今日重点项目雷达
安全 / 治理
产品 / 成本
开源 / 安全工具
采集:Mac 已连 →
collect_ai_world_daily.py(JSON ~1.1MB,errors=[])+ 官方页核对(Claude / GitHub Changelog / Anthropic Engineering 回源 / HF / 中文站)。相对 2026-09-24 筛过夜新变量;Medicare、Marketplace、Cursor Rollouts、ART 酶、Antigravity、Ember-1、Gemini TTS 昨已报,不再当主新闻。AI News 自有发布。厂商与研究者自报数字标待第三方验证。
一、今天一句话
昨夜重点不在「再出一个模型」,而在权限怎么写细:频道里能用个人连接器了(Claude Tag)、GitHub 企业高危动作要「人在场」再认证、网上开始成规模用 GEO 把假电话塞进 ChatGPT / Gemini 回答——店端知识页和机器人外发都碰得到。
二、本周动作(已定)
把权限表写实,补三块新例子。 频道里用个人连接器:谁的账号、回帖前谁看、无人值守仍走共享连接器(对照 Claude Tag)。高危动作要本人在场再认证,不能只靠长活会话(对照 GitHub proof of presence)。店端 / 知识页 / 销售助手:电话、邮箱、登录入口以官网为准,AI 搜到的联系方式先人核(对照 GEO 投毒)。昨天的研究 agent 撞墙停手、Medicare 通知时限、Muse / ZCode 行继续留在表里,不另开项目。
模型短名单继续只试用。 Sol / Luna、Opus 5.5 仍在候选。长会话先看缓存命中(Anthropic 称长 coding 会话成本差主要来自缓存读降价,厂商)。生产默认本周不切。挑 1–2 个真任务做 A/B。
Origin 一页纸日期改到至少 9/25。 昨天已写的 Rollouts(上线后盯回归)和 Security Reviewer 保留。补一句企业侧对标:高危合并 / 改安全设置前要「人在场」认证——先记口径,不本周强上。
三、今日卡片
安全 / 治理
#### Claude Tag:频道里可用「个人连接器」,发前可先给你看
- 摘要:2026-09-24 Claude 官方。Slack 频道里的 Claude Tag(beta)以前只能用管理员挂到频道的共享连接器;现在你点名提问时,可以用你自己账户上的连接器(日历、网盘、CRM、预发环境等),别人用不了你的。回帖可先审再发,也可自动发(敏感内容仍拦);企业版管理员可强制全员先审。无人值守的定时任务仍只用频道共享连接器。Team 先开,Enterprise 随后。
- 有什么用:OpenClaw / 内部机器人直接对标——共享工具 vs 个人登录、发前审 vs 自动发、定时任务不许挂私人凭证。权限表补三行就能用,别让员工在群里私接网盘。
- 来源 · https://claude.com/blog/claude-tag-now-supports-personal-connectors-in-channels · 一手
#### GitHub:高危动作可要求「证明人在场」
- 摘要:2026-09-24 GitHub Changelog。Enterprise Cloud(托管用户 + Entra ID SSO)可对高危动作开启 proof of presence:建 token、改 webhook、改组织安全设置、看恢复码等,先被送回身份提供商做再登录或 MFA,通过才放行。针对被偷的会话 cookie / 长活 token;通过后同浏览器约两小时内同类动作免再验。PR 合并前强制尚在路上。公开预览。
- 有什么用:权限表与 Origin 流水线的企业对标——「有有效会话」不等于「此刻是本人」。友车若走 GitHub EMU + Entra,可评估;OpenClaw 外发 / 改权限类动作也应默认先人确认。
- 来源 · https://github.blog/changelog/2026-09-24-require-proof-of-presence-for-high-impact-actions/ · 一手
#### GEO 投毒:AI 回答里出现假客服电话(374 家企业,研究者称)
- 摘要:安全研究者 Ariel Simon 等发文(约近两日;AIHOT 9/25 收录)。称攻击者用生成式引擎优化(GEO)在论坛、PDF、UGC 站铺假联系方式,诱使 ChatGPT、Gemini、Google AI Overview 在用户查航司 / 银行 / 平台客服时给出诈骗电话或钓鱼页;点名 Delta、汉莎、BoA、Airbnb 等。自称侦测到约 374 家受害企业(研究者数字,待第三方复测)。称已向 Google / OpenAI 报漏洞赏金,多被判「不在范围 / 难复现」。
- 有什么用:店端销售助手、知识页、报价口径——联系方式只认官网与主机厂通稿,禁止「让模型搜一个电话」。对外话术:AI 给的号码要二次核实。权限表加「外链 / 网页代读结果不当事实」。
- 来源 · https://medium.com/@arielsimon/dark-sourcery-how-hackers-manipulate-ai-to-scam-you-88df434d2073 · 媒体/研究者(数字待核实)
产品 / 成本
#### Anthropic:Opus 5.5 为「更长、更重上下文」的 coding 会话算账
- 摘要:2026-09-24 Claude 官方工程向博文。复述 Opus 5.5 相对 Opus 5 典型负载约低 40% 成本(厂商);强调近半年 Claude Code 单次请求上下文约增 2.6×、缓存读占比升高,所以缓存读降价 60%对长会话更敏感。建议:开场定模型别中途乱切、离开前先 compact、API/云侧可开一小时缓存。开篇数字与 9/22–23 发布口径一致,本条当「怎么用」补丁,不当新模型发布。
- 有什么用:短名单试用时盯
/usage缓存命中;OpenClaw 长任务别中途换模型打断缓存。仍不切生产默认。 - 来源 · https://claude.com/blog/claude-opus-5-5-built-for-coding-sessions-that-use-more-context · 一手(成本数字待第三方验证)
开源 / 安全工具
#### GitHub Security Lab:LLM 驱动的 C/C++ 自主 Fuzz 流水线
- 摘要:2026-09-24 GitHub 官方博客。开源 Fuzzing Taskflow:指向仓库后自动找入口、写 harness、跑 AFL++、读覆盖、补字典、分诊崩溃并写报告。默认 Claude Sonnet 5。作者明确警告:在宿主机跑编译与 fuzz,须用一次性 Codespace / 抛弃型虚拟机,勿提权。
- 有什么用:友车 / 开源依赖里有 C/C++ 原生组件时可小样;对照「安全 agent 必须沙箱」。仓进 GitHub 栏。
- 来源 · https://github.blog/security/application-security/ai-powered-fuzzing-with-the-github-security-lab-taskflow-agent · 一手;https://github.com/GitHubSecurityLab/seclab-taskflows-fuzzing · 一手
#### Liquid AI:视觉模型投机解码草稿 LFM2.5-VL-DSpark
- 摘要:2026-09-24 HF 博文。为 LFM2.5-VL-3B 释出约 2.8 亿参数草稿模型,厂商称端侧解码最高约 3.13×、H100 约 2.66×(待复测);日一支持 llama.cpp / MLX-VLM / SGLang。投机只加速解码,不加速视觉编码与 prefill。
- 有什么用:店端 / 本机多模态小样的速度旁路;先看许可证与实测,不进本周动作。
- 来源 · https://huggingface.co/blog/LiquidAI/lfm2-5-vl-dspark · 一手(速度数字待第三方验证)
四、GitHub 值得关注
Mac collect github.ranked_recent(74)按友车 / OpenClaw / ABU9 用途筛过;排除刷星空壳、水印灰产、APK 逆向、钱包贴图壳等。另手头补入本轮官方 Fuzzing Taskflow 两仓。星数为采集时点;Security Lab 两仓星数暂缺(API 限流),以仓链为准。共 60 个。
- GitHubSecurityLab/seclab-taskflows-fuzzing · ★— — LLM agent 驱动的 C/C++ 自主 fuzz 流水线(AFL++、覆盖反馈、崩溃分诊);须在一次性环境跑 · https://github.com/GitHubSecurityLab/seclab-taskflows-fuzzing
- GitHubSecurityLab/seclab-taskflow-agent · ★— — GitHub Security Lab 的 LLM 安全自动化 Taskflow 框架 · https://github.com/GitHubSecurityLab/seclab-taskflow-agent
- mikehasa/golive-skill · ★874 — Take your agent-built product live: hosting, database, domain, email, payments — on your… · https://github.com/mikehasa/golive-skill
- jev-chat/jev-chat-jarvis · ★6050 — 装在手机上的对话副驾:在 QQ / X / 飞书里读懂对方、给出候选回复、一键填入输入框,发不发由你。非侵入,只读屏幕,不 hook 不改包。 · https://github.com/jev-chat/jev-chat-jarvis
- zai-org/ZCode · ★6705 — Z · https://github.com/zai-org/ZCode
- unreallabsai/unreal-agent · ★1876 — Async-first agent harness · https://github.com/unreallabsai/unreal-agent
- driceroland/Search · ★1238 — A small, fast WebKit browser for macOS, by Office Commun · https://github.com/driceroland/Search
- tamaratran/fast-jev-compaction · ★6720 — Claude Code plugin that replaces the compaction summary with Jev decisions: every tool c… · https://github.com/tamaratran/fast-jev-compaction
- CopilotKit/openmuse · ★2076 — A personal agent with a browser, terminal, files, and work that keeps going built with C… · https://github.com/CopilotKit/openmuse
- browser-use/jev-ultrafast · ★19809 — Fastest and cheapest web agent · https://github.com/browser-use/jev-ultrafast
- mcncarl/jianying-headless · ★2496 — Private source preview: native Jianying drafts, isolated editing/export, and standalone … · https://github.com/mcncarl/jianying-headless
- yibie/awesome-jev · ★1619 — A curated list of public projects, integrations, and discussions built on Jev — TypeSafe… · https://github.com/yibie/awesome-jev
- kerpopule/hermes-jev-skills · ★774 — Jev-powered model routing, memory, compaction, skill selection, computer and browser use… · https://github.com/kerpopule/hermes-jev-skills
- Human-Agent-Society/reef · ★4654 — Continual learning infra for self-improving agents · https://github.com/Human-Agent-Society/reef
- XiaoDuoYa/codex-with-chatgpt · ★6612 — ChatGPT thinks · https://github.com/XiaoDuoYa/codex-with-chatgpt
- v-modal/awesome-jev-tools · ★713 — A curated list of tools built for Jev — TypeSafe AI's System One model for typed decisi… · https://github.com/v-modal/awesome-jev-tools
- vinzdg/codenotch · ★2466 — A macOS app that pins usage limits from Claude Code, Cursor, Codex, and Antigravity to a… · https://github.com/vinzdg/codenotch
- Nanako0129/sepia · ★2834 — De-AI writing skill for any Agent Skills-compatible agent (77+ via the Skills CLI), with… · https://github.com/Nanako0129/sepia
- shadcn-ui/lint · ★2755 — An agent-first linter for Tailwind design systems · https://github.com/shadcn-ui/lint
- anthropics/commerce-agents · ★3044 — Reference blueprint for building shopping and merchant agents with Claude · https://github.com/anthropics/commerce-agents
- agentverse-os/AgentVerse-OS · ★978 — Personal cloud OS for a developer and their AI agents on a single server · https://github.com/agentverse-os/AgentVerse-OS
- Rion-Wu-tech/wechat-intelligence-hub · ★2523 — Local-first WeChat intelligence system with a read-only CLI, Codex skills, searchable ch… · https://github.com/Rion-Wu-tech/wechat-intelligence-hub
- youngyangyang04/llm-master · ★945 — 大模型(LLM)全栈学习路线与中文教程🔥:覆盖 Prompt Engineering、RAG、AI Agent、MCP、微调、模型部署、Transformer、AI 编程与大厂… · https://github.com/youngyangyang04/llm-master
- xai-org/grok-build · ★27080 — SpaceXAI's coding agent harness and TUI · https://github.com/xai-org/grok-build
- hypit-ai/hypit · ★16113 — Clone any viral video with AI agents · https://github.com/hypit-ai/hypit
- kruzovic7/ai-data-extractor · ★843 — Free open-source extractor for AI coding assistant chat histories · https://github.com/kruzovic7/ai-data-extractor
- donvito/codex-astra-luna-orchestrator · ★1601 — Use Astra or Sol as orchestrator and Luna for subagents in Codex · https://github.com/donvito/codex-astra-luna-orchestrator
- eternityspring/reelbench-skills · ★835 — Learning notes and tooling skills for AI video - AI 视频相关的学习与工具 skill · https://github.com/eternityspring/reelbench-skills
- achimala/dream-loop · ★1547 — Agent skill for impressive 3D visuals using Blender + image gen + subagent critic · https://github.com/achimala/dream-loop
- Vincentwei1021/anything2explainer · ★2040 — Topic in, narrated explainer video out · https://github.com/Vincentwei1021/anything2explainer
- yc-software/qm · ★15233 — Multiplayer agent harness for work · https://github.com/yc-software/qm
- NandhaKishorM/laya · ★22980 — Non-autoregressive System 1 decision engine · https://github.com/NandhaKishorM/laya
- mizorewww/laya-mlx · ★6214 — Native MLX runtime for Laya typed decision models — 7–14 ms short decisions on M3 Max · https://github.com/mizorewww/laya-mlx
- jaredpalmer/kev · ★6741 — Jev-like family of decision models built on top of Qwen3 · https://github.com/jaredpalmer/kev
- deepopen-com/deepopen · ★1005 — 非自回归System 1决策引擎,专为结构化类型决策场景设计 DeepOpen Multilingual, non-autoregressive System 1 decis… · https://github.com/deepopen-com/deepopen
- Player-YN/BrowserKitten · ★2857 — Paw Work - selection-first web agent for Chrome: select on the live page, describe the o… · https://github.com/Player-YN/BrowserKitten
- bespokelabsai/nimble · ★1731 — Local typed decisions, contrastive data curation, and model evaluation · https://github.com/bespokelabsai/nimble
- mizorewww/laya-coreml · ★1436 — Local Laya typed decisions on Apple Core ML and Neural Engine · https://github.com/mizorewww/laya-coreml
- deeplethe/utopia · ★10005 — World's first open-source enterprise world model · https://github.com/deeplethe/utopia
- TianyuCodings/NanoJev · ★2202 — A nano replica of Jev: parallel decisions, dynamic candidates, and an end-to-end trainin… · https://github.com/TianyuCodings/NanoJev
- dataelement/dsh-desktop · ★9095 — DSHDesktop:DeepSeek Harness Desktop / DeepSeek Harness 桌面版 · https://github.com/dataelement/dsh-desktop
- miuuyy/codex-chatgpt-web · ★11282 — Use ChatGPT Web (including Pro) as a native model in Codex — with context, tools, stream… · https://github.com/miuuyy/codex-chatgpt-web
- NVlabs/SoL-Pi · ★3040 — SoL-Pi: Scaling Auto-Research Loops for Efficient Agent Harnesses · https://github.com/NVlabs/SoL-Pi
- genspark-ai/genoffice · ★7668 — Free, open-source AI Office suite: Docs, Sheets, Slides, PDF, Markdown and HTML editors … · https://github.com/genspark-ai/genoffice
- FareedKhan-dev/kimi-k3-in-c · ★8552 — A 2 · https://github.com/FareedKhan-dev/kimi-k3-in-c
- CopilotKit/OpenBot · ★5518 — Open-source AI coworkers that each get a computer of their own: a browser, files and too… · https://github.com/CopilotKit/OpenBot
- openai/codex-security · ★10841 — OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing secur… · https://github.com/openai/codex-security
- trailhq/Graft · ★9172 — Turbocharge Claude Code, Cursor, Codex, Gemini & every coding agent: faster, cheaper, wi… · https://github.com/trailhq/Graft
- Hisn00w/ASu-skills · ★5106 — 🚀面向求职与开发场景的实用 AI Skills 集合,支持简历优化、岗位投递、面试准备与开发提效。 · https://github.com/Hisn00w/ASu-skills
- unicity-aos/aos-ce · ★8465 — AOS Community Edition: the open agent operating system · https://github.com/unicity-aos/aos-ce
- heyjunpenn/awesome-jev · ★806 — A verified, community-maintained catalog of 896 open-source projects built with Jev · https://github.com/heyjunpenn/awesome-jev
- cbrock84/headcount · ★1663 — An agent organization structured as a company — 15+ departments, 125+ skills, each indep… · https://github.com/cbrock84/headcount
- truefoundry/trueforge · ★5955 — The open-source agent harness - the runtime layer that turns an LLM into a working agent · https://github.com/truefoundry/trueforge
- drumih/turbo-fieldfare · ★6819 — Gemma 4 26B-A4B inference in ~2 GB of RAM on any M-series MacBook · https://github.com/drumih/turbo-fieldfare
- aipoch/open-science · ★4920 — The open-source AI research workbench for scientific research and agent workflows · https://github.com/aipoch/open-science
- oomol-lab/open-connector · ★5898 — Open-source auth gateway connecting 1500+ SaaS providers to AI agents through SDK, CLI, … · https://github.com/oomol-lab/open-connector
- TencentCloud/Octop · ★4862 — A smarter, self-hosted AI assistant — multi-user, multi-agent · https://github.com/TencentCloud/Octop
- Vincentwei1021/video-shotcraft · ★9436 — AI video skill for Claude Code & Codex — cinematic product videos with Remotion: 152 sho… · https://github.com/Vincentwei1021/video-shotcraft
- bojieli/ai-infra-book · ★5244 — 《深入理解 AI Infra:量化分析与系统设计》(李博杰 著)开源书稿:从硬件约束和模型架构出发,量化推导 LLM 推理与训练系统设计。含全书正文、PDF、配套计算工具与实验 · https://github.com/bojieli/ai-infra-book
- zjwzcx/Awesome-Astra-Embodied-AI · ★1017 — GPT-6 Astra for embodied AI and robotics · https://github.com/zjwzcx/Awesome-Astra-Embodied-AI
五、WATCH
- OpenAI DevDay 下周二:Codex 负责人 Tibo 原帖称「会改你工作方式」;等官方日程与产品页再升主栏。 · https://x.com/thsottiaux/status/2102996313780736363
- GPT Voice 大升级(可调邮件/日历等):昨已旁观;仍等正式产品页。 · https://x.com/gdb/status/2102821706041819401
- Claude Code Cloud sessions 抵用金口径:团队称按订阅跑,推广为 Pro $100 / Max $250 一次性抵用(社媒/二手,待官方账单页)。
- Arena / AA 上 Opus 5.5 编程榜:第三方分数波动期,作短名单旁注,不单独驱动切换。
- OpenAI×苹果 ChatGPT 合作低于预期(法庭文件):行业旁观,不进本周动作。
- OpenAI Daybreak 向乌克兰民防开放:地缘/安全旁观。 · https://openai.com/index/openai-extends-cyber-access-to-ukraine-for-civilian-defense
- Medicare / Transluce 续报:昨已写进权限表;更多日志披露不新开项目,只加固「撞墙停手 + 通知 SLA」。
六、Grok Bot / Cursor 用法增量(相对昨)
- 无新的 Grok Bot 公开用法帖需进主栏(相对 9/24)。
- 对标增量(非 Grok):Claude Tag 的「个人连接器 + 发前审」可借鉴到内部机器人频道治理;GitHub proof of presence 对应「高危动作不能只靠长会话」。
- Cursor Rollouts / Security Reviewer 昨已报,不重复。
七、全文垫后(采集备注)
- Mac collect
errors=[];ranked_recent74 条;列入栏的 GitHub 仓 60。 - Anthropic Engineering 旧文(含 5 月 containment、4 月 postmortem)出现在 Follow Builders 博客信号里,已回源确认日期,不写入今日主栏。
- 软失败:z.ai/blog 404;机器之心首页壳薄;GitHub API 星数限流(Security Lab 两仓星标为 —)。
- Sepia 人话终检:拆「个人连接器 / 人在场认证 / GEO 假电话」三块;禁工单英文;厂商与研究者数字旁注条件。
- 本版发布 flyingnick HTML;未碰 Telegram;花费未超 ¥100。