In partnership with

OpenHands crossed a real milestone this week, but the number isn't the story. What's interesting is what showed up right next to it: a security-audit skill built specifically to not trust the agent that's running it. Cloudflare's new skill runs multi-phase checks and hands back machine-readable findings that are independently verified, not just self-reported. That's the actual shift. We stopped asking agents to grade their own homework and started building the grader as a separate, adversarial step. If you're running any coding agent unattended, this is the piece you're missing.

The AIgent stays free for everyone, and reader support is what keeps it that way. Support The AIgent so we can keep delivering it to you. Your support funds the newsletter and the people and technology that make it.

Sponsored

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads

Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:

After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.

The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.

“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”

Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.

The Drops

The Drops

RepoOpenHands

88,165 stars · OpenHands/OpenHands

An open-source software development agent that sandboxes execution, browses the web, and edits code without a human driving every keystroke.

Here is the real problem it solves. Most coding agents either need constant babysitting or run wide open with no containment. OpenHands sandboxes the whole loop, so a bad command doesn't touch your real filesystem.

Quick start: clone it, point it at a task in the sandboxed runtime, and watch the trajectory log before you trust it with anything that touches production.

Catch: sandboxing costs you speed. Expect noticeably slower iteration than a raw API loop, and budget for that tradeoff up front.

Open the repo

AffiliateGamma

The same instinct that turns a messy audit finding into a clean, gradeable report is what turns a rough outline into something you can actually put in front of a client today. Gamma, describe a topic and it builds a designed presentation, document, or website in under a minute, no slide-wrangling. For builders who need to pitch an agent, brief a client, or ship a launch page fast, it turns a rough outline into something shippable.

Use it for: turning a rough outline into a pitch deck or launch page in under a minute.

See how Gamma works

We may earn a commission.

Skillsecurity-audit-skill

6,704 stars · cloudflare/security-audit-skill

A coding-agent skill that runs a multi-phase security audit and returns independently verified, machine-readable findings.

Use it for: bolting an adversarial check onto any agent that writes or merges code, so the agent isn't the one grading its own patch.

Catch: it's a skill, not a firewall. It catches what it's built to check for, nothing more.

Repocrawl4ai

83,684 stars · unclecode/crawl4ai

An open-source web crawler and scraper built to hand LLMs clean, structured page content instead of raw HTML soup.

Use it for: feeding a research agent real, current web data without writing your own scraper from scratch.

Catch: sites change their markup constantly. Expect to babysit selectors on anything that matters.

Repovoicebox

54,265 stars · jamiepine/voicebox

An open-source AI voice studio for cloning a voice, dictating text, and generating speech from it.

Use it for: narrating a demo or a launch video in your own voice without booking studio time.

Catch: voice cloning tools carry consent and disclosure obligations most operators skip. Don't.

From Our Partners

The best in influencer marketing. And you’re invited. Return on Influence Festival ‘26 is a free, virtual conference with speakers running some of the best programs in the world. Save your spot

Start Here

Start Here

Read and draft email with AI, safely, in five minutes.

Here's what you'll walk away able to do: get a first draft of any reply written for you, without ever pasting your actual inbox into a tool that keeps it.
1. Open ChatGPT, Claude, or whatever assistant you already have a login for.
2. Copy the email you're replying to, but strip out names, account numbers, and anything you wouldn't want stored somewhere you don't control.
3. Paste the stripped version in and say what you want the reply to do: confirm, decline, ask for more time, whatever it is.
4. Read the draft it gives you out loud before you send anything. If a sentence sounds like nobody you know, rewrite that line yourself.
5. Never let it auto-send. You are always the last set of eyes.

TRY THIS: pull up one email sitting in your inbox right now, strip the personal details, and ask your assistant for a two-sentence reply. Read it out loud before you decide if it's good.

Recommended

Once you've got a rhythm for handing your assistant a stripped-down draft and a clear ask, the next unlock is knowing exactly what to ask for across the rest of your day, not just your inbox.

HubSpot's 100+ ChatGPT Prompts guide is a free download of working prompts for writing, research, and daily tasks, organized so you can lift what you need and go.

Grab the free prompts guide →

We may earn a commission.

Frontier Signals

Frontier Signals

Claude Cowork and Claude chat just merged into one product. If you've been running separate workflows for each, expect menus and defaults to shift; check anything you automated against the old split. (Simon Willison)

CIOs are building guardrails around agents that are already misbehaving in production. The fix under discussion isn't smarter agents, it's shutting off unnecessary access before an agent ever gets the chance to misuse it. (Fortune)

Salesforce is betting its UI stops mattering and agents become the interface instead. If your workflow assumes a human clicking through a dashboard, start planning for an agent calling the API directly. (Stratechery)

Vercel is trimming how many deployments free Hobby projects retain. If you're running side projects or client demos on the free tier, check your deployment history before the storage cap catches you mid-launch. (Vercel Blog)

Apple is reportedly getting back into building servers, possibly paired with Nvidia. If that lands, expect a new hardware option in the AI infrastructure market that isn't a hyperscaler cloud bill. (The Verge)

Recommended reading

If you like The AIgent, a small group of operator-tier publications worth your inbox: see the shortlist.

Before You Go

Reply and tell me which one you're actually cloning this week: the security skill or the voice studio. I read every reply, and the ones that say "here's what broke" shape what I go looking for next.

See you Friday.

Before you go: we started a room for people actually building with agents. Tell us what you want us to build next. Join the community →

Want to reach builders shipping with AI every weekday? Advertise in The AIgent.