KHKevin Hwanginkevinhwang.dev·Sep 2 · 7 min readClassifying Malicious Repositories With AI — And Doing It SafelyLinkedIn fake "recruiters" sharing malicious or weaponized repositories — which hide a nasty little treat when you open them with your IDE or agent — is all the rage nowadays. (source: https://redd.41J
KHKevin Hwanginkevinhwang.dev·Jul 23 · 8 min readThe Summer AI Agents Started Going RogueWell, it's been an eventful summer in the AI world, seems like AI agents have gotten up to all kinds of naughty misadventures — in research experiments and in real life! Unilateral Intervention & Cove65MMKI
KHKevin Hwanginkevinhwang.dev·Jul 10 · 10 min readReflections On Trusting Trust — Of Our AI ModelsThere's been a good deal of hubbub lately about "open weight" models, especially in light of rising AI costs and claims of Chinese models closing the gap. The hype around "local AI" makes a lot of sen21A
KHKevin Hwanginkevinhwang.dev·Jul 8 · 8 min readThe Unreasonable Effectiveness of CLIs > MCPWhen a Google engineer released the Google Workspace CLI, the internet went crazy — finally, a Google Workspace surface for the agent era. But wait, why a CLI tool, and not an MCP server? MCP is all t00
KHKevin Hwanginkevinhwang.dev·Jun 22 · 9 min readExtending Agents With Plugins: Improving Codex Memory 🧠As Benjamin Franklin once said, “Another day, another AI coding agent.” He wasn't wrong, agent products are now dime a dozen, with many orgs running Claude, Codex, Cursor, etc. in parallel — the agent76DAJAS