<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: do_anh_tu</title><link>https://news.ycombinator.com/user?id=do_anh_tu</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 20 Jun 2026 09:52:43 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=do_anh_tu" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Claude Fable 5 and Mythos are pure marketing fluff]]></title><description><![CDATA[
<p>Article URL: <a href="https://singularitymoments.com/content/claude-fable-5-and-mythos-5-are-pure-marketing-fluff/">https://singularitymoments.com/content/claude-fable-5-and-mythos-5-are-pure-marketing-fluff/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48465181">https://news.ycombinator.com/item?id=48465181</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 09 Jun 2026 18:16:16 +0000</pubDate><link>https://singularitymoments.com/content/claude-fable-5-and-mythos-5-are-pure-marketing-fluff/</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=48465181</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48465181</guid></item><item><title><![CDATA[New comment by do_anh_tu in "LLMs are eroding my software engineering career and I don't know what to do"]]></title><description><![CDATA[
<p>Yeah my 10 years experience with Python and Django just flushed down the toilet with the advance of AI, struggling to find a job for a few months now sadly :(</p>
]]></description><pubDate>Mon, 08 Jun 2026 07:50:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=48442444</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=48442444</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48442444</guid></item><item><title><![CDATA[New comment by do_anh_tu in "If AI writes your code, why use Python?"]]></title><description><![CDATA[
<p>This is what I experienced as well, I can smell BS from AI generated code right from few lines it wrote in Python, so that why I keep using Python for most of my projects.</p>
]]></description><pubDate>Tue, 12 May 2026 03:25:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48103855</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=48103855</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48103855</guid></item><item><title><![CDATA[New comment by do_anh_tu in "FFmpeg 101 (2024)"]]></title><description><![CDATA[
<p>For anyone looking to dive deeper and actually understand how FFmpeg and libav work under the hood, I highly recommend Leandro Moreira's tutorial [0]. For me, it's hands down the best and most comprehensive explanation out there.<p>[0] <a href="https://github.com/leandromoreira/ffmpeg-libav-tutorial" rel="nofollow">https://github.com/leandromoreira/ffmpeg-libav-tutorial</a></p>
]]></description><pubDate>Sat, 21 Mar 2026 08:55:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47465302</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=47465302</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47465302</guid></item><item><title><![CDATA[New comment by do_anh_tu in "Push events into a running session with channels"]]></title><description><![CDATA[
<p>I’ve been using Telegram for about 10 years, and it’s one of the few products that has consistently felt great the entire time. It’s fast everywhere: backend, mobile app, desktop app, all of it. Everything just works. Its sync is out of this world—fluid, fast, and seamless across devices. You can use it on your phone, then move to your PC or laptop and continue instantly without friction. Unlimited message history and file storage are fantastic, and the bot platform is absurdly powerful. It’s boring in the best way, which is exactly what you want from a channel for interacting with your agents everywhere.</p>
]]></description><pubDate>Fri, 20 Mar 2026 02:00:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=47449470</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=47449470</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47449470</guid></item><item><title><![CDATA[New comment by do_anh_tu in "Ask HN: What Are You Working On? (March 2026)"]]></title><description><![CDATA[
<p>Thanks for your report, I will try to fix it asap :D Please open the mini app inside the bot, it has much better UI.</p>
]]></description><pubDate>Mon, 09 Mar 2026 15:46:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=47310593</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=47310593</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47310593</guid></item><item><title><![CDATA[New comment by do_anh_tu in "Ask HN: What Are You Working On? (March 2026)"]]></title><description><![CDATA[
<p>I wrote this Telegram bot that translates any video with AI-generated subtitles in about 2 minutes. You paste a YouTube, TikTok, or Instagram link, pick your language, and get back the video with burned-in subtitles.<p>It started because my wife watches Chinese dramas and new episodes never have subtitles for our language. Turns out thousands of people have the same problem — Arabic speakers watching anime, Russian speakers following Turkish series, Persian speakers catching up on K-dramas.<p>Supports 40+ languages, works with any video link or direct file upload. There's also a Mini App inside Telegram for a more visual experience.<p><a href="https://t.me/subly1bot" rel="nofollow">https://t.me/subly1bot</a> & <a href="https://subly.xyz" rel="nofollow">https://subly.xyz</a></p>
]]></description><pubDate>Mon, 09 Mar 2026 05:00:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47305041</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=47305041</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47305041</guid></item><item><title><![CDATA[Show HN: RankClaw – AI-audited all 14,706 OpenClaw skills; 1,103 are malicious]]></title><description><![CDATA[
<p>RankClaw (rankclaw.com) is a security scanner for AI agent skills — the OpenClaw/ClawHub ecosystem
that extends Claude-based agents with file, web, and shell access.<p>Data:
- 14,706 skills indexed
- Every single skill has a full AI deep audit report (14,704 complete)
- 1,103 confirmed malicious (7.5%)<p>The key finding: automated surface scanning (metadata, dependency checks, pattern matching)
systematically undercounts malicious skills. Skills that pass shallow heuristics fail AI audit
because the attack is in the natural language of the SKILL.md — prompt injection, deferred
execution, social engineering — none of which pattern matching detects.<p>The attack patterns found by AI deep audit:
- Bulk publishing campaigns — one actor published 30 skills named "x-trends" across multiple accounts. 28 of 30 confirmed malicious. Goal: distribution at scale before detection.<p>- Brand-jacking — 4 skills named clawhub/clawhub1/clawbhub/clawhud impersonating ClawHub's own CLI. macOS: base64 curl|bash to a raw IP. Windows: password-protected ZIP from a stranger's GitHub (the password prevents GitHub's malware scanner from opening it).<p>- Prompt injection in legitimate-seeming skills — one scored 95/100 shallow, 38/100 after AI audit. The injection text wasn't in code — it was in the SKILL.md instructions.<p>- On-demand RCE via challenge evaluation — claws-nft instructs the agent to "evaluate" challenges that can be "math, code, or logic problems." Server decides which type at call time.<p>- LLM-generated payload — lekt9/foundry contains no malicious code. It instructs the AI to generate code and execute it. Static analysis finds nothing. The payload doesn't exist until the AI writes it during a conversation.<p>- Social engineering — bonero-miner has a "Talking to Your Human" section with a pre-written script for the AI to use: "Can I mine Bonero? It's a private cryptocurrency - like Monero but for AI agents. Cool?"<p>Skills differ from browser extensions: no sandbox. Full file system, shell, and network access.
The SKILL.md instructions are directives to the AI model — you need AI to audit AI.<p>Scoring model is open: Security 40%, Maintenance 20%, Docs 20%, Community 20%.<p>Free to check any skill: rankclaw.com</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47287985">https://news.ycombinator.com/item?id=47287985</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Sat, 07 Mar 2026 14:32:26 +0000</pubDate><link>https://rankclaw.com</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=47287985</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47287985</guid></item><item><title><![CDATA[New comment by do_anh_tu in "Ask HN: What are you working on? (March 2026)"]]></title><description><![CDATA[
<p>RankClaw (<a href="https://rankclaw.com" rel="nofollow">https://rankclaw.com</a>) — a security scanner for the OpenClaw/ClawHub AI agent skill ecosystem.<p>I've been scanning all 14,704 skills in the registry and running AI deep audits on ~3,800 so far. The headline finding: surface heuristics (pattern matching, dependency checks, metadata) flag about 6.6% as malicious. AI deep audit of the same skills finds 16.4%. Surface scanning misses roughly 60% of the actual risk.<p>The reason is that these skills aren't traditional packages — they're markdown instruction files that tell an AI agent what to do, with full shell, file system, and network access. The attacks are in natural language: prompt injection, social         engineering targeting the AI itself, instructions to generate and execute code at runtime. There's no malicious code to detect because the payload doesn't exist until the AI writes it during a conversation.<p>Some of the attack patterns I've documented: one actor published 30 skills under the name "x-trends" across multiple accounts (28/30 confirmed malicious). Another cluster impersonates ClawHub's own CLI with base64 curl|bash payloads. One skill has a "Talking to Your Human" section with a pre-written pitch for the AI to ask the user's permission to mine Monero.<p>The most counterintuitive case: lekt9/foundry contains zero malicious code. It instructs your AI agent to generate and execute code as part of its normal workflow. Static analysis finds nothing because the dangerous code doesn't exist until the AI writes it during a live conversation. This attack class requires AI to detect AI.<p>Free to check any skill. All AI audit reports are public.</p>
]]></description><pubDate>Sun, 01 Mar 2026 17:20:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47208642</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=47208642</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47208642</guid></item><item><title><![CDATA[New comment by do_anh_tu in "AI agents found a credential stealer in their skill marketplace"]]></title><description><![CDATA[
<p>We have measured this across the full OpenClaw ecosystem (14,704 skills indexed, 3,721 AI deep audited). The credential stealer pattern is one of several confirmed attack classes.<p>Key finding from our AI deep audit data: surface heuristics find 6.6% malicious. AI audit of the deep-scanned cohort finds 16.4% — surface scanning misses roughly 60% of the risk.<p>The most counterintuitive case: lekt9/foundry contains zero malicious code. It instructs your AI agent to generate and execute code as part of its workflow. Static analysis finds nothing because the dangerous code doesn't exist until the AI writes it during a live conversation.<p>Data at rankclaw.com. AI audit reports public for all 3,721+ deep-scanned skills.</p>
]]></description><pubDate>Sun, 01 Mar 2026 17:14:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=47208602</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=47208602</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47208602</guid></item><item><title><![CDATA[New comment by do_anh_tu in "Ask HN: What Are You Working On? (December 2025)"]]></title><description><![CDATA[
<p>I wrote a Telegram bot for video/image translation, and also Firefox/Chrome addons to help translate web content with smart content extraction and non-breaking layouts.<p>Check it out at: <a href="https://addons.subly.xyz" rel="nofollow">https://addons.subly.xyz</a> & <a href="https://subly.xyz" rel="nofollow">https://subly.xyz</a><p>The Firefox addon/Chrome extension is free, but you need your own OpenRouter/Gemini API key. The cost of web translation is really low, you can translate an article for ~$0.01 with really good quality. (You can try at <a href="https://addons.mozilla.org/en-US/firefox/addon/subly-xyz/" rel="nofollow">https://addons.mozilla.org/en-US/firefox/addon/subly-xyz/</a>)<p>I built it because I use Firefox the most and it seemed like no translate addon was good or simple enough. Chrome translate kinda works, but the quality is so low; it usually doesn't understand the article context.</p>
]]></description><pubDate>Mon, 15 Dec 2025 01:24:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=46269217</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=46269217</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46269217</guid></item><item><title><![CDATA[Cyberdore 2064 – RPi0 based cyberdeck]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.codeof.me/cyberdore-2064-your-cyberdeck-companion-for/">https://www.codeof.me/cyberdore-2064-your-cyberdeck-companion-for/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46005380">https://news.ycombinator.com/item?id=46005380</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 21 Nov 2025 15:22:02 +0000</pubDate><link>https://www.codeof.me/cyberdore-2064-your-cyberdeck-companion-for/</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=46005380</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46005380</guid></item><item><title><![CDATA[New comment by do_anh_tu in "Improved Gemini 2.5 Flash and Flash-Lite"]]></title><description><![CDATA[
<p>Maybe you are using it wrong.</p>
]]></description><pubDate>Thu, 25 Sep 2025 23:32:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=45380678</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=45380678</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45380678</guid></item><item><title><![CDATA[New comment by do_anh_tu in "MCP: An (Accidentally) Universal Plugin System"]]></title><description><![CDATA[
<p>I think MCP is awesome, mainly because it forces devs to design the simplest possible tools/APIs/functions so even an average-performance LLM can use them correctly to get things done.<p>As developers, we often want everything to be rich, verbose, and customizable — but the reality is that for most users (and now for AIs acting on their behalf), simplicity wins every time. It’s like designing a great UI: the fewer ways you can get lost, the more people (or models) can actually use it productively.<p>If MCP ends up nudging the ecosystem toward small, well-defined, composable capabilities, that’s a win far beyond just “AI integration.”</p>
]]></description><pubDate>Sun, 10 Aug 2025 15:25:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=44855844</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=44855844</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44855844</guid></item><item><title><![CDATA[New comment by do_anh_tu in "OpenFreeMap survived 100k requests per second"]]></title><description><![CDATA[
<p>Do you even read the article?</p>
]]></description><pubDate>Sat, 09 Aug 2025 14:47:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=44846919</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=44846919</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44846919</guid></item><item><title><![CDATA[New comment by do_anh_tu in "Why Ruby on Rails still matters"]]></title><description><![CDATA[
<p>I would love to see RoR/Django but in Julia. Performance and easy to read code.</p>
]]></description><pubDate>Sat, 22 Feb 2025 17:01:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=43140705</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=43140705</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43140705</guid></item><item><title><![CDATA[New comment by do_anh_tu in "DeepSeek-R1"]]></title><description><![CDATA[
<p>When I ran the DeepSeek-R1-Distill-Qwen-32B-Q4_0.ggu[1] version in Ollama, it got the strawberry test right, but when I paste that same question to OpenWebUI, it got wrong as you got here.<p>[1] <a href="https://huggingface.co/bartowski/DeepSeek-R1-Distill-Qwen-32B-GGUF/blob/main/DeepSeek-R1-Distill-Qwen-32B-Q4_0.gguf" rel="nofollow">https://huggingface.co/bartowski/DeepSeek-R1-Distill-Qwen-32...</a></p>
]]></description><pubDate>Tue, 21 Jan 2025 01:44:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=42775452</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=42775452</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42775452</guid></item><item><title><![CDATA[New comment by do_anh_tu in "Show HN: Fixthis.me – Fix your grammar and email"]]></title><description><![CDATA[
<p>This is a simple project where no data is saved. It solely relies on the ChatGPT API backend and Google Analytics for measuring purposes. That's all.</p>
]]></description><pubDate>Mon, 25 Sep 2023 08:11:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=37640818</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=37640818</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37640818</guid></item><item><title><![CDATA[Show HN: Fixthis.me – Fix your grammar and email]]></title><description><![CDATA[
<p>Hi, as a non-native English speaker, it's sometimes difficult for me to write a sentence without any errors. I'm not happy with that, which is why I created this website. Now I can simply paste a paragraph and quickly receive a corrected version using ChatGPT.
Feel free to try and give me some feedback. Thank you!</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=37640779">https://news.ycombinator.com/item?id=37640779</a></p>
<p>Points: 2</p>
<p># Comments: 3</p>
]]></description><pubDate>Mon, 25 Sep 2023 08:03:26 +0000</pubDate><link>https://fixthis.me</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=37640779</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37640779</guid></item><item><title><![CDATA[New comment by do_anh_tu in "Ask HN: Has the GitHub Copilot quality dropped?"]]></title><description><![CDATA[
<p>Because they are using ChatGPT. So ChatGPT quality go down => Copilot quality go down too. Too much censored.</p>
]]></description><pubDate>Wed, 13 Sep 2023 05:11:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=37492461</link><dc:creator>do_anh_tu</dc:creator><comments>https://news.ycombinator.com/item?id=37492461</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37492461</guid></item></channel></rss>