You're reading the brief from Sun, Oct 4.Back to the latest brief
Sun, Oct 43 items
0 of 3 readToday's open-source and developer news centers on security and AI-agent tooling: Archestra's open-source OpenAPPA engine reports zero attack success across two benchmarks, an AWS team open-sources the Pizza Bot inbox for background AI agents, and Google ships AndroidX libraries for component-level security patch verification.
Archestra open-sources OpenAPPA with 0% attack success on two benchmarks
Archestra released OpenAPPA, an open-source security engine to stop data exfiltration from prompt injection or model hallucination. It reports zero successful attacks on Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench, versus 10% for Claude Code's auto mode and 31% for Microsoft FIDES.
Why it mattersIf reproducible, it raises the bar for agent security benchmarks and gives teams a direct attack-success metric to compare options.
AWS team open-sources Pizza Bot, an inbox for background AI agents
Developers at AWS open-sourced Pizza Bot, a self-hosted app that lets AI agents run tasks in the background and return results via an inbox-style interface. Agents can do scheduled or webhook-triggered work, delegate to specialized workers, and pause for human approval.
Why it mattersSelf-hosting plus human-approval checkpoints offers a ready reference for controllable, auditable background agent tasks.
Google's AndroidX Security State libraries enable component-level patch checks
Google's AndroidX Security State libraries let apps verify security patch status at the individual component level instead of relying on a single device-wide patch date.
Why it mattersFiner-grained patch visibility lets apps assess risk per component rather than by a single device-wide date.