Intelligent Machines (Audio) IM 863: Fire and Ash - Hot Takes on Tech Trials
29 snips
Mar 26, 2026 Marshall Kirkpatrick, tech journalist and builder of the 'What's Up With That' AI browser extension, demos a tool that flags what is genuinely new in articles. Conversation hops between agent risks and supply-chain malware, models behind the extension and on-device compression, the LA bellwether trial over platform harms, and strategies for safer agent credentials and research augmentation.
AI Snips
Chapters
Books
Transcript
Episode notes
Tool That Flags What's Truly New
- Marshall Kirkpatrick built What's Up With That to show what in an article is genuinely new by mapping the state of the art in real time.
- It scans the web, flags patterns and anomalies, and highlights paragraphs that move the needle for journalists and researchers.
Store Keys In Ephemeral Vaults For Agents
- Use ephemeral tokens and vault-based access for AI agents to prevent accidental leakage of API keys and limit access by policy.
- Keycard Labs and Bitwarden's Agent Access SDK both provide token issuance and revocation plus human-in-the-loop approval to reduce exposure.
Supply Chain Infection Via Transitive Python Packages
- A malicious PyPI package (LightLLM) briefly distributed malware that exfiltrated SSH keys, cloud credentials, ENV variables and more, and was pulled after being live for about an hour.
- Transitive dependencies and automatic installs by agents make supply-chain infection highly scalable and stealthy.





