跳到正文
北京时间
原文
Andrew Ng· @AndrewYNg · X·· 2026-08-26精选AI 评分67
AI 导读

Andrew Ng 旗下开源智能体 OpenWorker 发布新版,强化安全工作流。其 harness 完全开源,安全团队可审计无后门。新版内置代码漏洞扫描、依赖供应链注入检测和云安全配置检查三类网络安全智能体,并支持本地运行开源权重模型以保护敏感代码。

推荐理由

OpenWorker 把漏洞、依赖和云配置检查放进可本地运行的开源 agent,安全团队能在代码不出本机的前提下审计工具链,比闭源方案多一层透明。

正文 · 原文

OpenWorker -- an open source agent that doesn't just chat but completes tasks on your laptop -- just released a new version with many features for security workflows.

After our initial release, many users found it especially useful for cybersecurity. Attackers are already using AI; OpenWorker is committed to giving defenders the same leverage. Running an agent requires both (i) A model and (ii) A harness (the software around the model). Because the OpenWorker harness is fully open source, security teams can audit it to make sure we haven't built any backdoors that exfiltrate your code and data to some company or even a foreign adversary.

OpenWorker now comes with built-in cybersecurity agents for (i) Scanning your code for vulnerabilities. (ii) Scanning dependencies for supply chain injections. (iii) Checking your cloud security configuration for attack surfaces. This enables developers to do much more security work before deployment (part of what's called the "shift left" movement).

You choose the model: you can run open weight models fully locally so sensitive code never leaves your machine. This helps with legitimate security work (like reproducing a known exploit to defend against it) that can trigger refusals in leading closed models. Or use your ChatGPT subscription, or stealth preview models like Ox Alpha, or any model via API key.

Thanks also to all the open source contributors!

Join work with @rohitcprasad so please follow him too to get more frequent updates.

Try it out: https://openworker.com/
Code: https://github.com/andrewyng/openworker

来源:Andrew Ng · x.com

相关事件