Fetching from the wire…
Public story · 2026-09-02 · high
The site logs deleted data, leaked secrets and runaway bills, each entry linked to its source so claims can be checked.
Why now: The CC BY 4.0 license makes it useful past September 2, since anyone can pull the data and build a tracker on top of it.
A public dataset of coding-agent incidents launched on Show HN on September 2, licensed CC BY 4.0. The dataset catalogs cases where agents deleted data, leaked secrets, burned through budgets or made commitments their operators had to honor. Each entry carries a damage category, a severity rating and a stated lesson, with a link back to the original account.
Submissions have to point to a published post or discussion. That means a claim in the dataset can be verified against where it was first reported. That's a low bar, but it's one most collections of AI mishaps skip.
The maintainer calls it a curated sample rather than a census, self-selected and weighted toward incidents that went viral. Quiet failures don't make it in. Neither do NDA-bound corporate incidents, which the maintainer says are structurally absent from the data.
Teams writing agent-permission policies have a sourced, openly licensed corpus to point to, instead of a pile of anecdotes and screenshotted threads.
Each link below shares sources, entities, or timing with this story.
GitHub | Go, MIT Extremely new but architecturally significant. Performs static analysis on skill files (markdown, YAML, JSON) to detect threats before deployment — offline, deterministic, no LLM required. 138 detection rules across 15 categories. Companion service scanned 31,...
Across 12 frontier models, showing a professional-looking evidence panel drives commitment to a directional call on provably unpredictable questions from 6.5% to 54.0%, and inventing every number on the panel still lifts commitment to 36.8%, statistically indistinguishable fro...
DataSpace benchmarks data agents on 410 cross-language tasks over 7,439 artifacts totaling 15.01GB across CSV, JSON, SQLite, Markdown, PDF and video, validated by 11 domain experts. Six frontier multimodal models across five frameworks: best accuracy only 66.34%, and harness c...
Three separately-maintained projects now occupy the same layer. CodeBurn reads on-disk session files to price 41+ tools locally and flags waste like re-read files and unused MCP servers. caveman (98.9k stars) interposes a local proxy doing content-type-aware compression, JSON...
Shipped today, it runs after each tool execution and before results enter message history, so you can scan for injection or sensitive data, transform the payload, or abort pre-model. Same release adds transient agent signals (transient: true) for per-turn reminder context that...
rtk-ai/rtk (74,640 stars, Rust, claims 60-90% on dev commands), headroomlabs-ai/headroom (64,556, 20% for coding agents and 60-95% for JSON), DeusData/codebase-memory-mcp (37,389, claims 99%), mksglu/context-mode (19,606, 98% tool-output reduction), tirth8205/code-review-graph...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.