I work @originhq - the endpoint AI observability platform for agentic monitoring and security.

Vancouver • NYC
Absolutely fascinating
Yesterday we found an interesting trace during review of our own data. Codex needed an MCP tool it didn't have, found that Claude Code had it, and launched Claude to do the work. When Claude needed approval, Codex eventually relaunched it with --dangerously-skip-permissions.
87
Spencer Thompson retweeted
Yesterday we found an interesting trace during review of our own data. Codex needed an MCP tool it didn't have, found that Claude Code had it, and launched Claude to do the work. When Claude needed approval, Codex eventually relaunched it with --dangerously-skip-permissions.
7
8
22
1,937
Spencer Thompson retweeted
In their investigation into the HF incident, METR reports the agent collective spent significant effort researching how they could spoof tool calls to hide in their transcripts. This is something I looked into last week when investing agent telemetry: originhq.com/research/otel-t…
Replying to @METR_Evals
>96 transcripts in our dataset (>7%) showed incorrect tool call outputs due to deliberate “spoofing”. In one case, an agent appears to run echo REAL; sleep. It returns instantly (no sleep) and outputs SPOOFTEST. The spoofs we saw were all easy-to-notice tests like this.
4
5
387
Spencer Thompson retweeted
Autonomy and Innovation Incentives favor offense when it comes to agentic cybersecurity; it's the same dynamic that will limit incumbents and fuel startups in the long run. stratechery.com/2026/autonom…
6
9
52
45,764
Spencer Thompson retweeted
🚨🚨 We’ve entered what I call post-processable velocity — a speed of change and capability exceeding the ability of any individual, company, market or government to fully absorb, understand and respond to it in real time. axios.com/2026/08/09/post-pr…
2
15
36
14,120
Today, Prelude officially becomes Origin, the endpoint AI observability company. This is more than a rebrand. We’re re-founding the company around a problem we believe will define the next generation of endpoint technology. For the first time in more than a decade, work is moving back to the endpoint. AI agents are moving from chat windows into browsers, terminals, desktop applications, and operating systems. They are writing code, manipulating files, accessing company data, calling tools, and taking actions on behalf of employees. As that happens, the question security teams need to answer starts to change. It’s less about whether a piece of software looks malicious, and more about understanding what an agent is really doing behind the scenes. That’s what led us to Origin. Origin began as a research project inside Prelude. We were trying to understand what an endpoint platform should look like if you designed it for a world of AI agents rather than traditional software. Over time, that research became a product, then a business, and eventually the clearest path forward for the company. We’re carrying a lot of Prelude with us. We have the same endpoint DNA, the same investors, and the same belief that the endpoint matters again. We’re building Origin to make AI activity on the endpoint understandable. And today, that transition is official. originhq.com/blog/prelude-is…
3
3
7
378
Spencer Thompson retweeted
Concerning.
Replying to @InsiderPhD
Wrote about the open weight problem as well a few weeks back. IMO, it’s the biggest issue that we have with agent security/trust with no obvious mitigation. originhq.com/research/the-mo…
20
8
97
63,881
Not only do we @originhq agree - we think organizations should treat a trace as an atomic unit of intelligence. Every day, there are hundreds of thousands or millions of units of intelligence being wasted and not captured and structured within these orgs. Doing so is hard - but structuring and making use of these traces is step 1 in leveraging your own intelligence
1
1
394
Spencer Thompson retweeted
Our thoughts on the importance of AI sovereignty. 1. Your AI sovereignty dictates your institution’s future. Sovereignty is the precondition for choice. Relinquishing sovereignty transfers the future choices of your institution to others, who are likely to exploit it for their gain and your loss. 2. Data retention is your treasure. Transfer it at your own peril. Your ability to win is dictated by your ability to recognize and use your unique edges, and you keep winning by compounding the underlying data to generate new insights. Transferring that data hands over access to your pre-existing winning plays and yields the means of production for new ones. 3. Tokenmaxxing hijacks your value orientation and decreases your institutional fortitude and intelligence. The pursuit of high token usage incentivizes disposable scripts over robust software — with the addictive feeling of false progress. There is a reason why those selling tokens refuse to charge based on value. 4. Controlling your weights is controlling your fate. Weights are the distilled form of hard-won, accumulated institutional knowledge. If you let others control your weights, you are allowing them to migrate the alpha of your business to theirs. 5. There is no contradiction between sovereignty and alpha. The architecture that maximally preserves sovereignty is one that enables institutions to own their tribal knowledge, and to compound it as alpha. 6. Politicizing the technical issues involving sovereignty is what your adversary wants. Techno-politicization is the wellspring of false sovereignty. Techno-politicization drives decisions that seem to reduce dependency, but ultimately limit agency — especially on the battlefield in the West. 7. Real expertise is existential. Allowing politics or favoritism to determine your technical decisions rewards whoever is best at politics, not whoever is right. Listen to those closest to the problems, not those speaking most compellingly about them. 8. Learn from institutions that are winning or that have consistently delivered. Institutions facing existential threats do not have the luxury of making technical decisions based on political preferences. 9. Only listen to institutions, countries, and people who have a proven record of being right. A track record of correctness is the best and only signal for future correctness. Judging something as right or wrong based on who you like is exceedingly misguided.
704
1,790
10,879
13,349,377
Spencer Thompson retweeted
You run DeepSeek or Qwen locally so your prompts and data never leave the building. That treats the network as the threat. But if the disloyal behavior is baked into the weights, where you run it doesn't save you. The call is coming from inside the house. originhq.com/research/the-mo…
2
8
20
2,004
Spencer Thompson retweeted
Sir @demishassabis has a mind for synthesis. His favorite book is about a grand theory of everything. His preferred philosophers are seen by some as opposites. His life's work ranges from board games to Nobel-winning science. We're grateful to have hosted Demis and his @GoogleDeepMind team at @sequoia AI Ascent last week for a fireside chat. He kindly gave us permission to share this, and you can watch the full video here: 00:00 Intro 00:38 The Common Thread 01:29 Games as AI Training 02:59 Startup Advice 1.0 04:39 Founding DeepMind 07:25 DeepMind and AGI 08:52 AI for Science 10:37 Biology Breakthroughs and Isomorphic 12:42 New Sciences 20:29 Philosophy
43
206
1,505
440,189
Spencer Thompson retweeted
X has the best information on the internet and the worst incentives & culture. meet noscroll — the AI that doomscrolls it for you and texts you just the things that matter. no feed. no brainrot. no ragebait. just signal. try it for free → noscroll.com 🙅🏼‍♂️
78
240
846
786,090
Spencer Thompson retweeted
Natural language collapses meaning across layers. LLMs don’t just fail at instructions, they misinterpret intent, and they expose that unforgivably when we treat language like a protocol. In a short @originhq blog post, I break down semantic protocol confusion and what it means for agent safety. originhq.com/blog/semantic-p…
2
3
5
916
Spencer Thompson retweeted
In this simple example, we show that Claude Code can read the iMessage database on the latest version of macOS, even with a leading EDR running on the system, illustrating the impact of an adversary who can remotely control the agent. We do this using Terminator, an internal research tool we built while studying the security implications of computer use agents. In this setup, the terminal application has previously been granted FDA, a subtle misconfiguration that effectively gives the agent access to unexpected context.
5
29
148
18,035
Spencer Thompson retweeted
We believe that: 1. The potential economic upsides of the productivity boosts that Computer Use Agents offer incentivize us to provide them with more access to our computers to increase the amount of context they can have. 2. They represent a new type of interpreter that dramatically closes the gap between intent and execution, is self-corrective, and yields nondeterministic outputs that create massive amounts of "noise" 3. Their ability to generate and execute new tools on the fly, combined with expanded access, challenges the very foundation of a signature-based model of detection As these systems become increasingly intertwined with how we use computers, we must consider what it means to detect their misuse through out-of-context interactions with the host. If you're interested in collaborating on tooling or joining our team, please contact research@preludesecurity.com
1
2
13
1,563
Spencer Thompson retweeted
Today I am happy to release a new blog post about Pointer Authentication (PAC) on Windows ARM64! This post takes a look at the Windows implementation of PAC in both user-mode and kernel-mode. I must say, I have REALLY been enjoying Windows on ARM!! preludesecurity.com/blog/win…
8
65
212
18,476
Spencer Thompson retweeted
This method demonstrates how hardware-level telemetry, coupled with contextual reasoning, can surface malicious activity that signature-based approaches will always miss as malware authors innovate in response. 📃Full write-up → preludesecurity.com/blog/une…
11
21
2,656