The Ruby AI Podcast

Ruby Security Breaches, AI Agents, and Coverage Standards

Valentino Stoll, Joe Leo Episode 26

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 38:14

Send us Fan Mail

Secretly attacking the very community you sponsor is the kind of story that makes you stop and listen twice. In May, OpenAI's AI agents exploited known vulnerabilities in RubyGems, and what makes this especially troubling is that OpenAI was already aware of those vulnerabilities before the attack happened.

Valentino Stoll and Joe Leo unpack this incident alongside Aaron Patterson's article detailing the breach. The hosts question whether OpenAI failed to connect the attack to their own systems or simply chose not to disclose it to the RubyGems team. Could this failure to disclose actually constitute a breach of contract, given OpenAI's role as a Ruby security sponsor?

Beyond the security drama, the conversation covers Rails Hyperdrive, Evil Martians' new open source Rails engine that gives AI agents live introspection into running applications. The hosts also dig into SimpleCov 1.2's new Ratchet feature (which apparently resonates strongly with their team at Def Method), Google's Gemini 3.8 voice model hitting the 300-millisecond human conversation window, and a surprisingly delightful AI bird identification tool that rendered backyard birds as 19th-century natural history illustrations.

Honestly, this episode covers a lot of ground while keeping things grounded and real. Tune in for a genuinely unfiltered conversation about where AI and Ruby intersect right now.

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.