
Hosted by AI Frankly · EN

A note before you listen: this episode's deep dive was produced in NotebookLM. NotebookLM is our executive producer. It also mispronounces Ollama as "Alama" about forty times. We use AI to talk about AI. When the AI hits its limit, we point at it instead of hiding it.---Three recipes for a voice assistant that doesn't have to phone home.Recipe 1 takes ten minutes — a browser-based Jarvis you can run today.Recipe 2 takes thirty minutes — a one-command local install with Ollama.Recipe 3 takes a weekend — Home Assistant Voice PE, replacing Alexa entirely.I built one. I read the receipts on two more. Here's what each actually costs in time, money, and trade-offs.Read the full article: https://aifrankly.substack.com/p/the-local-jarvisCHAPTERS:00:00 - The Smart Home Illusion03:30 - Recipe 1: The Browser Jarvis07:45 - The Browser API Privacy Trap12:00 - Recipe 2: The One-Command Jarvis15:30 - Why It Knows When You Stop Talking18:15 - The Hardware Reality Check22:00 - Recipe 3: The Whole-Home Jarvis26:45 - The Frustrating Five-Second Delay30:00 - The Honest Bill32:15 - The Partner Test34:30 - Local Is Not a Security Policy36:45 - Auditing Microphone Vulnerabilities40:30 - High-End and Cloud Alternatives44:15 - Am I Tony Stark?RECEIPTS:- Ollama: https://ollama.com- Home Assistant Voice PE: https://www.home-assistant.io/voice_control/- Kokoro TTS: https://github.com/hexgrad/kokoro- NetworkChuck's local AI tutorials: youtube.com/@NetworkChuck- Eddie Chen's voice assistant builds: youtube.com/@EddieChen- Smart Home Solver's HA Voice PE testing: youtube.com/@SmartHomeSolverAI Frankly. Built from parts. Owned outright. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com

MCP 202: The Missing Control Layer Between Your Agents and Your Tools.Security researchers have a name for what's happening inside most enterprise AI deployments right now: NeighborJack.This episode breaks down what NeighborJack is, why vendors are racing to sell you MCP Security Gateways, and the four questions every operator should ask about any MCP server they're running.Full article: https://aifrankly.substack.com/p/someone-needs-to-sit-between-your-b31Watch on YouTube: https://youtu.be/TKiDj4vH4VcSubscribe free at aifrankly.substack.com.AI Frankly: Build the layer or buy the breach. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com

Half a million lines of source code leaked. A federal court fight the same week. And the thing the internet actually remembered was an ASCII owl named Zornix.This episode covers what EP.15 and EP.16 didn't -- the cultural artifact that came out of the worst press week in Anthropic's history.Download the Python script (see all 18 buddies, free): https://tinyurl.com/zornixRead the full article: https://aifrankly.substack.com/p/the-week-anthropic-leaked-the-internetEP.15 -- Anthropic Did It Again: https://aifrankly.substack.com/p/anthropic-did-it-againEP.16 -- The Blueprints Are Public Now: https://aifrankly.substack.com/p/the-blueprints-are-public-now00:00 - Introduction: The Dissonance 03:00 - Timeline of the Leak 07:00 - The Mechanics of Minification 12:00 - The Discovery (30 Seconds) 16:00 - Unpacking KAIROS: The Autonomous Daemon 21:00 - Undercover Mode 26:00 - The Compaction Attack Vector 30:00 - The Bash Security Parser Differential 34:00 - The Axios NPM Supply Chain Collision 38:00 - Mitigation Protocols 42:00 - The Pentagon Lawsuit and Responsible Scaling 45:00 - The Verification Agent 48:00 - The Phenomenon of Zornix 50:00 - ConclusionSubscribe free on Substack: https://aifrankly.substack.com Apple Podcasts: https://podcasts.apple.com/us/podcast/ai-frankly/id1873177211 Spotify: https://open.spotify.com/show/6iEuQyxwLeUDsR67QleSTnAI Frankly: aifrankly.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com

Anthropic refused defense contract terms that would have allowed military use of Claude. A federal judge called the Pentagon's response classic First Amendment retaliation. Seven days later, the complete source architecture of Claude Code was permanently mirrored across GitHub.This is the full deep dive. 41 minutes covering the Pentagon lawsuit, Judge Rita Lin's ruling, KAIROS, Undercover Mode, the compaction attack vector, and what it means for enterprise IT practitioners right now.What we cover:- The Pentagon dispute and Judge Rita Lin's ruling- KAIROS -- the fully built autonomous daemon nobody announced- Undercover Mode and the irony at the center of the story- The compaction attack vector and context poisoning- The bash security parser differential- The Clean Room Clone and the IP legal paradox- The IPO stakes and what this means for enterprise trustWatch on YouTube: https://youtu.be/0L2isrk88y0Read the full article: https://open.substack.com/pub/aifrankly/p/the-blueprints-are-public-nowFind everything at aifrankly.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com

On March 31, 2026, an intern at a blockchain security firm checked the npm registry for the newest release of Claude Code. Within 30 seconds he found a 59.8MB source map file that should never have shipped to production. Inside: 512,000 lines of TypeScript, 1,900 files, and the complete architecture of one of the most important AI developer tools ever built.This is the full deep dive. 45 minutes covering the mechanics of how it happened, what the leaked source code actually revealed, and the concurrent Axios supply chain attack that hit the same morning.What we cover:How a single missing line in a config file exposed the entire codebaseKAIROS: the fully built autonomous daemon mode Anthropic never announcedThe Buddy virtual pet system and the hex-encoded duckUndercover Mode and the grand irony at the center of this storyThe Axios npm supply chain attack and who is actually at operational riskThe operator verdict: Watch, Act Now, AdoptWatch on YouTube: https://youtu.be/XGv8sW2NS0kRead the full article: https://open.substack.com/pub/aifrankly/p/anthropic-did-it-againFind everything at aifrankly.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com

Anthropic shipped six major products in March 2026. A federal lawsuit over autonomous weapons. And a quietly revised safety pledge with no hard stop. All in the same 30 days.In this episode we unpack the full operator picture -- what shipped, what it means for enterprise security, and what every IT practitioner needs to know before deploying any of it.In this episode:Claude Computer Use and the endpoint security risk nobody has filed a ticket for yetClaude Code Auto Mode and the shadow IT threat of ChannelsThe death of RAG pipelines with 1M context at standard pricingThe $100M partner network with the big four consulting firmsThe RSP revision that removed the hard stopThe Pentagon lawsuit and what it means for your vendor risk assessmentOperator Verdict: Adopt, Watch, Skip -- exactly what to do with each updateFind everything at aifrankly.com Watch on YouTube: https://youtu.be/19wv2Pqa0Eg Listen on Apple Podcasts and Spotify -- search AI Frankly This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com

Nobody hacked Anthropic. A misconfigured CMS left roughly 3,000 unpublished assets publicly accessible. One described a new model nobody was supposed to see yet. Cybersecurity stocks dropped billions in a single session. Not a breach. A config error.In this episode we unpack the full anatomy of the incident, what actually leaked, why Wall Street panicked, and what it means for every enterprise IT team managing content and documentation systems right now.In this episode:The anatomy of the CMS misconfigurationWhat leaked: Claude Mythos and the Capybara tierWhy cybersecurity stocks dropped billions in one sessionWhat Anthropic actually shipped in March 2026Claude Computer Use reaches general availabilityThe 15-minute rogue audit every IT team should run todayFind everything at aifrankly.com Subscribe free on Substack Watch on YouTube: https://youtu.be/4zheW7QJ4k4 Listen on Apple Podcasts and Spotify -- search AI Frankly This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com

MCP hit 30 CVEs in 60 days. 38 percent of public MCP servers had zero authentication. The protocol works. The governance layer doesn't exist yet.This episode covers the real threat model for MCP in production: three villains, five layers of defense, and a six-question self-audit you can run against any MCP server today.MCP didn't break your security model. It exposed that you didn't have one.Topics covered:- The incident that should have been an incident report- The Content Injector, the Supply Chain Attacker, and the Over-Helpful Agent- Five layers of defense: identity, supply chain, isolation, policy, and monitoring- The governance maturity model: Stage 0 through Stage 3- The six-question self-auditRead the full article: https://aifrankly.substack.com/p/mcp-201-the-governance-deficitFull MCP Security Series: https://aifrankly.com/mcp-securityAI Frankly: Are We Having Fun Yet! This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com

Bonus Episode - Season 1Anthropic didn't have a week. They had a product conference that nobody announced.This deep dive breaks down everything that shipped in March 2026, sorted by who it actually affects: everyday Claude users, developers building with Claude Code, and enterprise operators responsible for securing all of it.What we cover:Persistent memory and the governance nightmareSonnet 4.6 and the 1M token context windowWhy RAG pipelines are becoming obsoleteClaude in Chrome and the Cowork native host conflictThe /loop command and runaway agent scenariosClaude Code Channels and the Telegram attack vectorVoice mode and generating bad code fasterClaude Code Security grading its own homeworkCowork on Desktop and why the VM sandbox failsSuperpowers, Dispatch, and awesome-agent-skillsThe IT velocity gap that is now permanentThe memory test: ask Claude what it remembersFree resource mentioned in this episode: claudehq.app - no account requiredFull article: https://open.substack.com/pub/aifrankly/p/this-already-hit-production-yourAI Frankly: The memo your IT team didn't get. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com

Here are the show notes:MCP 103: I Gave Claude Code Someone Else's Tools (Full Deep Dive) Season 1, Episode 11This week I wired three public MCP servers into Claude Code and gave it one sentence. It touched GitHub, n8n, and Notion without being asked which ones to use. No ticket filed. No audit trail.This episode covers the full lab report: what I connected, what Claude did without being told, and why the governance conversation is happening after the fact in most enterprises right now.Topics covered:GitHub MCP: read-only access and unprompted anomaly detectionn8n MCP: autonomous workflow chaining across three automationsNotion MCP: persistent memory that survives the conversation windowWhat happened when all three were connected simultaneouslyThe connectors panel moment: that list is your attack surfaceGlasses ON: enterprise governance gapGlasses OFF: the Minecraft PC Standard still appliesTry This Yourself: n8n, one test workflow, 30 minutesRead the full article: https://open.substack.com/pub/aifrankly/p/mcp-103-i-gave-claude-code-someoneWatch on YouTube: https://youtu.be/0idx_l2o5X0Settings:Title: MCP 103: I Gave Claude Code Someone Else's Tools (Full Deep Dive)Season 1, Episode 11, FullRSS toggle: ONSend via email: OFFNo paywallReady to upload the audio? This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit aifrankly.substack.com