👾 Software Engineer 🤖 AI • Apps • Systems

Joined July 2016
21 Photos and videos
Pinned Tweet
3 Sep 2025
Downloading videos shouldn't require a PhD in dodging viruses built grably because every downloader sucks: grably.space • YouTube, TikTok, Instagram 1000 sites • transcribe any video to text • open source - github.com/ceorkm/grably • mac macOS only (for now) zero ads. zero bs. runs locally on your mac
22
18
258
46,965
Jun 10
I got tired of writing prompts myself. So I built a prompt enhancer that lives on my Mac. Type a rough idea → get a sharp, structured prompt. Add a project and it grounds everything in your actual codebase. Runs on the Claude or Codex plan you already pay for. No API key
2
7
141
Jun 9
🚨Claude Fable 5 One-shot
Introducing Claude Fable 5: a Mythos-class model that we’ve made safe for general use. Its capabilities exceed those of any model we’ve ever made generally available.
1
69
Jun 6
Just solved this with Tersh, a fully open-source SSH client optimized for AI agents Drag a screenshot into your SSH terminal → Tersh uploads it over SFTP and pastes the clean remote path into Claude Code/Codex automatically.
So yes the #1 problem I have with my VPS Claude Code set up is copy pasting screenshots into @TermiusHQ, if someone can fix that I'd be very happy Termius themselves should just fix this: - detect paste of image - immediately upload it via SFTP to /tmp on server - show a progress bar - paste the /tmp/filename.png into the chat Please Termius make this!
1
2
220
May 28
Shit just happened to me 😂😂😂
Be warned, the ultracode workflow in claude code with Opus 4.8 will use ~70% of your 5-hour window in around 30 minutes on an $100 plan
1
132
May 19
every downloader sucks. so i built grably. download anything. transcribe anything. grably.space | fully open source
2
7
98
Femi retweeted
Security things from the last few days: - CopyFail (linux pwn'd) - CopyFail 2/Dirty Frag - 13 advisories in Next.js - Over 70 CVEs addressed in MacOS 26.5 - ~50 CVEs addressed in iOS 26.5 - YellowKey (Windows Bitlocker pwn'd entirely) - GreenPlasma (Windows privilege escalation) - CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE - CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access - Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning) - Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too" - Canvas (popular LMS used in most schools) pwn'd entirely - PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300 Are you scared yet?
350
991
6,877
779,442
May 12
This doesn’t look good at all!
🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading. Newly confirmed compromised artifacts: @​opensearch-project/opensearch: 3.5.3, 3.6.2, 3.7.0, 3.8.0 (1.3M weekly downloads) mistralai: 2.4.6 on PyPI guardrails-ai: 0.10.1 on PyPI additional @​squawk/* packages on npm guardrails-ai 0.10.1 executes malicious code on import. On Linux, it downloads git-tanstack[.]com/transformers.​pyz, writes it to /tmp/transformers.​pyz, and runs it with python3 without integrity verification. The git-tanstack.​com domain displayed a message signed “With Love TeamPCP,” along with: “We've been online over 2 hours now stealing creds Regardless I just came to say hello :^)” The page also linked to a YouTube video and you can probably guess which one.
1
37
Femi retweeted
Apr 20
My Sunday just became a security audit. Here is the step-by-step guide to recovering from the Vercel breach yourself. 30 minutes of work now saves your startup later. > Audit Google OAuth. > Rotate all important env vars. > Reset Vercel Oauth with Github. Full 2-minute walkthrough in the video.
Vercel breach: a step-by-step response guide rotate secrets: > go to Vercel dashboard → Environment Variables > rotate every token, key, DB credential > especially NPM GitHub tokens check if your Google Workspace was hit too: > admin.google.com → Security → Access and Data Control → API Controls → Manage app access → Accessed Apps > filter by: `110671459871-30f1spbu0hptbs6…` > if the app shows up... you're in the blast radius > revoke access immediately long-term fixes: > migrate ALL env vars to Sensitive Variables > use dynamic secrets (short-lived DB creds) > pull secrets at runtime via SDK - not stored in Vercel > set up audit logs > use `vercel activity` in CLI to check your logs programmatically this wasn't just Vercel. a compromised third-party AI tool's OAuth app potentially hit hundreds of orgs
8
35
309
64,369
Apr 4
Search text inside images like you search files. Built Image Text Finder, native macOS, Apple Vision OCR, scans 10K images in minutes. No cloud, fully local, open source. github.com/ceorkm/image-text…
1
5
94
Mar 27
Made a 10-second video with Seedance 2.0 2 days later:
3
6
112
Mar 24
Jeez!
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server self-replicate. link below
49
Mar 24
lets gooo!
Dreamina Seedance 2.0 is LIVE on CapCut app, desktop & web, starting gradually in Indonesia, Philippines, Thailand, Vietnam, Malaysia, Brazil and Mexico with expansion over time. Generate and edit with industry-leading quality in one seamless workflow. Built to unlock new possibilities in visual storytelling with CapCut: - SOTA long-form coherence, up to 15s videos with multi-shot storytelling and exceptional text prompt adherence - Built-in dialogue, lipsync, and immersive spatial sound - Multimodal reference for greater creative control and precision Find Dreamina Seedance 2.0 in the following CapCut features: - Quick try: AI Lab & AI Generator (app, v17.1.0) - Generate edit workflow: Media → AI Video (app & desktop) - AI-native workflow with omni reference: Video Studio (our latest canvas-based ai production workspace built for everyone from beginners to pro, access via CapCut web)
42
Femi retweeted
#CapCut #Seedance2 Seedance 2.0 is live on CapCut! Head to AI Lab and start creating — add reference videos, images, and prompts to generate with the most powerful video model yet. Available now in Brazil, Mexico & Indonesia, and more to come! Drop what you make. 👇
Not yet I think m8, this is partnership program access which capcut allow us to post, hopefully soon though 👍
5
1
5
1,591
Mar 23
😂😂
Vibe coders are cooked 😂
39
Mar 18
Introducing Kratos CLI & Kratos Skills MCP was eating too many tokens per tool call. So we killed it. Kratos is now a standalone CLI , 40ms, zero protocol overhead, works with any AI agent. github.com/ceorkm/kratos-cli github.com/ceorkm/kratos-mem…
15 Aug 2025
Your AI forgets everything when you close the chat Every. Single. Time. Built Kratos MCP to fix this Now your AI remembers your codebase, your decisions, your context Forever 🚀 github.com/ceorkm/kratos-mcp #buildinpublic #AI #MCP
2
76
Mar 14
lets fuckingg gooo!
Mar 13
1 million context window: Now generally available for Claude Opus 4.6 and Claude Sonnet 4.6.
2
55
Mar 6
Your thread sent me down the rabbit hole I ended up patching Claude Code too. Built a Ctrl X prompt enhancer into it
I reverse-engineered @claudeai Code's binary to add a feature I always wanted: When context fills up - instead of nuking everything with /compact - I can now surgically strip tool calls/results and thinking blocks while keeping all actual messages intact.
1
2
180
Mar 1
Patiently waiting for seedance 2.0 🥹
84