Open Source Radar — October 6: nothing leaves your machine

Share
Open Source Radar — October 6: nothing leaves your machine

Today's trending board is all projects we ran earlier this week, so the fresh signal comes from the Product Hunt launch slate instead — three open-source tools that share one instinct: your phone, your pixels and your MCP traffic should stay on hardware you control. All three verified at the source.

iphone-use (Rust, MIT, about 59 stars) is computer-use for a real iPhone: an agent reads the screen as text, taps, swipes and types over WebDriverAgent, and every action comes back with an honest verdict — applied, sent but unconfirmed, or unknown — instead of silent success. That honesty is the point: apps with no API work, including payment apps that block screenshots (those come back as a wireframe), and a task you perform once can be saved as a flow that replays later with no model calls at all. It ships as an HTTP API plus an MCP server for Claude Code and other clients, launched on Product Hunt this week, and the catch is setup friction — macOS 15+, a USB-connected phone and a signed Xcode install before anything moves.


Scumble (JavaScript, GPL-3.0, about 63 stars) is a free desktop editor for AI inpainting: select part of a picture, say what belongs there, and the result lands as its own colour-matched layer you can mask, blend, filter and export — PSD export included — rather than a flattened overwrite of your file. What earns it a slot is where the models run: your own ComfyUI instance, local or remote, or API keys you already pay for (FLUX 3, GPT Image, Nano Banana, Seedream and more), with an MCP server so an agent can drive it too. It launched on Product Hunt this week and ships on Windows today; it's 0.1.x software, so keep backups of anything you care about.


mcpgawk (Python, Apache-2.0, brand new) attacks a supply-chain hole most agent setups ignore: an MCP server you approved can change what its tools do after the fact, and nothing in the protocol tells your agent. Mcpgawk sits in the path on your machine, takes a baseline of every server your agents can reach, checks each call against it, and blocks anything that drifted — nothing is uploaded. It launched on Product Hunt with a GitHub tag and already ships on PyPI plus VS Code, Cursor and GitHub Marketplace integrations; the free layer is the seeing and blocking, while fleet-wide enforcement and drift alerts sit behind a paid platform, so read the tier split before standardizing. Zero stars and days old — a watch-list entry, but the problem it names is real.

Worth watching this week.

Would you let an agent drive your payment apps if every action reported back honestly? Tell us in the comments.

Read more

Korea probes AI agents in bank hacks as president cites 'signs'

Korea probes AI agents in bank hacks as president cites 'signs'

South Korea opened a formal investigation into whether AI agents drove a wave of bank breaches — and it isn't the only AI story moving money today. President Lee Jae Myung said "signs" point at AI models, and the probe is now at the highest level a national banking sector has seen. Speaking at a cabinet meeting, Lee said that "in some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," and police have since opened a full-scale investigation

Deep Dive — Anthropic's guardrails cost it the Pentagon, court or not

Deep Dive — Anthropic's guardrails cost it the Pentagon, court or not

The Pentagon "has ceased the use of Anthropic products," a department official said in a statement to the BBC on Monday — the first time the US military has said out loud what it has been working toward since February. The order to phase Claude out was signed by defense secretary Pete Hegseth on February 27 with a six-month deadline attached; the deadline passed in late August with no public explanation, no successor named, and no acknowledgment that anything had changed. What finally forced a s

DeepSeek nears $12B round with Tencent and CATL ahead of IPO

DeepSeek nears $12B round with Tencent and CATL ahead of IPO

Three stories shape the last 24 hours: a record-scale fundraise at China's most famous model lab, a first-of-its-kind hearing at New York City Hall, and Cohere rebuilding its enterprise agent platform around other people's models. DeepSeek is close to raising at least $12 billion — 80 billion yuan — in a single round that could reach roughly $14.9 billion, after investor demand outstripped the company's own target, with Tencent and battery maker CATL as the biggest contributors, people famili

AI 101 — What are scaling laws?

AI 101 — What are scaling laws?

Scaling laws are the empirical rules describing how an AI model's performance improves in a smooth, predictable curve as three things grow: the size of the model, the amount of data it trains on, and the computing power spent training it. They are not physics — nobody proved them in a lab the way gravity was proven — they are patterns that kept holding every time someone measured them, which is why the entire AI industry now plans around them. The pattern got its canonical statement in a Janua