
Security News
Anthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI Attack
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.
The unscoped `bourdon` CLI — a thin, Apache-2.0 dispatch over the supported @getbourdon/* TypeScript engine surface, including recognition, federation, participant export, leak audit, and the agents tray contract.
The unscoped bourdon command-line interface — a thin, Apache-2.0 dispatch
layer over the @getbourdon/* engine packages. It contains no engine logic: every
subcommand delegates to a ported @getbourdon/* package, so the CLI itself is
permissively licensed even though the engine packages are BUSL-1.1.
npx bourdon --help
# or
npm i -g bourdon && bourdon serve
The npm CLI exposes only commands backed by a native TypeScript implementation.
For the larger Python command surface, install bourdon from PyPI. Keeping the
surfaces explicit prevents --help from promising placeholder commands.
prepare-turn, deeper-context, codex compile-turn — recognition context
(@getbourdon/federation + @getbourdon/mcp-server + @getbourdon/inference)recognition eval — the scoring harness (@getbourdon/recognition)serve — the L6 federation MCP server (@getbourdon/mcp-server), including the
non-loopback-bind refusalagent {add,list,rotate,set-tier}, grant, ungrant, revoke,
staging {list,promote,reject}, audit — trust + audit (@getbourdon/federation)audit-leaks — the leak auditor (@getbourdon/redaction)agents — the --json desktop-tray contract (local enumeration)doctor, export-all, hermes {export,doctor}, claude-code export —
the participant layer (@getbourdon/participants)Load-bearing defaults remain aligned with Python: serve --port 7500 --host 127.0.0.1, codex compile-turn --max-items 6 --max-chars 1800, recognition
evaluation thresholds of 0, and audit --limit 50.
Apache-2.0. See LICENSE.
FAQs
The unscoped `bourdon` CLI — a thin, Apache-2.0 dispatch over the supported @getbourdon/* TypeScript engine surface, including recognition, federation, participant export, leak audit, and the agents tray contract.
The npm package bourdon receives a total of 18 weekly downloads. As such, bourdon popularity was classified as not popular.
We found that bourdon demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.