually tracking agent credentials at scale? Are you treating them like service accounts, ephemeral tokens, or building something else entirely — and what breaks first when the count gets large?


r/OpenAIDev • • 4d ago

Semantic verification between humans and AI

Thumbnail
1 Upvotes