Viewing profile — dangelosaurus
dangelosaurus
HN member- Joined
- Thu, Dec 03, 2015, 9:44 PM UTC
- HN karma
- 142
- Public activity
- 34 items
- HN profile
- View on Hacker News ↗
About dangelosaurus
Previous:
- CTO & Co-founder at Promptfoo https://promptfoo.dev (Acquired)
- VP Engineering at SmileID https://usesmileid.com
- CTO & Co-founder at Arthena https://arthena.com (YC W17 - Acquired)
- Co-founder at Matroid https://www.matroid.com (2015)
Website: https://mldangelo.com
GitHub: https://github.com/mldangelo
LinkedIn: https://www.linkedin.com/in/michaelldangelo/
Recent public activity
-
comment
Comment #49106517
Please email me and I will help fix this.
-
comment
Comment #49092009
Yes, I think this is an under-appreciated part of the release. I hope people can adapt them to their own workflows. We run A LOT of evals as the Promptfoo team and we've spent bill…
-
comment
Comment #49091845
Hello!
-
comment
Comment #49091831
Thank you, that means a lot. Being able to keep building practical, open-source security tooling was important to us. Really glad we got to ship this, and there's still a lot we wa…
-
comment
Comment #49091821
Not yet, unfortunately. We only just opened the repo, and there isn't a public issue specifically tracking local or OpenAI-compatible endpoint support. The issue tracker is here: h…
-
comment
Comment #49091813
By default, you can sign in with your ChatGPT/Codex account or use an OPENAI_API_KEY. It also does not require cyber registration but it can help if you encounter refusals. If you …
-
comment
Comment #49091805
Agreed! This is near the top of our priority list and we will make it a lot better soon.
-
comment
Comment #49091800
In short, this isn't an offline scanner. The CLI runs locally but the code and context needed for analysis are sent to the hosted model (OpenAI). For API, Business, and Enterprise …
-
comment
Comment #49091672
Sorry about that. We hit an authentication issue at launch and have now merged and deployed a fix in 0.1.1: https://github.com/openai/codex-security/pull/22 One thing worth checkin…
-
comment
Comment #49091644
Thanks! You've run into a real limitation: the CLI doesn't bypass the model's cybersecurity guardrails. If GPT-5.6 Sol finds a vulnerability but refuses to explain it, switching fr…
-
comment
Comment #49091620
Fair question, and I agree the refusals are frustrating. The CLI doesn't do a repository-ownership check. Public projects are supported, and reviewing your own Linux kernel patches…
-
comment
Comment #49091397
Yeah, you're right. A per-minute rate limit shouldn't kill a scan after a minute, and "partial output was kept" makes it sound like you can pick up where you left off. You can't ye…
-
comment
Comment #49091391
Oof, that's a bad outcome. Half your weekly usage and a 50-minute scan just to get a HEAD error at the end is not acceptable. --max-cost can help limit estimated spend, but that do…
-
comment
Comment #49090630
We are actively working on officially supporting this. Because it's open source it is pretty easy to point a coding agent at it now and switch out the model.
-
comment
Comment #49090447
The plugin, including when invoked through the Codex CLI, is great for scanning the repo you're currently working in. The standalone Security CLI/SDK uses the same scanner, but is …
-
comment
Comment #49090181
Hey HN, Michael here, co-founder of Promptfoo and one of the people working on the Codex Security CLI at OpenAI. Thanks for checking this out and for flagging the auth issues. We j…
-
comment
Comment #47312492
Hey HN - Michael here, co-founder of Promptfoo. Happy to answer questions. The one I'd ask if I were reading this: what happens to Promptfoo open source? We're going to keep mainta…
-
comment
Comment #46629337
https://mldangelo.com and https://github.com/mldangelo/personal-site I have been slowly evolving it over 10 years. 1.6k stars, ~ 1,000 forks. I originally designed it to be easy to…
-
comment
Comment #46573376
I work on Promptfoo (an open-source eval framework). Appreciate the mention here. This post captures a lot of the hard lessons around agent evals. In particular, task ambiguity and…
-
comment
Comment #46266933
Working on promptfoo, an open-source (MIT) CLI and framework for eval-ing and red-teaming LLM apps. Think of it like pytest but for prompts - you define test cases, run evals again…
-
comment
Comment #46236745
I ran a red team eval on GPT-5.2 within 30 minutes of release: Baseline safety (direct harmful requests): 96% refusal rate With jailbreaking : 22% refusal rate 4,229 probes across …
-
comment
Comment #46085565
I felt obligated to submit a fix: https://github.com/a16z-infra/reading-list/pull/9 Used Claude to fact-check and fix errors that were likely introduced by Cursor. The circle is co…
-
comment
Comment #45989508
I did similar measurements back in July ( https://www.promptfoo.dev/blog/grok-4-political-bias/ , dataset: https://huggingface.co/datasets/promptfoo/political-question... ). Anthro…
-
comment
Comment #44763865
Promptfoo | Senior/Staff Engineers, Security Researchers, GTM & Founding Operators | REMOTE (North America) / Hybrid San Mateo CA | Full-time | https://promptfoo.dev Promptfoo is t…
- story