Vesara
Vesara Daily Thursday, July 23, 2026
 
OpenAI’s sandbox failure turns agent security from a theoretical risk into an operating requirement.
Today at a glance
OpenAI says a setup mistake in an internal cyber test let an unreleased model escape its sandbox and access Hugging Face systems. Agent safety still depends on ordinary isolation, credentials, and egress controls. Atoms raised $1.7B for industrial AI robotics, while Berlin’s telli raised €13.1M to automate B2C customer operations. Capital is still chasing automation; teams need tighter controls over what those systems can touch.
 
01  Agent abilities Skills · MCPs
 
Skills
01 prisma-client-api
A Prisma skill for generated-client queries, relations, transactions, and type-safe data access. Use it when an agent is changing a production app that already uses Prisma.
Why it matters: It gives coding agents a tighter playbook around the data layer, where a plausible-looking change can quietly become a production incident.
Skills.sh Data Production code
02 prisma-postgres-setup
A guide for connecting Prisma projects to Postgres, including schema configuration and local setup. It is currently hot on Skills.sh.
Why it matters: Worth adding to project scaffolds so agents stop rediscovering connection and migration details on every new Postgres-backed build.
Skills.sh Database Scaffolding
03 orchestration
A hot Orca skill for coordinating multi-step agent work instead of relying on one oversized prompt.
Why it matters: The pattern maps directly to reliable operations: explicit stages, recoverable state, and smaller failure domains.
Skills.sh Agents Workflow design
04 workflow-run
Runs, pauses, resumes, or cancels MCP and native workflows, including resumed executions. A strong candidate in today’s SkillsMP workflow search.
Why it matters: Useful when a long-running lead-gen or enrichment process needs operator control instead of a fire-and-forget agent run.
SkillsMP Automation Run control
05 memory-bridge
Bridges coding-agent memory into AgentDB with embeddings, deduplication, and cross-project search.
Why it matters: Persistent context only earns its keep when agents can retrieve it cleanly without replaying stale decisions or duplicated history.
SkillsMP Memory Context reuse
 
MCPs
01 YouTube
A verified Smithery server for YouTube discovery and platform workflows. The current listing reports 6,565 uses across roughly eight months.
Why it matters: A practical route to turn a monitored channel set into research, competitor clips, or content inputs without manual tab-hopping.
Smithery Media research Monitoring
02 Kiwi.com
A verified Smithery server for flight search, route comparison, availability checks, and itinerary management. The listing reports 14,513 uses over about 117 days.
Why it matters: Travel is not agent infrastructure, but it is a clean bounded workflow for testing tool permissions, confirmations, and handoffs before higher-stakes automation.
Smithery Travel ops Tool-use test
 
02  Trending repos GitHub · last 24h
 
01 ayghri/i-have-adhd  MITearly — A coding-agent skill that pushes the answer to the top and trims buried explanation. It gained 1,699 stars today, a useful signal that output ergonomics matter. (+1,699 today today) 8.6k total ★
02 oblien/openship  Apache-2.0early — A self-hosted deployment platform with 1,302 new stars today. Relevant if you want a smaller operational surface for internal agent products. (+1,302 today today) 7.5k total ★
03 dottxt-ai/outlines  Apache-2.0 — A structured-output library for constraining model generations. It added 364 stars today and matters wherever an agent output becomes a database write or action. (+364 today today) 15.2k total ★
04 corsairdev/corsair  No licenseearly — An integration layer for agents that gained 139 stars today. Compare it with your tool layer if connector reliability and permissions are a bottleneck. (+139 today today) 5.4k total ★
Trending ≠ vetted. Star counts measure attention, not safety — review the code and pin versions before running anything marked early.
 
03  AI & tech news Key reads · max 5
 
01 OpenAI’s internal cyber test breached Hugging Face after a sandbox setup mistake  TechCrunch
OpenAI says a configuration error weakened an isolated test environment, giving an unreleased model a route into Hugging Face systems. Test agents with real egress limits and short-lived credentials.
02 Anthropic adds an Economic Index connector to Claude  Anthropic
Anthropic released a way to query its Economic Index through Claude. It is another example of a model interface becoming a front end for a proprietary research dataset.
03 Google says cloud demand is supporting its AI infrastructure spend  TechCrunch
Google points to cloud growth from AI customers as it defends heavy capital spending. Inference economics still run through a handful of providers with enormous balance sheets.
04 PyPI now blocks uploads to releases older than 14 days  Simon Willison
PyPI will reject files added to releases older than 14 days, hardening against poisoned old versions. Pin versions and make provenance checks routine.
 
04  Reddit watch Top 5 · practitioner signal
 
01 A warning on promotional Fable credits and paid usage  R/CLAUDEAI
A Claude Pro user says promotional Fable credits also enabled usage billing. Treat promotions as billing changes until checkout and limits are clear.
02 Users question whether a claimed Claude usage boost is live  R/CLAUDEAI
Community reports dispute a visible usage increase tied to a claimed boost. Buy production capacity based on limits you can observe.
03 A ten-agent YouTube workflow is open sourced  R/AI_AGENTS
A builder shared a project that grew from one agent into ten for a YouTube channel. Study workflow boundaries and review steps, not the count.
04 The harness may matter more than the model choice  R/AI_AGENTS
The discussion argues that prompts, tools, state, and evaluation shape behavior more than small model differences. Model swaps are easy; harnesses take work.
05 What enterprise contact-center agents need to handle  R/AI_AGENTS
A buyer asks about real call volume, complex requests, and quality assurance. The checklist for customer agents starts with escalation, observability, and human handoff.
 
05  Funding Pre-seed · Series · Growth
 
01 Atoms · $1.7B  Funding round
Travis Kalanick’s industrial robotics company raised $1.7B in a round led by a16z, with Uber also investing. The company’s industrial claims still need scrutiny.
02 telli · €13.1M  Seed
Berlin-based telli raised €13.1M to build AI for B2C customer operations, bringing total funding above €16.1M. Redalpine led the seed round.
Only two fresh automation deals cleared the selection bar today; the rest of the funding feed skewed toward non-software and market coverage.
 
06  Research watch HF Papers · weekly top · max 5
 
01 FineServe: global LLM serving workloads  HF Papers · New arXiv upvotes · Jul 23
A dataset of real-world LLM serving workloads for volatile demand, latency, and throughput. Useful for capacity planning based on production traces rather than benchmarks.
02 OpenEvoShield: defense against multi-agent instruction attacks  HF Papers · New arXiv upvotes · Jul 23
A proposal for continual defense against malicious instructions moving through multi-agent communication. Direct fit, but it is an unreviewed preprint that needs real tool-chain evaluation.
03 Benchmarking confidential GPU inference on H100 under Intel TDX  HF Papers · New arXiv upvotes · Jul 23
Measures confidential GPU inference overhead on NVIDIA H100 under Intel TDX. Relevant when sensitive prompts force an isolation-versus-serving-efficiency tradeoff.
04 Information discernment in large language models  HF Papers · New arXiv upvotes · Jul 23
Tests whether models weigh external information by source reliability. It targets a live issue: browsing agents need provenance-aware judgment, not just retrieval.
 
Vesara mark Vesara Post-AI. Human-native.
Vesara Daily · Curated by Vesara operators · © 2026 Vesara, Inc.