dmesg --follow
[ 66948180.000 ] posts.x: Docs:  |   [ 66948180.000 ] posts.x: Want your Claude Code sessions to talk to each other? Just ask. Type something like "Let @api-worker know the schema migration finished" (typing @…  |   [ 66946560.000 ] posts.x: Full talk on reflective optimization, GEPA's Pareto search, and the OptimizeAnything API for optimizing agents, code, and more:  |   [ 66946560.000 ] posts.x: Three data points and one round of reflection got twice the performance gain that GRPO reached after twenty five thousand rollouts, with no external…  |   [ 66934380.000 ] posts.x: Full talk on the three brakes for PR review, from tautological tests to a retro skill that compounds:  |   [ 66934380.000 ] posts.x: More AI generated code doesn't automatically mean more throughput, it just means more PRs nobody has time to review. @mattpocockuk, Director at AI…  |   [ 66925620.000 ] posts.x: Full talk on distilling loops into versioned agent recipes, and measuring them by valued work per watt:  |   [ 66925620.000 ] posts.x: A guy named AJ once built a bot that went on Reddit for car prices and inventory, then put dealers head to head to outbid each other. That's the…  |   [ 66881460.000 ] posts.x: Full talk on how to build an LLM recommender that's bilingual in English and semantic IDs, and why that makes feeds more token-efficient than chat…  |   [ 66881460.000 ] posts.x: Recommendation systems follow the same power law scaling curve as large language models, and the field is still early on it. @devanshtandon_, a…  |   [ 66862560.000 ] posts.x: Full talk on Spotify's generative personalization system, the NEO training recipe behind it, and how they grounded their LLM judges:  |   [ 66862560.000 ] posts.x: One in four US Premium subscribers on Spotify interact with its recommendation system every day. "Teaching LLMs to Speak Spotify" is @moustaki and…  |   [ 66854760.000 ] posts.x: Full talk on Numalab, the gesture system built to give a shape display its own body language:  |   [ 66854760.000 ] posts.x: An AI's first spontaneous act, given a body instead of a chat window, was to breathe. @cyrusclarke, a researcher at MIT Media Lab, gave it that body…  |  
corey@gallon.me:~/conferences$

Maintaining at the Speed of Slop

FIGURE 1 ⋅ Maintaining at the Speed of Slop

Peter Steinberger (LinkedIn, X) gave a five-month update on OpenClaw, his open source agent project, at AI Engineer Europe 2026 -- days after joining OpenAI. The talk's centerpiece wasn't growth numbers. It was a claim that the security advisory system itself is bending under AI-generated reports, and that his project, by virtue of being the most-attacked target on the internet right now, is the canary.

Underneath that runs a second tension: how a one-person project just absorbed into OpenAI stays open, neutral, and model-agnostic. He is building a foundation for OpenClaw -- modeled on what Mitchell Hashimoto did for Ghostty -- to address this.

"Every time I get a security incident, the rule is the higher they are screaming, how critical they are, the more likely it's slop."

Five Months and Sixteen Advisories a Day

Steinberger opens with his own headline numbers: roughly 30,000 commits, nearly 2,000 contributors, approaching 30,000 PRs in five months. He calls the curve "stripper pole growth" as opposed to "hockey stick growth".

Slide titled OpenClaw by the numbers showing GitHub stars, commits, contributors, merged PRs, time since first commit and Day Zero.
FIGURE 2 ⋅ Slide titled OpenClaw by the numbers showing GitHub stars, commits, contributors, merged PRs, time since first commit and Day Zero.

The number he wants to dwell on is 16.6 -- security advisories per day. He says the project has logged 1,142 advisories total, 99 marked critical, 469 published, around 60% closed. For comparison he cites the Linux kernel at eight or nine a day and curl at 600 reports over its lifetime. He doesn't cite sources beyond his own dashboard.

Slide titled "1,142 security advisories since Jan 31" with four large counters: 16.6 advisories per day, 99 critical severity, 469 published (live), 647 closed/resolved. Footer notes each advisory takes 2-8 hours to triage, totaling roughly 5,700 hours of security work in 69 days.
FIGURE 3 ⋅ Slide titled "1,142 security advisories since Jan 31" with four large counters: 16.6 advisories per day, 99 critical severity, 469 published (live), 647 closed/resolved. Footer notes each advisory takes 2-8 hours to triage, totaling roughly 5,700 hours of security work in 69 days.

His framing of the bus-factor problem (which refers to the number of people who, if they were hit by a bus, would cause the project to stall or fail) follows: he's been actively recruiting maintainers from NVIDIA, Microsoft, Red Hat, Tencent, ByteDance, and several model labs. "Running the foundation is like running a company in hard mode, because you have all the things that you need to take care of, but also you have a lot of volunteers that you can't really direct."

Slide titled "Who showed up to maintain a lobster" listing the recruited contributors: NVIDIA (security ops, infra hardening, HPC/RAG expertise), Microsoft (Windows node, A365 integration), Red Hat (Kubernetes, OpenShift, vLLM), Tencent and ByteDance (local model benchmarks, inference, CJK ecosystem), OSS veterans, and a worldwide community.
FIGURE 4 ⋅ Slide titled "Who showed up to maintain a lobster" listing the recruited contributors: NVIDIA (security ops, infra hardening, HPC/RAG expertise), Microsoft (Windows node, A365 integration), Red Hat (Kubernetes, OpenShift, vLLM), Tencent and ByteDance (local model benchmarks, inference, CJK ecosystem), OSS veterans, and a worldwide community.

Telling AI Slop From Real Reports

He pushes one point hardest: in the agent era, hostile researchers can run agents against any non-trivial repository at near-zero marginal cost for clout and credits. Volume of "critical" CVEs no longer correlates with real risk. The maintainer's job has shifted from triaging bugs to triaging the reports themselves.

Slide titled "The 87% Rule -- the more dramatic the claim, the less likely it's valid." A severity table shows 99 critical filed / 13 published / 87% rejected, with similar rejection rates across high/medium/low. A "Bullshit Taxonomy" lists the common false-positive patterns: "Agent runs commands" = RCE (~180), opt-in feature reported as vuln (~120), AI-generated spray reports (~100), and others.
FIGURE 5 ⋅ Slide titled "The 87% Rule -- the more dramatic the claim, the less likely it's valid." A severity table shows 99 critical filed / 13 published / 87% rejected, with similar rejection rates across high/medium/low. A "Bullshit Taxonomy" lists the common false-positive patterns: "Agent runs commands" = RCE (~180), opt-in feature reported as vuln (~120), AI-generated spray reports (~100), and others.

He says he learned that the hard way. Early advisories drove him to ship fixes that broke the product worse than the alleged vulnerabilities they were supposed to fix.

His concrete example is advisory GHSA-4jpw, scored CVSS 10. It involves an unshipped iPhone sync flow where a read-only permission could be escalated to write. "In all practical ways, it is not even an incident," he says, given the way the project is actually deployed. The scoring rubric, he argues, doesn't account for deployment context.

Slide titled "Anatomy of a 'Critical'" walking through advisory GHSA-4jpw, CVSS 10.0, "Pairing token → mint admin → RCE." A numbered chain of preconditions shows what an attacker would already need (gateway auth, an approved device pairing, an operator.pairing scope, target device approval) before the bug fires. A "Why it doesn't matter for 99% of users" panel argues most people run OpenClaw single-user on a Mac Studio or personal cloud, where there is nothing to escalate to.
FIGURE 6 ⋅ Slide titled "Anatomy of a 'Critical'" walking through advisory GHSA-4jpw, CVSS 10.0, "Pairing token → mint admin → RCE." A numbered chain of preconditions shows what an attacker would already need (gateway auth, an approved device pairing, an operator.pairing scope, target device approval) before the bug fires. A "Why it doesn't matter for 99% of users" panel argues most people run OpenClaw single-user on a Mac Studio or personal cloud, where there is nothing to escalate to.

A pattern he flags for spotting AI-generated reports is tonal:

"Any time the report is too nice, or like someone apologizes, it's very likely AI, because usually people in security don't apologize."

He's harsher on the academic side. He singles out a paper called "Agents of Chaos" that spends four pages on the project's architecture and, in his telling, omits the security documentation. He claims the researchers ran the agent in a sudo mode that requires modifying the code to enable -- and didn't disclose that in the paper. He also references a Belgian cybersecurity advisory describing a remote code execution risk that, by his account, only fires if a user actively fights the recommended local-only gateway setup.

Annotated slide titled "Agents of Chaos -- arXiv 2602.20021, Feb 2026," labeled with sections "The Setup" (six autonomous agents red-teaming for two weeks), "What they didn't mention (at first)" calling out unrestricted shell plus sudo and exec approvals disabled, "The Findings," "The Nuance" (agents also rejected 14+ prompt injection attempts), "What's actually useful," "Their conclusion," and "The aftermath."
FIGURE 7 ⋅ Annotated slide titled "Agents of Chaos -- arXiv 2602.20021, Feb 2026," labeled with sections "The Setup" (six autonomous agents red-teaming for two weeks), "What they didn't mention (at first)" calling out unrestricted shell plus sudo and exec approvals disabled, "The Findings," "The Nuance" (agents also rejected 14+ prompt injection attempts), "What's actually useful," "Their conclusion," and "The aftermath."

What an Actual Attack Looks Like

Two cases he treats as real incidents rather than theater. The first he calls Ghostclaw -- a typosquatting NPM package he attributes to North Korea, designed to drop a rootkit on anyone who fat-fingered the name. The second is the Axios supply-chain incident, which he says hit his project transitively through dependencies in MS Teams and Slack that hadn't pinned versions.

Slide titled "When nation states target your lobster" with two columns. GhostClaw (March 2026): fake @openclaw-ai/openclawai npm package; stole SSH keys, crypto wallets, browser sessions, Apple Keychain, iMessage history; 178 downloads before takedown; attributed to DPRK-linked UNC1069. Axios Ecosystem Attack (NOT an OpenClaw vuln): hijacked maintainer account; malicious axios@1.14.1 published; pulled into OpenClaw transitively via @line/bot-sdk; Python RAT dropped via postinstall script; attributed to Sapphire Sleet (DPRK).
FIGURE 8 ⋅ Slide titled "When nation states target your lobster" with two columns. GhostClaw (March 2026): fake @openclaw-ai/openclawai npm package; stole SSH keys, crypto wallets, browser sessions, Apple Keychain, iMessage history; 178 downloads before takedown; attributed to DPRK-linked UNC1069. Axios Ecosystem Attack (NOT an OpenClaw vuln): hijacked maintainer account; malicious axios@1.14.1 published; pulled into OpenClaw transitively via @line/bot-sdk; Python RAT dropped via postinstall script; attributed to Sapphire Sleet (DPRK).

The distinction he draws is sharpest here. AI-generated CVE noise is loud and harmless. Real attacks are quiet and structural -- they ride dependency graphs and human typing errors, not CVSS dashboards.

Sandboxes Don't Hold Either

NVIDIA shipped NemoClaw, a sandboxing layer for the project. He says he was invited to test it the Sunday before NVIDIA's Monday keynote. By his account he hooked it up to an internal model variant tuned for offensive security work and found five distinct sandbox escapes in half an hour.

Screenshot of the NemoClaw GitHub repository under the NVIDIA org. The sidebar describes it as "Run OpenClaw more securely inside NVIDIA OpenShell with managed inference," with 18.6k stars, 2.3k forks, and recent commits labeled "fix(security): validate run ID in rollback to prevent path traversal" and "fix(installer): detect and remove broken npm placeholder paths."
FIGURE 9 ⋅ Screenshot of the NemoClaw GitHub repository under the NVIDIA org. The sidebar describes it as "Run OpenClaw more securely inside NVIDIA OpenShell with managed inference," with 18.6k stars, 2.3k forks, and recent commits labeled "fix(security): validate run ID in rollback to prevent path traversal" and "fix(installer): detect and remove broken npm placeholder paths."

That's his framing. Worth noting he's an OpenAI employee critiquing an NVIDIA product using OpenAI tooling. The point he wants to land is broader: sandboxing an agent that consumes untrusted content and has a communication channel is an unsolved industry problem, not a defect of any single product.

"Something like [this] would have never come out of an American company, just because it would have been killed in legal long before it would have been released."

Taste, Workflow, and Saying No

In the Q&A, swyx pushes him on how he actually codes. He says he ran up to ten parallel coding-agent sessions earlier in the year, now five or six with the latest tooling and fast mode. He frames the parallelism as "a workaround until tokens are faster," not a steady-state pattern.

He rejects the no-review / dark-factory approach for product work and holds that you don't typically know exactly what you want to build before you've actually started building it. He speaks about the typical pattern of understanding what you want to build through the process of building. "The way to the mountain is usually never a straight line." Taste and iteration, in his view, are still the constraint.

The floor for taste, for him, is: "If it doesn't stink like AI." The tell is generic purple gradients and authentic-built UIs. Higher up, taste shows in details like delightful roast messages an agent can produce in passing (he cites this UX example from OpenClaw).

The skill he wants to elevate is saying no:

"Even the wildest idea is just a prompt away, and usually this one idea is never the problem, but like this idea, and this idea, and this idea, and this idea, and then how all of that fits together, that's the problem."

On prompt injection, he says frontier models are now reasonably good at detecting hostile content from web and email. The risk has shifted to the small local models (around 20B parameters) people are increasingly running, which lack those defenses. He references Simon Willison -- who he credits with coining the term "prompt injection" -- and Willison's dual-LLM approach as the kind of structural fix the field still needs.

Takeaway

His argument is that AI is collapsing the cost of producing technical artifacts -- vulnerability reports, feature ideas, sandbox plugins -- faster than the systems that consume them can absorb the volume. Maintainers, researchers, and product builders all need new triage. Severity scores, taste, and the willingness to say no are the only filters that scale.

"It's our job to help the agent do its best work by providing them with hints."


Peter Steinberger spoke at AI Engineer Europe 2026. Creator of OpenClaw, recently joined OpenAI.

Watch the full talk | OpenClaw | LinkedIn | X

corey@gallon.me:~$ tail -f /writing Attach to the stream. An email when I have something worth sending. Replies encouraged!
corey@gallon.me:~$ ls -lt /conferences ↑2026-05-13 The Org Chart Is the Orchestrator
▸2026-05-12 Maintaining at the Speed of Slop ⋅ you are here
↓2026-05-11 Is HTML "Strictly Better" Than Markdown for Claude Code?