This Claude Code Setup Makes Your AI Smarter Every Day
An 18-minute walkthrough of the three MCP harvests — Gmail, Slack, and call recordings — that keep an AI operating system's context from going stale.
June 24thA 13-minute live demo where a security plugin catches 15 out of 15 planted vulnerabilities with zero false positives.
Codex Security eliminates false-positive noise by doing what no static scanner does -- it clones your code into a throwaway sandbox and actually fires the exploit before it will ever call something a vulnerability.
Codex Security is a plugin for Codex and VS Code that runs in four stages: build a threat model, scan for likely bugs, validate each finding by actually triggering it in an isolated sandbox, then write a patch. The validate stage is what separates it from traditional scanners -- findings that do not fire in the sandbox get dropped, so you see zero false positives. A small dummy repo took 22 minutes and wiped a full ChatGPT Plus plan; realistic use requires Codex Pro for the cloud tier, especially on larger codebases where scans can run for hours.
Sign in and you get 23 free chat messages on us — ask for the hook, quote a framework, find the exact transcript moment, generate a markdown action plan. Bring your own key when you want unlimited.
Create a free account →
Models scale faster than traditional security approaches; vibe-coded apps ship full of holes nobody notices.

Lives inside your coding tool; finds vulnerabilities, explains them in plain English, offers remediation.

Top of CyberGym for real-world vuln finding, beating GPT-5.5 Cyber.

Plugin install, scan type selection, threat scoping toggle, scan kicked off.

Tier-1 must-catch bugs, Tier-2 harder bugs, deliberate decoys to test false-positive discipline.

Threat model -> scan (impact x likelihood) -> validate (sandbox trigger loop) -> patch.

Ephemeral sandbox clones code, triggers each candidate bug, keeps fires, drops misfires. You are the final approver.

15/15 caught, zero false positives, 3 bonus bugs. plan drained by one small scan.

Plus = local plugin only, small allowance; Codex Pro = cloud tier for long-running large-repo scans.
The gap between 'this looks vulnerable' and 'this is exploitable' is where traditional scanners fail and where sandbox validation changes everything.
“You can bake in any of the things that have found in here, like recurring patterns and things like that, put them in those files so that it doesn't keep making the same mistakes when you're building.”
“This thing caught 15 out of 15 reachable exploitable vulnerabilities with zero false positives, and it even found three bonus bugs that Claude didn't cater for.”
“Just because this thing found something doesn't mean that it's entirely accurate. So what it's doing here is it's actually testing to prove that each bug is really a bug.”
See every word as it's spoken — crank it to 2× and still catch all of it. The same dual-channel trick behind Amazon's Kindle + Audible.
OpenAI shipped a security plugin for Codex the day this video dropped -- and the host immediately built a deliberately-broken repo, loaded it with planted vulnerabilities and decoy false positives, and let the tool run. Thirteen minutes later: 15 for 15, zero noise, three bonus bugs nobody asked it to find.
Four-stage pipeline: understand attack surface, rank bugs by impact x likelihood, prove each bug fires in sandbox, write a minimal patch.
High likelihood + low impact does not equal high risk. High impact + low likelihood still influences the risk score. Neither dimension alone determines priority.
“check out the videos on the screen now. They'll definitely help you in your journey.”
Standard YouTube end-screen CTA. No product pitch or affiliate link. Soft and brief.
00:00
00:11
00:24
00:34
00:44
00:54
01:04
01:14
01:24
01:34
01:42
01:54
02:04
02:14
02:29
02:34
02:44
02:54
03:04
03:14
03:24
03:34
03:40
03:54
04:01
04:14
04:22
04:34
04:44
04:53
05:04
05:17
05:24
05:34
05:41
05:54
06:04
06:14
06:24
06:34
06:44
06:54
07:04
07:14
07:24
07:34
07:44
07:54
08:04
08:14
08:24
08:34
08:44
08:57
09:05
09:14
09:20
09:34
09:44
09:54
10:04
10:14
10:24
10:34
10:44
10:53
11:04
11:14
11:24
11:34
11:41
11:54
12:04
12:14
12:24
12:34
12:44
12:54
13:05
13:14An 18-minute walkthrough of the three MCP harvests — Gmail, Slack, and call recordings — that keep an AI operating system's context from going stale.
June 24thA 9-minute rebuttal that reframes a government AI ban as a boring availability outage — and the six rules that make sure it never hurts you again.
June 16thA 16-minute screen-share tour of how to build a four-department AI operating system inside Claude Cowork Projects — no IDE required.
March 22ndAn 11-minute walkthrough of reverse prompting — purpose-built interview skills that extract your tribal knowledge and simultaneously build the AI workflows your business needs.
June 20thA 14-minute tutorial that converts the feeling of being lost into a five-step repeatable system for learning anything with AI.
June 17thA 10-minute live demo of a Claude skill that reads every connected SaaS system via read-only MCP connectors and returns a visual HTML data map — security flags, PII exposure, and a build-order recommendation included.
June 15th