Simon Willison uses frontier models to audit Datasette, finds subtle security bugs
Simon Willison · rss · 2026-09-11
Datasette shipped two security releases, 1.0a39 and 0.65.4, fixing vulnerabilities that matter for any instance on the public web — especially those mixing public and private tables.
- After issues reported by Sevban Dönmez, Simon Willison and Alex Garcia ran an extensive audit with Claude Fable 5.1, GPT-5.6 and GPT-6 Astra, then spent nearly a week reviewing and fixing
- The models surfaced very subtle bugs; Willison says frontier-model security audits will now be part of all their development work
- Productive split: one person wrote automated tests exposing each issue while the other implemented the fix in a shared private repo, so two humans plus multiple coding agents reviewed every issue
More from coding & agent
- One Dollar Audit Offers AI Smart Contract Security Audits for $1 on Base — seanwbren · 2026-09-11
- SWE-Together Update: Claude Fable 5 Tops Coding Benchmark, Muse Spark 1.3 Is 5x Cheaper — shuchaobi · 2026-09-11
- GPT-6 Astra 3D Workflow: Blender MCP for Hard-Surface, TripoAI for Organic Models — majidmanzarpour · 2026-09-11
- Gemini Canvas Turns Any Google Sheet Into an App, Sparking Startup-Killing Concerns — VishnuNath · 2026-09-11
- Developer asks how to turn real codebases into instruction-to-code fine-tuning datasets — ImBadGuyInEveryStory · 2026-09-11
- Sierra Catalina proposes Context Layer: a six-step user-controlled protocol for sharing minimal context across AI agents — sierracatalina · 2026-09-11