
Prizm — One API key. Every top AI model.
One API key to generate videos, images, and voice with multiple top AI models.
jking413 · HN
Prizm – One API key for every top AI video, image and voice model
The full gallery
Tech stack
26 projects

One API key to generate videos, images, and voice with multiple top AI models.
jking413 · HN
Prizm – One API key for every top AI video, image and voice model

Chat with AI agents to scan web apps and APIs for security vulnerabilities.
@SableOffensive · X
Building Sable. An AaaS where specialized AI security agents perform penetration testing for web apps and APIs, helping teams find vulnerabilities before they reach production.

Scan vibecoded apps for security vulnerabilities including exposed keys, broken authentication, and missing row-level security.
@MrBallaz · X
Protect your vibe-coded app

Create scoped cryptographic capabilities and verify actions offline.
@baronfud · X

Detect if your LLM API has been model-swapped or degraded with 6 deterministic probes.
cocodot LLM 降智检测 — 免费的 LLM API「降智/偷换模型」在线检测:填入任意 OpenAI 兼容端点的 base_url 和临时 API Key,跑 6 项探针(模型声明、动态题、能力完整性等)生成分项报告;Key 仅用于当次检测、不落库不留存,检测方法[开源](https://github.com/cocodot2026/cocodot-llmprobe)

Scans live web apps for security vulnerabilities like exposed keys and open databases in 60 seconds.
@guhanvenkaty · X
Tako's free preview is live: Paste your URL, get a security verdict on your vibe-coded app in 60s. Not an AI wrapper: it fires real requests and PROVES exposure, pulling data from your open DB with no login. Scanning puts you on the early-access waitlist.

Converts CVE vulnerability data into machine-readable risk signals for security automation.
robert_marshall5 · Product Hunt
attestd CVE and supply chain risk signals for autonomous AI agents.

Security middleware that detects prompt injection, persona hijacking, and data exfiltration for AI agents.
@SecraHQ · X

Search leads, find emails, and enrich contacts with a single API key.
@zeynepavann · X
Thank you to everyone who joined our "map your TAM from the terminal" session with last week. We built live in the terminal using Claude Code and the MCP. I wrote up the whole thing afterwards. The seven stages, why each one exists, what to do with the list once you have it, and the outreach half we covered at the end. The recording is linked inside. The skill is public too, so you can run it on your closed-won book. You bring your own accounts; the engine does the expansion, scoring, and contact-finding. Comment "TAM" and I'll send you both skill and guide.

Find security holes in your AI-built app before hackers do. StackSecured scans for exposed keys, injection flaws, CVEs and more — with copy-paste fixes.
@djdeepakjha · X
AI can build your startup in days. But who checks the security? Public configs. Weak APIs. Exposed secrets. If AI built your app, scan it before someone else does. 🔒 StackSecured — security assessment #CyberSecurity #VibeCoding #AppSecurity

Permanent webhook endpoints and instant HTTPS tunnels for developers and AI agents.
@BinaryScriptar · X
Introducing OtterKit. Always-on webhook endpoints and instant tunnels, built for developers and their AI agents. It started with a problem I kept hitting: every time my coding agent needed to test a Stripe or GitHub webhook, it had to open a tunnel. What OtterKit does • Permanent webhook URLs that answer senders 24/7 with the status, body and headers you choose, verify signatures on arrival (Stripe, GitHub, Shopify, Slack and 12 more), store full history, and forward matching events to your app, signed and retried • Instant HTTPS tunnels to any local port in one command, stable subdomains, auto stop, basic auth • Replay any captured request, edit the payload, re sign it, fire it at your local handler • Pulses: scheduled HTTP calls and dead man's switches with email alerts • Payload drift detection: baseline the JSON shape per event type, get emailed when a provider changes it • Custom domains ( and an email inbox on the same endpoint • A

Give AI agents YouTube answers they can cite. Search, ask, and verify claims with source quotes and exact timestamps via REST API or MCP.
@JanGrafX · X