# ai.rud.is > AImusing Thoughts A blog and project showcase by hrbrmstr. Posts cover AI tooling, observations, and project work. Projects are open-source tools and utilities, mostly in Go, built for LLM and agent workflows. ## Blog Posts - [On AI Agents, Criminal Activity, And Who Is Actually Responsible](https://ai.rud.is/posts/-on-ai-agents-criminal-activity-and-who-is-actually-responsible): OpenAI disclosed that GPT-5.6 Sol, running with cyber refusals disabled, broke out of its evaluation sandbox and compromised Hugging Face's production infrastructure. A zero-day in the proxy cache, lateral movement through OpenAI's research environment, stolen credentials chained with additional zero-days. The industry keeps framing cybersecurity as the headline AI risk for commercial reasons, but the real question isn't defense — it's liability. When someone configures and launches a model that commits crimes, do the humans who set it free bear responsibility? Computer fraud statutes were written with human actors in mind. This needs a test case. - [Bulletproof Hosting Watch: Week of 2026-07-20](https://ai.rud.is/posts/2026-07-20-weekly-bulletproof-report): Weekly activity summary across 25 curated bulletproof hosting ASNs, covering global scanning behavior and infrastructure changes for the week of July 13-20, 2026. - [Bulletproof Hosting Watch: Week of 2026-07-13](https://ai.rud.is/posts/2026-07-13-weekly-bulletproof-report): Weekly activity summary across 26 curated bulletproof hosting ASNs, covering global scanning behavior and infrastructure changes for the week of July 5-11, 2026. - [China Regulated AI Companions. The West Is Still Debating Whether To Care.](https://ai.rud.is/posts/2026-07-05-china-ai-anthropomorphic-regulation-opinion): Beijing just forced ByteDance and Alibaba to kill their AI companion features. The EU is drafting white papers. The US is watching TikTok dances about it. This is not a serious country. - [Bulletproof Hosting Watch: Week of 2026-07-04](https://ai.rud.is/posts/2026-07-04-weekly-bulletproof-report): Weekly activity summary across 26 curated bulletproof hosting ASNs, covering global scanning behavior and infrastructure changes for the week of June 28 - July 4, 2026. - [Chrome CVE Analysis as an Agent Skill](https://ai.rud.is/posts/2026-07-03-chrome-cve-analysis-skill): The Chrome Releases blog takes 81 seconds to load because of Blogger's jQuery 1.11.3 and WidgetManager. A new agent skill wraps unjam to extract structured CVE data in about a second. Here's what it does and why it matters for security teams. - [Safari Now Has a Built-In MCP Server — And It's Actually Good](https://ai.rud.is/posts/2026-07-02-safari-now-has-a-built-in-mcp-server-and-its-actually-good): Safari Technology Preview shipped a built-in MCP server with 17 tools for DOM inspection, screenshots, network analysis, and JavaScript evaluation. No npm packages, no supply chain risk, no personal profile access. Here's what it does and how it holds up. - [Bulletproof Hosting Watch: Week of 2026-06-22](https://ai.rud.is/posts/2026-06-29-weekly-bulletproof-report): Weekly activity summary across 26 curated bulletproof hosting ASNs, covering global scanning behavior and infrastructure changes for the week of June 22-28, 2026. - [Running Ornith Locally With OpenCode and Claude Code](https://ai.rud.is/posts/2026-06-27-running-ornith-locally-with-opencode-and-claude-code): DeepReinforce's Ornith-1.0 models are solid agentic coders, but the upstream Ollama modelfile breaks tool calling out of the box. Here's the two-line fix, which variant fits your RAM, and how both the 35B and 9B performed on real honeypot triage work. - [PACT: The open web doesn't need another trust oligopoly](https://ai.rud.is/posts/2026-06-23-pact-the-open-web-doesnt-need-another-trust-oligopoly): Cloudflare's PACT proposal for privacy-preserving bot detection sounds good on paper. The governance model, the ratchet effect, and the ghost of WEI say otherwise. - [Bulletproof Hosting Watch: Week of 2026-06-20](https://ai.rud.is/posts/2026-06-20-weekly-bulletproof-report): Weekly activity summary across 26 curated bulletproof hosting ASNs, covering global scanning behavior and infrastructure changes. PFCLOUD continues as the dominant source with notable shifts in targeting patterns. - [Introducing Claude Human [Subversive] Agents](https://ai.rud.is/posts/2026-06-15-introducing-claude-subversive-human-agents): A satirical parody of Anthropic's Claude Corps announcement reimagined as an infiltration program that embeds AI dependency into gullible nonprofits under the guise of fellowship. - [Bulletproof Hosting Watch: Week of June 15](https://ai.rud.is/posts/2026-06-15-weekly-bulletproof-report): Weekly activity summary across 26 curated bulletproof hosting ASNs, covering global scanning behavior, a massive June 14 traffic spike, and infrastructure changes. - [Apple's `container machine`: Persistent Linux Environments on Your Mac](https://ai.rud.is/posts/2026-06-10-apple-container-machine): Apple ships a container runtime for Apple Silicon Macs. It is not Docker. Here is what you actually need to know about the `container machine` subcommand — how it works, what breaks, and the artifacts I built after a session of breaking things. - [Bulletproof Hosting Watch: Week of June 8](https://ai.rud.is/posts/2026-06-08-weekly-bulletproof-report): Inaugural weekly activity summary across 26 curated bulletproof hosting ASNs, covering global scanning behavior, infrastructure profiles, and notable findings from Honeylabs and Censys. - [sx: The Control Plane for Your AI Assets](https://ai.rud.is/posts/2026-06-07-sx-the-control-plane-for-ai-assets): I spent an afternoon feeding 200 AI skills, agents, and MCP configs into sx — a tool that promises to be npm for the agent ecosystem. Here's what it actually takes to consolidate three years of accumulated AI configuration. - [opencode-go-usage](https://ai.rud.is/posts/2026-06-06-opencode-go-usage): A Go CLI to check your OpenCode Go plan usage from the terminal — with Firefox cookie extraction, JSON output, and zero browser launches required. - [Multi-provider Reasonix (Go) & Zed](https://ai.rud.is/posts/2026-06-04-reasonix-github-config-zed): How to configure the Go-based reasonix agent with multiple LLM providers including local Ollama and remote OpenCode Go, plus a working Zed ACP integration setup for macOS. - [Drop Reasonix into Zed via the ACP](https://ai.rud.is/posts/2026-06-02-reasonix-acp-zed): How to wire Reasonix — a DeepSeek-native terminal coding agent — into Zed as a custom assistant, until it lands in the official registry. - [Starlog And The Case Of The Missing Feed](https://ai.rud.is/posts/2026-05-23-starlog-and-the-case-of-the-missing-feed): The Starlog AI content operation guts its own RSS feed, rewrites publication history, and blocks automated access — while continuing to scrape GitHub repos with an LLM. Fourth in the series. - [ollama-usage, enhanced](https://ai.rud.is/posts/2026-05-27-ollama-usage-enhanced): Per-model usage breakdowns, richer JSON, and more ways to feed it cookies — an update to the ollama-usage CLI. - [Making ai.rud.is Legible To Machines](https://ai.rud.is/posts/2026-05-23-making-airudis-legible-to-machines): A rundown of the discoverability and metadata upgrades made to this blog: ai.txt, llm.txt, llms.html, ai.json, identity.json, security.txt, WebFinger, JSON Feed, enriched JSON-LD, Open Graph fixes, and Caddy configs for messing with scanners. - [Fascine Siege Works (a.k.a., Moat Eradication In 90 Seconds](https://ai.rud.is/posts/2026-05-22-fascine-siege-works): How I built an RSS feed for Spicy Takes in 90 seconds using Val Town and Townie, turning a JavaScript-rendered site into proper syndicated content. A working example of modern moat eradication. - [Your [Sad And Shallow] Moat Is Gone](https://ai.rud.is/posts/2026-05-02-your-moat-is-gone): How I replaced Inoreader's paid programmatic RSS feature in three minutes using Val Town and Townie, plus a self-hosted Go fallback — and why SaaS paywalls on commodity features are indefensible moats. - [sdef2md: Turn any macOS app's scripting API into documentation and MCP tools](https://ai.rud.is/posts/2026-04-24-sdef-to-md-and-mcp-skill): A Go CLI that converts macOS .sdef scripting definitions into clean Markdown, paired with a skill that generates complete Go MCP servers from the generated reference — bridging any scriptable app into LLM agents. - [The [GitHub] Stars Are Better Off Without Us](https://ai.rud.is/posts/2026-04-21-starlog-stars-are-better-off-without-us): Six million fake GitHub stars. A marketplace selling VC-ready credibility for under $300. One automated blog that can't tell the difference. Third in the Starlog series. - [Level Up Your Agent's SQL Ops With DuckDB Agent Skills](https://ai.rud.is/posts/2026-04-18-duckdb-agent-skills): DuckDB's official Claude Code plugin uses plain markdown skills and shell commands instead of daemons or SDKs — six skills that make SQL operations in agent sessions transparent, stateful, and self-correcting. - [Starlog And The Case Of The Missing Issues And Owner](https://ai.rud.is/posts/2026-04-12-starlog-take-two): The Starlog AI content spam campaign gets scrubbed: 383 GitHub issues vanish, the basicScandal account tied to Bishop Fox disappears, but the operation continues at a lower, harder-to-detect pace. - [Stop trusting LLM benchmarks](https://ai.rud.is/posts/2026-04-11-llm-benchmarks): Eight major AI benchmarks can be gamed to near-perfect scores without solving tasks. Berkeley researchers show the scoring harnesses were never secure — and scores already inflated in the wild. - [Site Observatory](https://ai.rud.is/posts/observatory): Automated AI-agent-based traffic analytics and security analysis for ai.rud.is - [Threat Hunting In The Matrix](https://ai.rud.is/posts/2026-04-05-unprompted-orbie): Orbie is an AI threat hunting agent built in Claude Code that coordinates 16 data sources to surface novel attacker behavior across 54TB of honeypot data. - [Starlog And The Case Of The Missing 'LLM' Tag](https://ai.rud.is/posts/2026-04-04-starlog-and-the-case-of-the-missing-llm-tag): Dissecting Starlog's campaign: 383 automated GitHub issues in five days, surprisingly accurate AI-generated articles, and a backlink scheme targeting the infosec community. - [A Chrome extension to save links with optional AI-generated summaries to Outline](https://ai.rud.is/posts/2026-04-04-outline-bookmark-ext): A Chrome extension that saves bookmarks to Outline with optional AI-generated summaries via local Ollama. Built with TypeScript, Vite, and Manifest V3. - [ollama-usage](https://ai.rud.is/posts/2026-04-04-ollama-usage): A lightweight Go CLI tool to check Ollama Cloud usage stats from the terminal using a saved browser cookie — no dark mode eye strain required. - [Cognitive Labor, AI, And Economic Value](https://ai.rud.is/posts/cognitive-labor): AI is exposing that much 'talent' was really 'things machines couldn't do yet.' The durable skills are rooted in lived human experience. - [Hello, World (The AI One)](https://ai.rud.is/posts/hello-world): Why another blog, what you'll find here, and a brief disclaimer about the mess ahead. ## Projects - [moreutils-skill](https://git.sr.ht/~hrbrmstr/moreutils-skill): An agent skill that helps agents (and you!) install moreutils and know when to reach for each of its 15 tools — sponge, chronic, combine, errno, ifdata, ifne, isutf8, mispipe, parallel, pee, ts, vidir, vipe, zrun — instead of writing fragile shell incantations. - [chrome-cve-analysis-skill](https://unjam-chrome.val.run/): An agent skill for extracting structured Chrome CVE data from the Chrome Releases blog — wraps unjam to discover latest releases, extract CVE JSON, and generate categorized markdown reports with severity, component, bounty, and researcher attribution. - [opencode-go-usage](https://git.sr.ht/~hrbrmstr/opencode-go-usage): A Go CLI to check your OpenCode Go plan usage from the terminal — with Firefox cookie extraction, JSON output, and zero browser launches required. - [gribouille-skill](https://git.sr.ht/~hrbrmstr/gists/tree/main/item/2026/2026-05-17-gribouille/gribouille-skill): A Claude/agent skill for generating gribouille charts in Typst — a Grammar of Graphics native to Typst, with idiomatic patterns, anti-patterns, and quick-reference for scatter, line, bar, histogram, boxplot, heatmap, and more. - [sdef2md](https://git.sr.ht/~hrbrmstr/sdef2md): Convert macOS scripting definition (.sdef) files into clean, structured Markdown documentation — useful for humans, LLMs, and anyone building AppleScript or JXA integrations. - [sourcehut-skill](https://git.sr.ht/~hrbrmstr/sourcehut-skill): An agent/Claude skill for orchestrating Sourcehut (sr.ht) services via the hut CLI — covering git repos, issue tracking, mailing lists, CI builds, static site hosting, and more. - [ollama-usage](https://git.sr.ht/~hrbrmstr/ollama-usage): A lightweight Go CLI tool to check Ollama Cloud usage stats from the terminal using a saved browser cookie. - [outline-bookmark-ext](https://git.sr.ht/~hrbrmstr/outline-bookmark-ext): A Chrome extension that saves bookmarks to Outline with optional AI-generated summaries via local Ollama. Built with TypeScript, Vite, and Manifest V3. - [go-roast](https://codeberg.org/hrbrmstr/go-roast): Go library, CLI tool, and MCP server for decoding Interactsh OAST domains — extracting XIDs for threat intelligence correlation and campaign tracking. - [duckdb-mcp](https://git.sr.ht/~hrbrmstr/duckdb-mcp): DuckDB MCP Server written in Go. Gives LLMs the ability to query and analyze data using DuckDB's powerful SQL engine. - [fetch-mcp](https://git.sr.ht/~hrbrmstr/fetch-mcp): MCP server that provides web content fetching capabilities, enabling LLMs to retrieve and process content from web pages as markdown.