BrokeIt - Trending Repos · All episodes: ↗

Vibecoded fuzzer bug, AI slop rejected, Trump blacklisting overturned

2026-08-28 · 7 min

Listen · Apple Podcasts Listen · Spotify

Stories covered

Transcript

Intro

Sam: The US government tried to blacklist one of the world's biggest AI labs... based on an intelligence report they later admitted was just plain wrong.

Kai: I'm Kai.

Sam: And I'm Sam.

Kai: And this is Builder vs. Skeptic! It's Friday, August 28th, 2026.

Sam: We've got a great show for you today, digging into the wild world of open source and dev tools.

Kai: A federal judge just handed the government a stunning defeat in its fight with AI giant Anthropic.

Sam: And we're hearing from open-source maintainers who are just drowning in low-quality, AI-generated pull requests.

Kai: Plus: a security researcher 'vibecoded' their way to a major bug in the FFmpeg media library.

Judge Rules Trump Administration’s Blacklisting of Anthropic Was Illegal

Kai: So, Sam, let's talk about Anthropic. A U.S. District Judge just ruled the Trump administration's 2024 decision to blacklist them was illegal.

Sam: Illegal and, it turns out, completely baseless. The ruling called the blacklisting 'arbitrary and capricious,' which basically means the government broke its own rules.

Kai: Pretty much legalese for 'you can't just do that.' As a reminder, this put Anthropic on the Entity List—usually reserved for national security threats—barring U.S. companies from doing business with them.

Sam: And the whole justification for this was a single intelligence report about Claude's potential for 'malicious persuasion'… a report the agency itself later retracted.

Kai: So the government broke its own rules to ban an American AI company based on faulty intel. That is wild.

Sam: It's a spectacular own-goal. The government looks incompetent, and they've handed Anthropic a massive PR win, basically making them martyrs.

Kai: So what does this mean for Anthropic now? Are the floodgates opening for massive government contracts?

Sam: Probably. But the bigger question is what this means for you, the developer. It shows just how quickly the political winds can turn on AI. Your company's tech could be labeled a 'threat' on a whim.

Kai: It's a warning shot for the whole industry. Today you're a darling, tomorrow you're on a blacklist because of one bad report.

Sam: Exactly. The ruling is a win for due process, but the fact it had to happen at all is the real story.

Please stop flooding our projects with AI slop to furnish your CV

Sam: Alright, let's shift from the geopolitical to the just plain annoying. A post from developer Neil Alexander is blowing up. The title says it all: 'Please stop flooding our projects with AI slop to furnish your CV.'

Kai: [laughs] Okay, I can feel the pain in that title. He's talking about people using ChatGPT or other LLMs to generate 'contributions' to open-source projects, right?

Sam: Exactly. People are making tiny, useless changes—like adding a comment that just restates the function name, or 'fixing' typos that aren't typos—all to pad their GitHub contribution graph.

Kai: I mean, I get the impulse. Juniors are told 'contribute to open source' to get a job. This seems like a shortcut.

Sam: It's not a shortcut, it's a burden. Maintainers have to waste their time sifting through useless PRs that often make the code worse. The signal-to-noise ratio is shot.

Kai: Is it really that bad? Can't the AI find some legitimate small fixes?

Sam: Rarely. He gives examples of an AI changing 'colour' to 'color' in a UK-based project, or adding comments that are just flat-out wrong. It's performative work, and it's burning out the real contributors.

Kai: So the takeaway for aspiring devs is simple: don't do this. One thoughtful pull request that fixes a real issue is worth more than a thousand of these AI-generated junk PRs.

Sam: And for hiring managers: the green-square contribution graph is officially a compromised metric. You have to actually click and see if the work is real.

Kai: It's the enshittification of open source contributions. It's just... [beat] a mess.

We found a division by zero bug in FFmpeg with a vibecoded fuzzer

Kai: Alright, on to a bug report with what might be the greatest title all year: 'We found a division by zero bug in FFmpeg with a vibecoded fuzzer.'

Sam: [dry] 'Vibecoded.' Is that what we're calling hacking with no plan now?

Kai: [laughs] Pretty much! So, a fuzzer throws tons of random data at a program to find crashes. This researcher was building one for FFmpeg—which is basically the library for handling audio and video.

Sam: Right, it's used in everything from VLC media player to YouTube and Netflix. A bug in FFmpeg is a very big deal.

Kai: And instead of some rigid process, they just 'vibecoded' it—tweaking the fuzzer based on pure intuition. And it worked! They found a critical division-by-zero error.

Sam: Which, to be clear, could crash any application that tries to process a specially crafted malicious video file. That's a classic denial-of-service vector.

Kai: So, the takeaway here is pretty clear. If you use FFmpeg, go update your dependencies. Seriously, right now.

Sam: And it's a great reminder that not all discovery is systematic. Sometimes just 'vibecoding'—following your intuition—can find bugs that structured methods miss. It's a total win for the hacker mindset.

Kai: I love it. It's the art, not just the science, of security research.

Sam: [sighs] I'm going to have to add 'Proficient in Vibecoding' to my resume, aren't I?

Kai: So, to recap our top stories: A judge ruled the government's blacklisting of Anthropic was illegal, setting a major precedent for the AI industry.

Sam: We covered how open-source maintainers are drowning in AI-generated 'slop' from people trying to pad their resumes.

Kai: And a researcher proved that 'following the vibes' is a legitimate way to find critical security bugs in core internet infrastructure.

Kai: Before we go, Sam, a little historical note. On this day in 1963, Martin Luther King Jr. delivered his 'I Have a Dream' speech.

Sam: I have a dream... that one day pull requests will be judged not by the speed of their generation, but by the content of their character.

Kai: [laughs] You had to, didn't you? Perfect.

Kai: That's our show for Friday, August 28th, 2026! We'll be back on Monday.

Sam: Until then, code with character, not just vibes. See you then.

This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.