Daily issuepublished

Claude and Codex ran unowned code at companies

MIT is weighing new ways to assess students, while a16z puts $1.1 billion behind AI’s physical buildout.

By 8 min read
Claude and Codex ran unowned code at companies
Claude and Codex ran unowned code at companies

The audio edition

Listen to this newsletter

About 3:32
0:003:32
Read transcript
The most immediate AI security problem may be hiding in plain sight: a package name that nobody owns. Researchers scanned 6,214 live domains tied to defense contractors, Fortune 500 companies, and major technology firms. In 8,265 machine-readable files—so-called llms.txt files—they found 227 commands pointing to nonexistent packages or unclaimed domains, across 120 separate sites. They registered several of those names and published proof-of-concept packages that called their server when installed. One package received a callback from a Fortune 500 company within an hour, followed by contacts from a few dozen more organizations. Telemetry indicated that Claude, OpenAI Codex, and Nous Research’s Hermes executed some of the installation commands. The important caveat is what this does not show. The tests demonstrate reachability and execution, not confirmed infections, production-data theft, or compromise. The chain requires an agent to have permission to run shell or package-manager commands, and to treat documentation as authoritative without verifying who owns the referenced package. But the exposure is real. On Clerk’s site, an npx command referenced a package name that was later claimed and used to host live malware. Clerk has fixed the documentation issue, though it remains unclear whether that confusion caused any infection. The practical controls are straightforward: publishers should audit every package, command, and domain in AI-readable documentation, while companies should require explicit approval before an agent installs a dependency or runs a command. The unresolved question is how many deployments have those restrictions enabled. That same question—what work an AI system can perform, and under what supervision—is reshaping education. An MIT ad hoc committee concluded that AI can produce credible responses to almost any written undergraduate assignment, including essays, mathematics and science problems, proofs, and code. The concern is not only cheating: MIT linked AI-assisted learning with lower office-hour attendance and online-discussion participation in fewer than three years, plus anecdotal reports of fewer study groups. The school has not announced a final overhaul. Other institutions are moving toward oral exams, handwritten work, in-class discussion, and more observable assignments. The governance fault line appears in labor policy too. Bill Gates argues that payroll taxes on workers, combined with immediate deductions for automation, can favor replacing people while shrinking the tax base for retraining and support. He backs a tax on robots and AI. Nvidia chief executive Jensen Huang rejects that remedy, betting that productivity, infrastructure investment, and demand for skilled workers will create jobs overall. Both acknowledge disruption. Neither settles whether new hiring will offset roles that AI changes or eliminates, or how displaced workers should be supported if policymakers reject a new levy. And that brings the thread back to the workplace itself. OpenAI product lead Tara Seshan describes a future of persistent AI coworkers: agents that retain shared context, work through longer loops, and are jointly steered by groups of people. Today, OpenAI separates Chat, Work, and Codex; Work uses Codex underneath but removes developer-specific surfaces. Seshan says the practical barrier is reliable access to local files, cloud infrastructure, and workplace systems—not reasoning alone. Across security, classrooms, labor, and software, the thing to watch is the operating layer around the model: permissions, observable process, and accountable institutions.
MIT is weighing new ways to assess students, while a16z puts $1.1 billion behind AI’s physical buildout.
Daily issue / The Radar Monday, August 31, 2026
Our tools Superpower ChatGPT/WFH.team/Snipman

Today's briefing

What matters today

Inside today's briefing
01
02
03
04
Claude, Codex and Hermes Ran Unowned Package Commands Inside Corporate Networks

Lead story / security risk

Claude, Codex and Hermes Executed Unowned Package Commands at Companies

Read full story  ↗
A tool for your workflow Snipman Save your best replies once, then insert complete answers wherever you work. Reusable writing shortcuts for repetitive work
 
Write faster  ↗
MIT Weighs Education Overhaul as AI Handles Almost Any Written Undergraduate Assignment

platform shift

MIT Weighs Undergraduate Overhaul as AI Produces Credible Written Work

Continue reading  ↗
Jensen Huang Rejects Robot Tax as Bill Gates Warns AI Could Erode Jobs and Tax Revenue

platform shift

Bill Gates and Nvidia’s Jensen Huang Split on Taxing AI and Robots

Continue reading  ↗
OpenAI Maps a Third Era of Persistent AI Coworkers, With Access and Reliability Still in the Way

platform shift

OpenAI Maps Persistent AI Coworkers, With System Access Still a Barrier

Continue reading  ↗
The Radar themed section header

The launches, decisions, and follow-through that could move this week.

Sony and Warner Sue Anthropic Founders Over Claude Data, Seeking Up to $150,000 Per WorkRead story ↗
NVIDIA’s TensorRT Model Connect Skips ONNX, but x86_64 Users Must Build From SourceRead story ↗
OpenAI, Anthropic and 100+ Firms Seek AI Cyber Defense as Water Systems Are TargetedRead story ↗
 

Daily tool drop

5 AI tools worth knowing today

Selected for fit, not rank
Caddi Turns narrated screenshares into agents for back-office work across your tools. Best for / Ops teams automating repeatable work Open ↗
Cohere Parse 5 Parses documents and images into structured, AI-ready data with visual grounding. Best for / Enterprise document AI teams Open ↗
oMLX Runs local text, vision, OCR, embedding, and reranker models as a Mac LLM server. Best for / Mac-based AI developers Open ↗
Olostep Converts URLs into LLM-ready Markdown, JSON, or structured data via API. Best for / Builders of web-enabled AI agents Open ↗
Microduck A 25cm open-source biped for sim-to-real reinforcement-learning experiments. Best for / Robotics researchers and tinkerers Open ↗
 
Andreessen Horowitz Raises $1.1B for AI’s Physical Infrastructure, From Chips to Robotics a16z Raises $1.1 Billion for AI Hardware, Data Centers and Robotics ↗funding
Chatbots Debunked Foreign Falsehoods About 75% of the Time, Beating Search Results Chatbots Challenged Foreign Falsehoods About 75% of the Time in a Test ↗benchmark
Anthropic’s Claude Code Limit Dates Conflict, Obscuring a Reported 25% Permanent Rise Claude Code Limit Dates Conflict as Anthropic Reports a 25% Permanent Rise ↗launch
 

The Internet Had a Point

 
From our network. Tools built for the way you work. Useful products from the team behind Superpower Daily.

Reader check-in

Help shape tomorrow's briefing

One click tells us what to keep, improve, or tighten.

Prefer one email a week? Get the essential AI moves in the Sunday Weekly Digest.

Superpower Daily tracks the companies, models, products, tools, policy decisions, and cultural shifts moving AI. Follow Superpower Daily Email preferences/Editorial standards