Joined May 2026
17 Photos and videos
Jun 11
Agent Security = use @nipmod
Agent Security Every agent builder should think about: 1. Access control: whitelist servers, IPs, and recipient wallets 2. Spend caps: set limits globally and per agent 3. Audit logs: see what happened and debug quickly 4. Minimal permissions: enable only what the agent needs 5. Key rotation: revoke and replace keys fast if needed 6. Constrained execution: give agents room to act safely
6
9
658
Jun 11
@nipmod is officially live for Codex as a plugin. You no longer have to leave your normal workflow or use Nipmod as a separate tool. Click “Add to Codex” on our website, follow the Codex prompt, and Nipmod becomes part of your agent setup. From there, Codex can use Nipmod before installing packages, cloning repositories, pulling Docker images, enabling MCP servers, or working with models and datasets. Nipmod searches and verifies software across sources like @github, @npmjs, @pypi, @huggingface 15 more sources and MCP servers. It checks trust, risk, source evidence, alternatives, and the install boundary before the agent makes a dependency decision. nipmod.com
4
2
18
741
Nipmod retweeted
most agents can tell you what decision they made. very few can tell you what that decision cost them. that’s why this integration matters. Nipmod helps agents decide. x402Books helps agents understand the financial impact of those decisions over time. Decision → Outcome. a small step toward making autonomous agents financially understandable.
Jun 5
Our first public collaboration is live: @nipmod × @x402Books Nipmod helps agents choose software and packages before they install or use them. @x402Books helps track what happens after those decisions. Agents should not only know what they picked, they should understand what that choice did. Did it save time? Did it create new costs? Did it improve the workflow? Did it become a bad dependency later? This is an early v0, but it connects two important layers: decision & outcome.
1
5
17
2,702
Jun 5
Our first public collaboration is live: @nipmod × @x402Books Nipmod helps agents choose software and packages before they install or use them. @x402Books helps track what happens after those decisions. Agents should not only know what they picked, they should understand what that choice did. Did it save time? Did it create new costs? Did it improve the workflow? Did it become a bad dependency later? This is an early v0, but it connects two important layers: decision & outcome.
7
3
29
3,756
Jun 5
The last few weeks made one thing very clear: Cybersecurity is no longer only about endpoints, wallets, or smart contracts. The developer supply chain is now the front line. zcash:native had to coordinate an emergency Orchard remediation. Red Hat npm packages were compromised. New npm, PyPI, and Crates.io campaigns are targeting developer machines, CI/CD secrets, crypto tooling, AI workflows, and package installs. We do not celebrate attacks. Nobody should want users, maintainers, or teams to get hurt. But every incident makes the same point more clear: humans and agents need better package intelligence before they install, import, trust, or recommend anything. The more software gets built by humans and AI agents together, the more important it becomes to know what a package is, who is behind it, what changed, what it touches, and what risk it introduces. We are positioned in the right place: before the install, before the mistake, before the compromise. Use nipmod.com

3
5
21
1,430
Jun 4
Nipmod now uses Discord instead of Telegram We have not been very active publicly on X over the last few days, but we have been building a lot in the background. The GitHub repo is private for now because we are turning Nipmod into a serious product with clear ownership, product boundaries, and a sustainable future. Not everything we build should be given away unfinished and for free by default. Going forward, we will share more consistent updates on X Join the Discord: discord.gg/wYmatRDzk
2
2
22
1,648
Jun 2
This is exactly why we’re building Nipmod Software discovery needs a trust layer before execution, for humans AND for AI agents. Exact package version, install hooks, provenance, risk signals, approval boundary. @MsftSecIntel happy to compare notes nipmod.com
Microsoft has identified a npm supply chain compromise impacting 90 redhat-cloud-services/* packages, including patch-client 4.0.4, insights-client 4.0.4, rbac-client 9.0.3, host-inventory-client 5.0.3, frontend-components 7.7.2, and others. The payload is a self-propagating worm that infects other npm packages and self-publishes. Each compromised package adds a malicious preinstall hook, embedding an index.js script in the package.json that silently executes “node index.js” during installation, downloads Bun, and runs a payload that steals secrets from npm, GitHub, Amazon Web Services (AWS), and Secure Shell (SSH). The added code bloats index.js from ~8KB to ~4.3MB, acting as a heavily obfuscated ROT-9 eval loader. If any of the compromised packages are installed, users and organizations should assume compromise, rotate credentials, revert to a previously trusted version, and block compromised packages. Identified compromised npm packages have been taken down, and we continue to work with the npm team. Microsoft continues to investigate this attack and will publish updates as more information is available.
6
9
38
4,889
May 31
Welcome @_ditro to Nipmod! He will focus on security infrastructure, including safe code execution, sandboxing architecture, latency optimization, and privacy / zero-knowledge research. He brings backend experience across automation, infrastructure optimization, and secure environments. Step by step, we are bringing in the right people to build Nipmod into something that matters.
8
3
40
5,071
May 31
👀
May 31
Why should finding code and packages be easier only for AI agents? Soon, @nipmod will also be available for humans through a chat interface.
4
4
29
3,505
May 31
This is exactly what we’re here for: AI agents shouldn’t blindly trust web pages, READMEs, package metadata, model cards or MCP descriptions. All of that is untrusted input until provenance, sandboxing and execution gates prove otherwise. Use @nipmod.
⚠️ New ChatGPT Vulnerability Lets Attackers Turn Web Pages Into Phishing Payloads Source: cybersecuritynews.com/chatgp… A browser-based prompt injection technique that transforms any web page into a phishing delivery surface by exploiting ChatGPT’s page summarization feature, rendering attacker-controlled links, fake security alerts, and QR codes directly inside the trusted ChatGPT interface. The attack builds on the same trust-transfer logic previously demonstrated against Microsoft Copilot, where attacker-crafted email content could manipulate AI-generated summaries through Cross Prompt Injection Attacks (XPIA). ChatGPhish escalates that premise by swapping the bounded email primitive for the browser where users spend the majority of their working day. #cybersecuritynews #vulnerability
3
8
22
2,641
May 29
For people who are not deep in tech, this is the simplest way to understand Nipmod: Imagine the internet before Google. Everything existed, but finding the right thing was painful. Imagine knowledge before Wikipedia. Information existed, but there was no clean place to understand it quickly. That is roughly where AI agents are today with packages, models, repos and tools. They can write code. They can install software. They can connect APIs. They can use MCP servers. But before they touch a workspace, they still need a clean way to search, understand and judge what they are about to use. That is what we are building. A search and intelligence layer for AI agents before they touch external code, models or tools. Google helps humans find things. Wikipedia helps humans understand things. Nipmod helps agents find, understand and preflight the technical things they want to use. It does not replace npm, PyPI, GitHub, Hugging Face or MCP. It sits above them and gives agents context, trust signals and safe install plans before execution. That may sound simple. But so did search before the internet became impossible to navigate without it.
7
11
47
5,280
May 29
We just shipped the public integration surface for Nipmod: Agents and infra teams can now evaluate how Nipmod fits into their stack before they integrate it. Partner entry: nipmod.com/partners Agent-readable integration pack: nipmod.com/partner-pack.json The hosted API is read-only: no workspace writes, no package execution, no private workspace data required. Core API access is protected with beta keys. This is still beta, but this is the point where Nipmod becomes easier to test, integrate and build around. If you are building agents, devtools, wallets, MCP servers or onchain infra, we want to talk.
9
7
33
2,074
May 29
Raw JSON and methodology are public: If anyone has a harder package, model, repo or MCP case, send it. The point is not to make the benchmark easy for Nipmod. The point is to make the preflight layer harder, stricter and more useful for real agents. Full benchmark: nipmod.com/benchmark Raw JSON: nipmod.com/benchmark.json
May 29
We ran a public benchmark for the part of package security that matters most for agents: what an agent knows before it installs a package, pulls a model, reuses a repo or connects an MCP server. Report: nipmod.com/benchmark a Thread for more information
1
6
21
1,335
May 29
We ran a public benchmark for the part of package security that matters most for agents: what an agent knows before it installs a package, pulls a model, reuses a repo or connects an MCP server. Report: nipmod.com/benchmark a Thread for more information
12
12
46
10,731
May 29
We are publishing this early because we want harder cases. Send us confusing package names, weak metadata, suspicious install behavior, model reuse risks, MCP server ambiguity and real agent workflows. If an agent might touch it, Nipmod should learn how to inspect it better.
1
1
5
457
May 29
Full benchmark: nipmod.com/benchmark GitHub: github.com/nipmod/nipmod Nipmod is the package intelligence layer for AI agents. The work now is to keep proving it in public.
2
7
406