happy sunday 🫶
gm legends and welcome back to the Roundup! In today's issue: Google's new prompt to UI tool, Claude's biggest update yet, a plain-language app builder, Jony Ive's newest product, and a discussion on how to audit your vibecoded apps.
Your agents stopped answering and started doing
Your agents call tools, write to databases and move money, so a wrong answer is now a wrong action, which is a considerably worse meeting. Arcjet runs policy before every LLM call, tool call, query and API request: prompt injection, sensitive data, bots, rate limits, spend quotas, and your own rules in Rego on top. It reads the OpenTelemetry you already emit, so switching it on is one environment variable, no code changes and nothing to deploy. Each check also reads the earlier steps in the same workflow, so an agent's tenth action gets judged against the first nine and not on its own. JavaScript, Python and Go SDKs all at 1.0, agent framework guards included, free tier to start on.
Leaderboard highlights





Jony's next big thing

In case you've been living under a rock the past week: Jony Ive, the guy who designed the iPhone, iPod, and more has decided to team up with OpenAI to crack the AI hardware nut.
What's the big move? An AI-powered vape, according to the internet. How much more Silicon Valley could you possibly get?
Wait, who is auditing the bots!?

Constantine dropped a worry bomb: “If you vibecode your product, part-time AI, part-time human, how do you keep it secure?”
Replies grouped up fast. Some folks lean on automated scanners and CI checks to catch the low-hanging bugs before code ever merges. Others call in pen-test pros once a quarter, treating AI-generated chunks with extra suspicion. A third camp swears by threat-modeling sessions and good old manual reviews, arguing that you still need eyeballs on every line, bot-written or not.
Big takeaway: AI can write code, but it can’t sign off on security. Worth a scroll if your repo already has more machine commits than human ones.

