Shay Elmualem's Avatar

Shay Elmualem

@norbin.bsky.social

Curious mind with a passion for always-learning: DevOps, Infra, Security, AI.

882 Followers  |  422 Following  |  27 Posts  |  Joined: 17.11.2024  |  1.6439

Latest posts by norbin.bsky.social on Bluesky

Everything including a demo is in the repo above so feel free to check it out - I included a detailed readme that should help make things clearer as well:

If you have any questions or want to chat about this, DMs are open ๐Ÿš€.

18.02.2025 12:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

3. Trivy: Performs security scans on the project to identify vulnerabilities and suggests fixes.

18.02.2025 12:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

2. MCP Server: Acts as an intermediary, receiving requests from the MCP client and orchestrating security scans and fixes by interfacing with Trivy.

18.02.2025 12:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

In this project, two tools are exposed: one for initiating Trivy scans and another for applying fixes. the LLM can choose when to use them based on its context.

18.02.2025 12:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

How does it work?

1. Cursor IDE (MCP Client): Serves as the development environment where code changes occur. With MCP support, Cursor's agent (Composer) has access to MCP tools.

18.02.2025 12:02 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
GitHub - norbinsh/cursor-mcp-trivy: A Model Context Protocol (MCP) server that provides Trivy security scanning capabilities through a standardized interface. A Model Context Protocol (MCP) server that provides Trivy security scanning capabilities through a standardized interface. - norbinsh/cursor-mcp-trivy

Sharing a quick proof-of-concept project: Cursor-MCP-Trivy.

I put together an MCP server that leverages trivy to scan the active cursor project for security vulnerabilities whenever cursor's agent (composer) changes a dependency file, e.g adding a new dependency.

github.com/norbinsh/cur...

18.02.2025 12:02 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Cursorโ€™s Privacy Mode starts OFF by default in the IDE, because clearly, they think sharing is caring. ๐Ÿ˜…

Check your settings and decide what works for you.

www.cursor.com/security#inf...

Good luck!

20.01.2025 07:07 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

Using chatgpt new tasks feature as a website availability tool ๐Ÿ˜†

17.01.2025 10:23 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

browser-use is pretty cool!
this demo's repo i setup is here github.com/norbinsh/kub...

17.01.2025 10:13 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
gitcicd.com Your GitHub Actions, Analyzed.

gitcicd.com

Small platform i built you can use to analyze a github repo for actions workflow potential risks, give it a go! ๐Ÿค˜

13.01.2025 21:25 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Introduction - Model Context Protocol Get started with the Model Context Protocol (MCP)

The Model Context Protocol (MCP) is an open standard for giving large language models secure, controlled access to tools and data sources.

"Think of MCP like a USB-C port for AI applications."

modelcontextprotocol.io/introduction

05.01.2025 16:45 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitDiagram - Repository to Diagram in Seconds Turn any GitHub repository into an interactive diagram for visualization.

gitdiagram.com

This tool will generate a mermaid diagram from a git(hub) repository.

04.01.2025 09:51 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

DSPy from Stanford NLP: a Python library for building multi-step LLM pipelines and prompt optimization.

dspy.ai

See in my attached example how it takes a tiny one-liner prompt, convert it (using llm as well) into sub questions - answer them - summarize, and return a final answer.

29.12.2024 17:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

5. Regulation should focus on the capabilities and actions of the entire system, not just the llm itself.

27.12.2024 15:18 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

4. Data-driven optimization techniques (like those offered by dsp ai) can help you automatically find the best prompting and sampling strategies for your system.

27.12.2024 15:18 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

3. Even small language models can outperform giant ones when they are part of a well-designed system.

27.12.2024 15:18 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

2. A powerful llm is useless without a robust system to support it. This includes:

- Carefully engineered prompting strategies

- Effective sampling methods for text generation

- Integration with relevant tools (like databases, and web access)

27.12.2024 15:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Interesting take on how we often over-emphasizes llms while neglecting the important role of building complete AI systems:

www.youtube.com/watch?v=vRTc...

1. The complete system running it, and not just the llm itself, are the key to unlocking the true potential of AI.

27.12.2024 15:18 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Some decent AI related "freebies" @ www.aiengineerpack.com - I am not affiliated with that site, just sharing in case and it'll help some others as well, grabbed an annual Perplexity pro sub for no cost. Good luck! (Oh and... always best to remove requested access once you are "done" with it).

11.12.2024 21:08 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Running terraform plan on untrusted code isnโ€™t as safe as it seems. Most ci setups I know would allow developers to do this on the PR phase, before even submitting the PR to a code review.
good read: snyk.io/blog/gitflop...

09.12.2024 22:42 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Day 1 Livestream with Paige Bailey โ€“ 5-Day Gen AI Intensive Course | Kaggle
YouTube video by Kaggle Day 1 Livestream with Paige Bailey โ€“ 5-Day Gen AI Intensive Course | Kaggle

Check out the first day live stream here if interested youtu.be/kpRyiJUUFxY?...

07.12.2024 23:35 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Google and Kaggle have launched a comprehensive, no-cost Generative AI course. Each day focuses on key topics:

โ€ข Day 1: Foundational Models & Prompt Engineering
โ€ข Day 2: Embeddings and Vector Databases
โ€ข Day 3: Generative AI Agents
โ€ข Day 4: Domain-Specific LLMs
โ€ข Day 5: MLOps for Generative AI

07.12.2024 23:35 โ€” ๐Ÿ‘ 13    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

technical, not skip any details, and sharing with it what is my purpose and why i would like this podcast. (e.g to learn about a subject or whatever the reason is).

07.12.2024 22:06 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

some relevant youtube videos, and some whitepapersand all put together, came out great. I really like how u can mix these sources together and just listen to the overall summary. also I noticed the instructions u can provide to the podcast generation request makes a difference. i ask it to be

07.12.2024 22:06 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

There are many! But for instance, I wanted to learn more about online payments from a system design perspective. So i went ahead and created a new collection, and pushed in quite a few relevant API docs pages from stripe, some relevant blog posts from their engineering blog, as well as

07.12.2024 22:06 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Been using Google's "notebooklm" almost daily to โ€œlistenโ€ to whitepapers or get quick intros to new topics with its podcast feature. Itโ€™s my go-to for deep dives while on the move. free and super convenient!

06.12.2024 17:06 โ€” ๐Ÿ‘ 13    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Screenshot of AWS documentation page titled โ€œModel distillation in Amazon Bedrock.โ€ The text explains the process of transferring knowledge from a teacher model to a student model using synthetic data. The page includes a โ€œFocus modeโ€ toggle and text size adjustment slider on the right sidebar.

Screenshot of AWS documentation page titled โ€œModel distillation in Amazon Bedrock.โ€ The text explains the process of transferring knowledge from a teacher model to a student model using synthetic data. The page includes a โ€œFocus modeโ€ toggle and text size adjustment slider on the right sidebar.

Shoutout to AWS for the โ€˜Focus modeโ€™ in their docs โ€“ a simple but game-changing feature for reading without distractions. More platforms should definitely follow this.

06.12.2024 11:21 โ€” ๐Ÿ‘ 7    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@norbin is following 18 prominent accounts