
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
A cat that babysits your AI agent so you don't have to. While Claude works, the cat sits on your terminal; when you're needed, the cat gets up.
A cat that babysits your AI agent, so you don't have to.
While Claude works, a real kitten sits on your terminal and keeps watch.
The moment you're needed — permission prompt, question, done — it rears up, meows, and steps aside.
One kitten, one continuous take — not a sprite sheet (see the FAQ for how it was made). By default catsit never touches your input; --guard is opt-in.
Full-quality kitten in kitty · Ghostty · WezTerm · iTerm2 — every other terminal gets the lo-fi living cat.
One continuous performance, one kitten — every transition connects.
| agent starts working walks in, settles down ![]() | still working sits and waits — if the cat is calm, you're not needed ![]() | 60s without your input curls up for a nap ![]() |
| you touch a key wakes up the slow way: yawn, stretch, sit ![]() | you're needed rears up with a meow (+ terminal bell) ![]() | steps aside walks off — an empty screen means it's your turn ![]() |
npx catsit --demo
Run it in kitty, Ghostty, WezTerm, or iTerm2 to meet the full-quality kitten. Anywhere else (Terminal.app, VS Code, tmux…) you get the lo-fi half-block version — same cat, chunkier pixels.
npx catsit claude
That's the whole setup. No config files, no hooks, no permissions to grant.
Agents made us babysitters. You can't look away — it might need a permission right now — so you sit there, watching a spinner, guarding a process that doesn't need you 95% of the time.
catsit inverts the notification. The cat's presence is the signal:
| The cat... | means |
|---|---|
| 🐈 walks in and sits down | the agent is working. You're not needed. Go do something else. |
| 😴 curls up asleep | you've been away a while. Still handled. |
| 🥱 wakes up with a yawn | you touched a key — it noticed, that's all. |
| ❗ rears up, meows, steps aside | permission prompt / question / finished — your turn. |
If you can see the cat, you can ignore the terminal. That's the deal.
By default catsit is watch-only: typing, message queueing, steering mid-task — every keystroke reaches your agent exactly as it would without catsit. The cat is pure signal.
--guard: gatekeeper mode (opt-in)Want the cat to actually stop you from micromanaging? catsit --guard claude:
🐟 hell…), so a blocked key
never looks like a bug. The first catch comes with a hint:
guarding · ctrl+g to shoo.ctrl+c, ctrl+d, esc, arrows, every control key — always pass
through instantly, even in guard mode.ctrl+g shoos the cat away for the rest of the session.| Terminal | You get |
|---|---|
| kitty, Ghostty, WezTerm, iTerm2 3.6+ | a real kitten — one continuous filmed performance floating above the text (kitty graphics protocol): it walks in, sits down, waits, rears up in a meow, and walks off |
| everything else (incl. tmux, VS Code, Terminal.app) | the same living kitten in chunky truecolor half-blocks — lo-fi, but it still walks, naps, and meows |
NO_COLOR / dumb terminals | a humble kaomoji (=˘ω˘=) |
catsit wraps your agent in a PTY and forwards every byte verbatim, while
mirroring the screen into a headless terminal (@xterm/headless).
When the cat is visible, each output flush becomes one atomic
repair → app bytes → cat → cursor restore batch inside a synchronized
update — the cat and the app can't corrupt each other, and nothing ever leaks
into your scrollback.
Working / needs-you state is fused from two channels: screen patterns
(ported from ccmanager's
production-tested detectors, MIT) and the Claude Code session transcript
(~/.claude/projects/…), whose turn_duration record is the reliable
"turn ended" signal. Permission prompts are detected from the screen itself.
Two runtime dependencies. Node 20+. macOS & Linux.
catsit <command> [args...] wrap any agent CLI (claude today; more soon)
catsit --demo bundled fake agent, for trying it out (guard on)
--guard gatekeeper mode: the cat swallows typing while
the agent works (ctrl+g shoos it)
--no-cat no overlay at all
--quiet no bell when the cat gets up
Is that a real cat? It's one continuous AI-generated performance (Kling) of one kitten on a green screen that doesn't exist — every state was generated with its first frame pinned to the previous state's last frame, so it never cuts, teleports, or slides. Details in assets/cat-frames/CREDITS.md.
Why "catsit"? The cat sits on your terminal, and it cat-sits your agent.
Can I still queue messages while Claude works? Yes — the default mode
never intercepts input, so typing-to-queue and steering work untouched.
--guard exists precisely for when you want to be stopped.
Codex / Gemini CLI / opencode? Planned — the detector is an interface, and the transcript channel is Claude-specific but optional. PRs welcome.
Windows? Not yet (ConPTY port planned).
Does it slow the agent down? Compositing costs ~0.1 ms per frame and nothing at all while the cat is off screen.
The "cute thing physically intervenes" mechanic was inspired by Cat Gatekeeper by ZOKUZOKU — a giant cat that blocks your doomscrolling. catsit is an independent project; different cat, different problem: it guards the agent, from you.
The kitten itself is an AI-generated continuous performance (Kling), cut into seamlessly chained beats — see assets/cat-frames/CREDITS.md. Terminals without graphics support play the same beats from a pre-baked low-res grid (half.bin) as half-block cells.
MIT © JinHyuk Sung
FAQs
A cat that babysits your AI agent so you don't have to. While Claude works, the cat sits on your terminal; when you're needed, the cat gets up.
The npm package catsit receives a total of 5 weekly downloads. As such, catsit popularity was classified as not popular.
We found that catsit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.