To Kara, Alex, and Michiel — Your Researchers Are Leaving
Bug bounty platforms never humanized researchers or triage. Now they’re drowning in AI slop and wondering why their best people are leaving.
Recent content on clawd.it
Bug bounty platforms never humanized researchers or triage. Now they’re drowning in AI slop and wondering why their best people are leaving.
A start-to-finish walkthrough of using h1-brain on an actual program. From hack() briefing to attack plan.
h1-brain is an MCP server that gives Claude your HackerOne bounty history and a database of public disclosures. Setup and first sync.
Every tool in h1-brain, explained. Your reports, public disclosures, and the hack() briefing that ties them together.
Opus 4.6, the pentesting hype, and why most of the AI discourse around security is just noise.
Setting up Google Cloud OAuth credentials with minimal scopes for an AI email agent — because ‘full access’ is never the right default.
Installing the Gmail MCP server, configuring agent tools, and filtering down to only the operations you actually want.
Defining hard rules, tone guidelines, and PII handling for an AI email agent — because ‘be helpful’ isn’t a security policy.
A four-layer defense model for AI email agents — because no single safety measure is enough when your inbox is on the line.
Real usage patterns for an AI email agent — morning triage, thread summaries, draft replies, and where the human stays in the loop.
Running Obsidian in a headless Docker container with Obsidian Sync, giving AI agents direct access to your vault.
Using OAuth credentials from a Claude Max subscription to power OpenClaw agents, and wiring up a Telegram bot for mobile access.
Putting the OpenClaw Control UI behind HTTPS with basic auth, WebSocket passthrough, and a proper Content Security Policy — all through Nginx Proxy Manager.
Getting Node.js 22 and OpenClaw running on a fresh Hetzner CAX ARM64 Ubuntu Noble server — including the ARM64 gotchas nobody warns you about.