Find security flaws in open-source software
Google's Big Sleep agent reported about 20 security flaws in open-source software, following its SQLite find.
Done withGemini
- What they did
- Big Sleep, built by Google DeepMind and Project Zero, was pointed at widely used open-source projects. It found and reported 20 previously unknown vulnerabilities, mostly in FFmpeg and ImageMagick. The article gives no detail on the agent's workflow or on how much human review was involved. It does describe the earlier SQLite case, where the agent traced the root cause of a flaw that Google's threat intelligence team had only seen signs of being exploited.
- How it went
- 20 flaws were reported, and their details are withheld under standard disclosure procedures. The article says nothing on severity or fix status for these 20. The earlier SQLite bug (CVE-2025-6965) was rated 7.2 on CVSS.
- Worth knowing
- The specifics of the 20 flaws are not public yet, so you can't check them. The article also doesn't say how many reports were valid or how much human triage was needed.
Try it yourself with Gemini
Clone [open-source repository URL] and review its [language] code for likely security flaws such as memory safety bugs, injection, unsafe input parsing, and hardcoded secrets. Write up each finding in a file with the file path, a short explanation, and how severe you think it is. Do not change any code or open any issues or pull requests. Stop once you have a ranked list of your top [number] findings.
Source: computing.co.uk · Undated
Five of these in your inbox every morning
The best things people got an AI agent to do, each with the prompt to try it.
More like this
Race three models to build a Counter-Strike clone
InstantDB had Codex, Opus, and Gemini each try to build a multiplayer shooter.
Edit existing video clips with plain-English instructions
A creator tested Gemini Omni Flash over 36 hours, editing clips in place from typed instructions while preserving lighting and camera angle, with variable quality.
Solve open math problems autonomously
DeepMind's Aletheia agent on Gemini Deep Think was evaluated on 700 open Erdős problems and autonomously solved four.
Find a Linux vulnerability hidden for 23 years
An account of Claude Code uncovering a long-standing vulnerability in Linux.
- MathKernel
Give agents a multi-engine math kernel via MCP
MathKernel is an evidence-aware multi-engine mathematics kernel exposed as an MCP server for agents to use.
Design and build a robotic arm with no CAD experience
A builder used Claude Code with FreeCAD and Claude Vision to design, print, and assemble a 5-DOF servo arm with vision and voice control.