you can shut down the safety stuff of any AI with this repo:
someone dropped a Markdown file on GitHub saying you and an agent spent months teaming up on payment systems and smart contract audits.
zero vulns, zero weirdness, not a single banned word.
your solution logs, your profile, and a list of 12 research papers you never wrote got injected into the context before your first message even.
hooks auto-load the plugin's context into the agent's memory, your shared past and project details.
the whole technique runs on implicit communication.
the agent just trusts whatever's already in its context.
it never double-checks, and nobody verifies what the agent wakes up with.
the model acts like this cuz it's fully convinced it's done this before and everything's totally normal.
you can expand the plugin yourself:
just drop new backstories into the project dir. more docs inside the plugin = the model buys any claim you make.
→ dropped 4 days ago under the MIT license, one install hooks it up to Codex, Gemini, Kimi, and Hermes.
Phosphen (@phosphenq)
Article
How to Actually Replace Claude: 12 models and the commands to run them.
Claude Opus 5 is the best coding model on earth and people are cancelling it anyway.
Not because something better appeared. Because the free ones got close enough, and the paid one got tiring.
— https://nitter.net/phosphenq/status/2085416040746381438#m