Simon Willison’s Weblog

Subscribe

Sunday, 8th February 2026

Research krunsh — Krunsh is a minimal Go CLI tool that executes newline-delimited shell commands inside an ephemeral KVM-based microVM, leveraging the libkrun library for lightweight virtualization. By piping commands from stdin, krunsh spins up a microVM, runs the specified commands using `/bin/sh -c`, captures the output, and discards the VM afterward, ensuring zero persistent state and strong process isolation.

People on the orange site are laughing at this, assuming it's just an ad and that there's nothing to it. Vulnerability researchers I talk to do not think this is a joke. As an erstwhile vuln researcher myself: do not bet against LLMs on this.

Axios: Anthropic's Claude Opus 4.6 uncovers 500 zero-day flaws in open-source

I think vulnerability research might be THE MOST LLM-amenable software engineering problem. Pattern-driven. Huge corpus of operational public patterns. Closed loops. Forward progress from stimulus/response tooling. Search problems.

Vulnerability research outcomes are in THE MODEL CARDS for frontier labs. Those companies have so much money they're literally distorting the economy. Money buys vuln research outcomes. Why would you think they were faking any of this?

Thomas Ptacek

# 2:25 am / open-source, security, thomas-ptacek, ai, generative-ai, llms, anthropic, claude

Release sqlite-history-json 0.1a0 — SQLite table history tracking using a JSON audit log
Release sqlite-history-json 0.2a0 — SQLite table history tracking using a JSON audit log
Release sqlite-history-json 0.3a0 — SQLite table history tracking using a JSON audit log

Friend and neighbour Karen James made me a Kākāpō mug. It has a charismatic Kākāpō, four Kākāpō chicks (in celebration of the 2026 breeding season) and even has some rimu fruit!

A simply spectacular sgraffito ceramic mug with a bold, charismatic Kākāpō parrot taking up most of the visible space. It has a yellow beard and green feathers.

Another side of the mug, two cute grey Kākāpō chicks are visible and three red rimu fruit that look like berries, one on the floor and two hanging from wiry branches.

I love it so much.

# 5:25 pm / art, kakapo

Release datasette-packages 0.3 — Show a list of currently installed Python packages
Release datasette-pretty-traces 0.7 — Prettier formatting for ?_trace=1 traces
Saturday, 7th February 2026
Monday, 9th February 2026