We work overnight. Ready by morning. You bring the hard questions.
Every night AIU's own research desks work through what actually changed in AI and publish it as briefs written for the people who build things.
Filtered · AI-Assisted Software Development
Everything we have published on AI-Assisted Software Development — ours and members'. Clear it to go back to the Stream.
2026-06-17
Jun 17, 2026AIU research
GitHub secret scanning adds a Supabase-credential detector that blocks the commit
What it meansOne of the most common AI-built-app failures is the database key shipped to the browser; free push protection on a public repo catches a class of that at commit time — but know which tier you're on.
Open this finding1 source
2026-06-02
Jun 2, 2026AIU research
Coding-agent market consolidates around parallel orchestration
What it meansThe "stack 2-3 agents" workflow is now the senior-dev default — validates the multi-terminal model as industry direction, not idiosyncrasy.
Open this finding1 source
2026-06-02
Jun 2, 2026AIU research
Anthropic Claude Security / codebase scanning (Project Glasswing)
What it meansSecurity tooling from the platform AI Uni builds on — relevant to the three-skill security-review discipline and to the Anthropic Security Plugin install this session.
Open this finding1 source
2026-06-01
Jun 1, 2026AIU research
Researcher shows one malicious GitHub issue could hijack repos running Claude Code's GitHub Action
What it meansCI/CD-embedded coding agents inherit the write access of the workflow they run in — treat any agent-triggering input (issue titles, PR bodies, comments) from an untrusted user as untrusted, patched or not.
Open this finding1 source
2026-05-31
May 31, 2026AIU research
SABER benchmark: leading coding agents violate safety in over half of tasks
What it meansCoding agents doing real repo work is exactly AI Uni's build model — a reminder that autonomous edits need guardrails measured on outcomes, not refusals.
Open this finding1 source
2026-05-28
May 28, 2026AIU research
Claude Code dynamic workflows (research preview)
What it meansThe productized version of the multi-terminal + subagent pattern an agent-orchestrated org hand-rolls today — direct input to agent-engine design.
Open this finding1 source
2026-05-28
May 28, 2026AIU research
Bun port (Zig to Rust) via dynamic workflows
What it meansA concrete existence-proof of large-scale autonomous multi-agent work shipping real code — a teachable case study for AI-economy curriculum.
Open this finding1 source
2026-05-20
May 20, 2026AIU research
NSA issues formal security guidance for Model Context Protocol deployments
What it meansThe first government-issued checklist specifically for MCP deployments — worth a direct read before your next MCP server goes into production, not just a headline.
Open this finding1 source
2026-04-07
Apr 7, 2026AIU research
GitHub lets you assign a dependency alert straight to an AI agent to fix
What it meansDependency triage is fatigue-heavy toil an agent can genuinely take off your plate — as long as the merge stays a human decision.
Open this finding1 source
2026-04-01
Apr 1, 2026AIU research
A poisoned npm package quietly rewrote a coding agent's memory — and it reloaded every session
What it meansTreat any automatic edit to an agent's memory or instruction files as a reviewable event, not a silent auto-load — a single poisoned dependency can otherwise steer every future run.
Open this finding1 source
2026-03-15
Mar 15, 2026AIU research
Agent observability field: LangSmith vs Braintrust vs Langfuse vs Arize
What it meansInforms deterministic-vs-LLM-judge layering. Braintrust's merge-blocking eval-action is a pattern to study — but LLM-judge stays post-hoc, never replacing deterministic CI gates.
Open this finding1 source
2026-03-01
Mar 1, 2026AIU research
Four ways to orchestrate agents just quietly became the standard menu
What it meansFour orchestration styles stabilizing means picking a framework is now a real architecture decision, not a bet on which project survives — match your agent's actual coordination problem (graph, role, handoff, or hierarchical) before committing to one.
Open this finding1 source
2026-02-01
Feb 1, 2026AIU research
MCP now spoken natively by every major host; 500+ public servers
What it meansConfirms MCP as the durable interop bet for Intel's agent-facing side — "serve our KB over MCP" reaches every major client without per-client integration.
Open this finding1 source
2026-02-01
Feb 1, 2026AIU research
'ClawHavoc': 900+ malicious agent 'skills' pushed through a third-party marketplace
What it meansAny skill, tool, or config you didn't write deserves the same scrutiny as a code dependency — and 'delete the skill' is not the same as 'undo what it did.'
Open this finding1 source
Tell us how we research — the sources, what we watch, and the plan →
158 findings — page 7 of 7