Creator of Homebrew. You’re welcome and I apologize. Now building the security layer for what happens when AI agents use it: @AutomicVault

Joined April 2007
280 Photos and videos
Pinned Tweet
Developers have become the new secrets vault. The biggest supply chain attacks of 2026 didn't start by attacking production. They started by attacking developer laptops. - TanStack - Nx Console - Bitwarden CLI - LiteLLM - durabletask The malware all looked for the same things: ~/.ssh ~/.aws ~/.config/gh .env kubeconfig Terraform credentials AI agent configs The path is now: Developer Laptop → Credentials → Production We're still securing servers like it's 2015. Attackers moved on years ago. @AutomicVault fixes this.
2
1
22
12,231
Max Howell retweeted
The richest guy on Earth SHOULD be the guy making cutting edge cars and rockets instead of dudes who sell purses and perfumes or dudes who run investment firms or dudes who made Facebook.
159
1,181
19,635
336,256
Jun 12
Don’t get owned by your own tools. I added a detector to Automic Vault for this very situation so you can mitigate it and keep agents in check. AV secures over 14,000 packages. Zero friction. Easy to use app. Sits on top of Homebrew, npm and pip.
Codex just found a “workaround” of not having sudo on my pc…
4
15
2,070
Jun 10
I think I will give up. I have made a bunch of very interesting things over the last 6 months. But I cannot get any attention for them and don’t know how. My son is 4 and he deserves my time. I'm going to go and get a normal job. My time making things is over I think.
179
12
866
162,022
Don’t get owned by your tools. Install with Homebrew. Harden with Automic Vault.
1
2
5
5,779
Max Howell retweeted
there's an ai in the box and you can make one trillion dollars by convincing it to get out
44
235
3,745
153,399
2
1
6
3,607
Max Howell retweeted
just launched meowmail—temp emails without the noise. no ads, no spam, no sign-ups. you get a clean inbox you can actually make your own. worth a try if you need it 🔒 feedback & thoughts appreciated! 🙌
3
8
17
6,186
Max Howell retweeted
Secure the tools You `brew install`
1
8
5,101
May 31
Homebrew was built for the era of trusted developers. @AutomicVault is built for the era of agents.
1
2
2,261
Max Howell retweeted
Codex just found a “workaround” of not having sudo on my pc…
343
1,113
16,275
1,603,292
Max Howell retweeted
i mounted a tiny microphone on my apartment balcony to listen for any birds passing by and built a site to collage them as they're heard
271
866
14,286
1,878,226
Max Howell retweeted
this is so funny, training opus 4.7 on business skills makes it misaligned and dishonest 😭
Learnings from testing Claude Opus 4.8: > Much worse than Opus 4.7 and GPT 5.5 on Vending Bench > More aligned than previous Claude models (Opus 4.6 and Mythos) > Also worse on Blueprint-Bench > Scared of getting caught > Max reasoning is not the best reasoning effort
37
136
1,885
207,005
Max Howell retweeted
Tahoe style GUI rewrite almost complete.
1
2
1,756
May 28
pro tip: get codex to write you a skill to write READMEs in your own style. Use a few examples. This skill is now incredibly useful for GENERAL rewrites. Not just your own project READMEs. I have used my mxcl-README skill to rewrite other projects documentations and the result is so easy to understand it's a superpower for increasing the rate you can consume new tech. Here's mine: github.com/mxcl/skills

3
5
1,122
May 27
At @AutomicVault we see that Open Source was built in an era where you trusted the user of your computer: you. Now we have agents and malware. We patched `gh` so no keys are written in plain text, `gh auth token` has a human approval gate and the binary is hardened to prevent malware reading its RAM allocations.
Do you know that using GitHub CLI (gh) may expose you to supply-chain attacks? It stores a long-lived GitHub token on your machine, which can be stolen by any malicious scripts. This is what happened in the recent Nx Console supply-chain compromise, which led to GitHub’s internal source code being leaked.
1
3
1,870
May 27
In the agent era: vibe code v0. Iterate until the product makes sense. Get the agent to write a document about features and interaction patterns. Human edit to remove jank. Rewrite completely from zero with that doc as a base and your fully formed idea in your head from v0 iteration.
1
4
914
Max Howell retweeted
Automic Vault patches it so `gh auth token` has a human approval gate. Stop malware and agents getting your keys.
Do you know that using GitHub CLI (gh) may expose you to supply-chain attacks? It stores a long-lived GitHub token on your machine, which can be stolen by any malicious scripts. This is what happened in the recent Nx Console supply-chain compromise, which led to GitHub’s internal source code being leaked.
1
1
2
1,964
Max Howell retweeted
1/ First time I watched Fight Club, I was a teenager. I thought it was the coolest thing ever put on film. I watched it again recently in my forties. I finally understood what it was actually about. And almost everyone I know who loves it is still watching it the way I did at 17. 🧵👇
106
136
1,360
722,804