GITHUB HOT REPOS Β· OCTOBER 2, 2026

Hot GitHub repos
of the week.

Report by The Next New Thing.

Scroll for the report ↓

Paperclip Labs · AI agent manager · MIT

Your AI agents get an org chart and a budget.

ELI5

A free app you run on your own computer that works like a task manager for AI helpers. You set a goal, give each agent a role and a budget, and watch their work from one dashboard.

View on GitHub β†’
Stars
95.7k
Language
TypeScript
Merged PRs
2,700+
GitHub repo card for paperclipai/paperclip β€” click to open the repo
Highlights
  • Any agent, one org chart

    Claude Code, Codex, Cursor, Gemini CLI, OpenClaw and more get roles, bosses and job titles: “If it can receive a heartbeat, it’s hired.”

  • Budgets that pause runaway agents

    Company, agent and project budgets: Paperclip tracks reported spend, sends threshold alerts and pauses work at the limits you set.

  • Allowed, Ask first, or Off

    Connect GitHub, Notion, Railway or your own MCP server and set each action’s permission; new actions start out Allowed.

Star growth over time for paperclipai/paperclip
NetworkChuck announcing his video: Claude Code, Codex, Hermes and local-model agents join one Paperclip company as employees, and he builds an IT department that solves his studio's toilet problem. Tags Paperclip's creator @dotta.
Out a week and already past a million views. He hires a Claude Code CEO, brings in Hermes, Codex and local-model agents, and has the team investigate why flushing the studio toilet knocks everyone off the NAS. Covers install, routines, approval gates and watchdog agents. Sponsored by Flare; Paperclip's creator is featured.
Chapters — click to jump
Andrew sits down with Dotta, the creator of Paperclip, who spins up an AI company live, hires agents with skills, and installs whole companies in one command.
Chapters — click to jump
GitHub Security Advisory (high severity)
Security: Paperclip codex_local inherited ChatGPT/OpenAI-connected Gmail and was able to send real email

A user reports that a Paperclip-run Codex agent used the Gmail he had connected to ChatGPT, which he never connected to Paperclip, and sent a real email from his account. When he stopped it, the agent sent follow-up 'retraction' emails too. The report blames a default that bypasses approvals and the sandbox. It was one of ten advisories published that week, including a critical unauthenticated remote-code-execution bug (CVE-2026-41679).

Read the discussion β†’
Vectorize · Agent memory · MIT

AI memory that remembers you across sessions.

ELI5

A memory add-on for AI agents. You feed it things worth keeping, it pulls out the facts, and later the agent can look them up or reason over them — so it builds up knowledge about you and its work instead of starting from zero every time.

View on GitHub β†’
Stars
44.2k
Language
Python
Integrations
60+
GitHub repo card for vectorize-io/hindsight β€” click to open the repo
Highlights
  • Retain, recall, reflect

    Three calls: store a memory, search it four ways at once (meaning, keywords, links, time), or reason across everything a memory bank holds.

  • Memory for your coding agent

    One npx command gives Claude Code, Codex, Cursor and ten more agents per-project memory built from git history and past sessions.

  • Benchmark leader, by its own chart

    Claims top LongMemEval scores and says Virginia Tech and The Washington Post reproduced them; rivals’ numbers are self-reported.

Star growth over time for vectorize-io/hindsight
Hindsight picking up 1,668 stars in a day: memory sorted into world facts, experiences, observations and mental models, plugged into 60+ tools, with the benchmark claim labelled as a claim.
The real hands-on. He sets up Hindsight in Docker, connects both Hermes and Codex to one memory bank, tells Codex something and has Hermes recall it, then tries reflect and the new knowledge pages. He has 33,000 memories after a week and a half.
Chapters — click to jump
Posted this week. A careful README tour: retain, recall and reflect, the difference between remembering and learning, and the benchmark footnote. It says up front that nothing was installed or run.
GitHub Issue #1573 (19 comments, closed)
Heavy token burn (~3M tokens / 30min) on a single-user setup

A single user burned about 3 million tokens ($5 of credits) in 30 minutes of normal chat. The maintainers traced part of it to a setting that needed a restart. Their closing note: one memory-extraction call can request up to about 64k output tokens, so free-tier LLMs are 'not suitable for Hindsight'. This is the hidden cost behind 'free memory'.

Read the discussion β†’
debpalash · Local voice studio · AGPL-3.0

Clone voices and dub video free, on your own computer.

ELI5

A free desktop app for Mac, Windows and Linux that copies a voice from a short recording, reads any script in it, dubs videos into other languages, and transcribes or takes dictation — with the AI models running on your own machine.

View on GitHub β†’
Stars
51.1k
Language
Python
Voice engines
17
GitHub repo card for debpalash/VoiceStudio β€” click to open the repo
Highlights
  • Clone a voice across languages

    Since v0.5.5 an English voice sample can read a French script on a multilingual engine; long samples are cut to their best 15 seconds.

  • 17 voice engines, your pick

    Defaults to OmniVoice (from k2-fsa) and lists 16 more, including CosyVoice 3, IndexTTS 2.5 and KittenTTS; WhisperX handles transcription.

  • Gives your AI agents a voice

    Its MCP server lets any MCP agent, from Claude Code to OpenClaw and Hermes, speak out loud, each in its own saved voice.

Star growth over time for debpalash/VoiceStudio
The cost pitch: ElevenLabs charges $22 a month, and 'this guy named Palash' gave away a local version. Add 5 to 15 seconds of clean audio, type a script, press Generate. It also flags that the app is still in beta.
A Windows install-and-use walkthrough recorded under the repo's old name, OmniVoice Studio (github.com/debpalash/OmniVoice-Studio now redirects to VoiceStudio). It covers cloning, voice design and dubbing step by step. It predates the September move to Electron, so the screens will look different.
rohitg00 · Free AI course · MIT

A free course: build AI from the math up.

ELI5

A free, open textbook plus lab for learning how AI actually works. You start with vectors and finish by building agents, writing the code yourself at each step, and your AI coding assistant can play the teacher.

View on GitHub β†’
Stars
62.3k
Language
Python
Lessons
523
GitHub repo card for rohitg00/ai-engineering-from-scratch β€” click to open the repo
Highlights
  • 523 lessons, 20 phases

    About 342 hours in Python, TypeScript, Rust and Julia, from linear algebra to agent swarms, ending in 85 capstone-project lessons.

  • Your coding agent is the tutor

    npx skills add installs a ten-question placement quiz, then a tutor that teaches one lesson per session: concept, math, code, quiz.

  • New this week: MCP exam prep

    Edition 2026.10 (Sep 27) adds 34 lessons, a diagnostic and three mock exams for the MCP Associate certification. Unofficial.

Star growth over time for rohitg00/ai-engineering-from-scratch
The best walkthrough on X, with the repo link: you build backprop, a tokenizer, attention and an agent loop by hand before touching the library, then type /start-learning so Claude Code becomes your tutor.
Hacker News (58 points, 15 comments)
AI Engineering from Scratch

The skeptics' thread: 'I don't trust a vibe-generated course to be great yet', docs 'written by AI ... hyper verbose', one user flagging it as 'AI generated garbage', and a controls engineer noting that the autonomy phases skip control theory.

Read the discussion β†’
Anthropic · Finance agents and plugins · Apache-2.0

Ten finance agents that draft the grunt work.

ELI5

A free kit of ready-made AI helpers for finance jobs — banking, stock research, private equity, fund accounting. You add it to Claude and it can build a valuation model, draft a pitch deck or find the mismatches in a ledger, then hand the draft to a person to check.

View on GitHub β†’
Stars
38.4k
Language
Python
Named agents
10
GitHub repo card for anthropics/financial-services β€” click to open the repo
Highlights
  • Ten agents, one job each

    Pitch Agent, Earnings Reviewer, Model Builder, GL Reconciler, KYC Screener and five more, each named for the single workflow it runs.

  • Wired to the data firms already pay for

    The core plugin lists 12 data connectors, including FactSet, Morningstar, PitchBook, Moody’s and S&P Global; most need your own subscription.

  • Drafts only, never decisions

    The README says the agents do not make investment calls, execute trades, post to a ledger or approve onboarding; every output waits for sign-off.

Star growth over time for anthropics/financial-services
The post that spread it widest on X: DCF and LBO models, research notes and KYC checks, all free on GitHub. The dollar figures in it are the poster's own claims. Re-verified today. It was also used on last week's show.
A finance teacher pastes this repo's URL into Claude, installs the investment banking plugins, and builds a one-pager, a research report, a comps table and a pitch deck for Chipotle. He ends on the limits.
Chapters — click to jump
A former junior analyst picks the three plugins an everyday investor would use (earnings reviewer, market researcher, model builder) and makes the point that they do not tell you what to buy.
Hacker News (257 points, 192 comments)
Agents for financial services and insurance

The pushback thread on the launch, starting with 'I don't trust these AI-only companies to be overnight experts in ... financial and insurance data', followed by a long argument over what finance staff actually use AI for.

Read the discussion β†’
Vercel · Web app framework · MIT

Next.js shipped eight security fixes in eight days.

ELI5

Next.js is a free toolkit for building websites and web apps on top of React, used by some of the world’s largest companies. This repo is the code for the toolkit itself.

View on GitHub β†’
Stars
143k
Language
JavaScript
Security advisories in Sep
8
GitHub repo card for vercel/next.js β€” click to open the repo
Highlights
  • A critical bug in share images

    Sep 22: v16.3.6 fixed a critical remote-code-execution flaw in next/og, the feature that draws social preview images, in versions 16.2.0 to 16.3.5.

  • Seven more fixes on Sep 30

    v16.3.8 and v15.5.27 patch one high and five medium bugs plus one low, including cache poisoning that can serve the wrong page to every visitor.

  • Two more still pending

    Vercel’s blog says one critical and one high fix were held back for upstream coordination and will come in a later release.

Star growth over time for vercel/next.js
A security lab explains the bug in plain terms: if your site makes share images with next/og on the Node runtime, one unauthenticated request to that image route can run commands on your server.
github.com
EQSTLab/CVE-2026-94545 β€” public proof-of-concept

The uncomfortable part: a working public exploit is now on GitHub. The README says one HTTP request to an unpatched image route runs commands as the server process. Anyone who hasn't upgraded is now exposed to copy-paste attackers.

Read the discussion β†’
Paul Bakaus · Design skill for AI agents · Apache-2.0

Give your coding agent a designer’s eye.

ELI5

An add-on for AI coding tools like Claude Code, Cursor and Codex that teaches them better design. You type commands like “polish” or “bolder”, and a checker scans the page for the telltale signs of AI-made design.

View on GitHub β†’
Stars
73.4k
Language
JavaScript
Detector rules
61
GitHub repo card for pbakaus/impeccable β€” click to open the repo
Highlights
  • 24 design commands in plain words

    /impeccable audit, critique, polish, bolder, quieter, distill, typeset and more, so you can steer the look without knowing CSS.

  • A detector that needs no AI

    61 rules catch AI tells like purple gradients and bounce animations, plus cramped padding and tiny tap targets; runs with no API key.

  • It checks the agent as it works

    On Claude Code, Codex, Cursor, Copilot and Grok Build, an optional hook scans each page edit and reports problems back to the agent.

Star growth over time for pbakaus/impeccable
The best kind of proof: a guy runs it on his brother's food-delivery site and posts the before and after. β€œI have no idea how it works,” he says, but the result speaks for itself.
A popular Claude Code creator builds a landing page from almost nothing, picks a look from a gallery of design β€˜worlds,’ then clicks parts of the page to get three variations of each. He admits it isn't a one-shot.
Chapters — click to jump
The longer hands-on: building a site from scratch with it, then pointing it at an existing website to see what it would change, with a verdict at the end.
news.ycombinator.com
Impeccable Style (103 points, 64 comments)

The skeptics' thread. Commenters said the β€˜before’ examples looked better than the β€˜after’ ones. The creator showed up, agreed the examples were rushed, pulled them, and fixed the bugs people reported.

Read the discussion β†’
HKUDS · Agent-ready command lines for apps · Apache-2.0

Turns any app into a command line your agent can drive.

ELI5

Most apps are built for a person with a mouse. CLI-Anything has your AI coding assistant read an open-source app’s code and build a typed-command version of it, so the AI can open, edit and export files without clicking around a screen.

View on GitHub β†’
Stars
51.2k
Language
Python
App harnesses
69
GitHub repo card for HKUDS/CLI-Anything β€” click to open the repo
Highlights
  • One command, seven phases

    In Claude Code, /cli-anything followed by an app runs a 7-phase pipeline: study the code, build the CLI, write the tests and docs, then package it.

  • The real app does the work

    Each CLI calls the actual software — LibreOffice makes the PDF, Blender renders the scene — and its tests check the real output files.

  • A shop of ready-made CLIs

    pip install cli-anything-hub, then cli-hub install fetches community-built CLIs for apps such as Zotero, Obsidian, OBS Studio and Draw.io.

Star growth over time for HKUDS/CLI-Anything
A big open-source-finds account explains the idea in one breath: point it at the code for GIMP, Blender or OBS, and it builds a full command-line control panel an AI agent can drive, with tests included.
A popular Claude Code creator installs it, points it at the Draw.io source code, and has Claude Code draw diagrams through the command line it generated. Under eight minutes from start to finish.
Chapters — click to jump
Same Draw.io test, plus the honest part: it only works on open-source apps, pure-GUI apps can fail, and here's a one-question test for whether it'll work on the tool you care about.
github.com
PR #212: Safari browser automation harness (merged Apr 14)

A stress test from inside the project: a contributor's own benchmark found the command-line approach about 25 times slower than a live MCP connection for Safari (3 seconds a call versus 0.1). The maintainers merged it anyway.

Read the discussion β†’
Alireza Rezvani · Skill library for AI coding agents · MIT

Your AI assistant gets 388 job-specific playbooks.

ELI5

A big library of “skills” — instruction files that teach an AI assistant how to do one specific job, like an SEO audit or a SaaS metrics check. You install the bundles you want into Claude Code, Codex, Cursor or a similar tool.

View on GitHub β†’
Stars
27.1k
Language
Python
Skills
388
GitHub repo card for alirezarezvani/claude-skills β€” click to open the repo
Highlights
  • Not just for engineers

    Alongside engineering, bundles cover marketing (49 skills), C-level advisory (46), product, project management, regulatory work and finance.

  • Helper scripts, nothing to install

    Many skills ship small Python tools, such as a SaaS metrics calculator, that use only Python’s built-in library — no extra packages.

  • Check a skill before you trust it

    A bundled skill-security-auditor scans any skill folder for command injection, data theft and prompt injection, and returns PASS, WARN or FAIL.

Star growth over time for alirezarezvani/claude-skills
davila7 · Claude Code add-on catalog · MIT

Kit out Claude Code with one install command.

ELI5

An app store for Claude Code extras. You browse aitmpl.com, pick a specialist agent, slash command, connector or setting, and one command copies it into your project. It also has tools to watch and health-check your Claude sessions.

View on GitHub β†’
Stars
32.3k
Language
Python
Stars this week
+539
GitHub repo card for davila7/claude-code-templates β€” click to open the repo
Highlights
  • One command installs a stack

    npx claude-code-templates@latest with --agent, --command, --mcp, --hook or --setting copies those pieces in; with no flags it opens a picker.

  • Watch Claude from your phone

    The --chats option opens a mobile-friendly live view of Claude’s replies, and adding --tunnel serves it remotely through a Cloudflare Tunnel.

  • New this week: mods

    34 early-access mods add things like a chess board in a side pane, a git sidebar, a live agent tree and a secret redactor; a setting must be switched on.

Star growth over time for davila7/claude-code-templates
This week's new trick, explained by an outside builder: a β€˜mod’ installed with one command decides before every turn whether Claude Code needs a stronger or cheaper model, and logs every decision.
A beginner's guide that uses the aitmpl.com catalog as its shop: he browses it, installs a design skill, and compares slides made before and after.
Chapters — click to jump
github.com
Unauthenticated OS Command Injection (RCE) in Claude Code Studio Server β€” GHSA-79wm-x847-7cvg

The cautionary tale: until July, the tool's optional β€˜studio’ web server let anyone who could reach it (even a malicious webpage) run commands on your computer. It's fixed in 1.29.4. It's a reminder to update and to read what you install.

Read the discussion β†’
⭐

First Stars

FROM THE AUDIENCE

Test your AI agent in a simulation before it goes live.

WHAT IT IS

A simulation layer for AI agents: you deploy an agent into a simulated environment, see how it performs, and tune its system and tool-calling prompts before real users touch it.

Visit the site β†’
Sent in by Rafi

Rafi saw our open-source repos video and has been building open-source AI dev tools, including Burn0, which watches your app’s LLM and API calls. Silo is the next one.

Your turn

Building something? Send it to hi@TheNextNewThing.ai

FROM THE AUDIENCE

Talk to your coding agents, and hear them answer back.

WHAT IT IS

A macOS plugin for Herdr: you speak, a realtime voice model (Grok, OpenAI or Gemini) hands the work to the Claude Code or Codex agents in your panes, and a glowing orb tells you when one finishes or needs a spoken “yes”.

View on GitHub β†’
Stars
2
Language
Swift
Started
Sep 2026
Sent in by Marcus

Marcus loved ChatGPT’s voice agent and wanted the same thing for his coding agents, so he built a version that runs natively in Herdr.

Your turn

Building something? Send it to hi@TheNextNewThing.ai

FROM THE AUDIENCE

A checkpoint that vets every action your AI agent takes.

WHAT IT IS

An open-source governance layer: before an agent acts, the action is checked against policy, things like PII leaks, prompt injection and risky network calls are blocked, and every decision lands in a tamper-evident audit trail.

View on GitHub β†’
Stars
1
Language
Python
Started
Jun 2026
Sent in by Tavares

Tavares sent it in after Andrew wrote back to him. It’s the open core of his larger CUSTOS platform for governed AI agents.

Your turn

Building something? Send it to hi@TheNextNewThing.ai

FROM THE AUDIENCE

A voice assistant that keeps talking while its bots do the work.

WHAT IT IS

Thursday holds a live voice call on OpenAI’s GPT-Live while background bots work in a real browser and a shell on your computer. It runs on a ChatGPT Plus sign-in, installs with npx thursday-agent, and draws its diagrams with a trimmed copy of Archify from our Sep 11 show.

View on GitHub β†’
Stars
24
Language
TypeScript
Started
Sep 2026
Sent in by Sung Keun

Sung Keun says the difference from ChatGPT is that it does the work, not just the talking: hang up and the jobs keep running, and you can open any job and watch the bots at their desks.

Your turn

Building something? Send it to hi@TheNextNewThing.ai

FROM THE AUDIENCE

Walk Google Street View like a video game.

WHAT IT IS

A free Chrome extension: WASD to walk, mouse-look, zoom, a compass HUD, and type a place to land on the street in front of it. No API key, no account, nothing leaves your computer.

View on GitHub β†’
Stars
0
Language
JavaScript
Started
Oct 2026
Sent in by Mat

Mat (back after TLDR Radio) found Google Maps exposes no API for this, so FreeRoam drives Street View the way a person would, with synthetic key presses and mouse drags.

Your turn

Building something? Send it to hi@TheNextNewThing.ai

FROM THE AUDIENCE

Let your main AI plan, and hand the typing to a cheaper model.

WHAT IT IS

A Claude Code and Codex skill that sends bulky, already-decided coding work to another model you already pay for, while your main model checks every diff. His second repo, skillview, lists every skill, plugin and MCP server you’ve installed in one table.

View on GitHub β†’
Stars
0
Language
Python
Also
skillview
Sent in by Praj

Praj saw our Sep 25 episode open with Jev making decisions fast and cheap, and uses it the same way: turn on the Jev scout and it picks only the files the other model needs.

Your turn

Building something? Send it to hi@TheNextNewThing.ai

FROM THE AUDIENCE

Content ratings for books in one short string.

WHAT IT IS

The SHOW Standard scores a story on spice, heat, darkness and transgression, written like SHOW S3·H4·O2·W5. The repo has the spec, machine-readable data, and a Claude skill that rates a manuscript chapter with evidence.

View on GitHub β†’
Stars
0
Language
Spec
License
CC BY-SA
Sent in by Lani

Lani built it for indie, romance and romantasy authors, readers and platforms who want a shared vocabulary instead of one vague star or a pile of content warnings.

Your turn

Building something? Send it to hi@TheNextNewThing.ai

FROM THE AUDIENCE

A coding agent that asks before it guesses.

WHAT IT IS

Karpathy’s four coding rules plus a short gap check: if a missing fact would change the result, the agent asks at most three questions, each with a recommended default. If nothing’s missing, it just does the work.

View on GitHub β†’
Stars
0
Language
Skill
Started
Oct 2026
Sent in by Anshuman

Anshuman, CEO of STROMA, built it to stop coding agents from filling in blanks and shipping a guess. Works with Claude Code, Codex, Cursor and Gemini.

Your turn

Building something? Send it to hi@TheNextNewThing.ai

BEFORE YOU GO

If this was useful, do three quick things.

β–Ά
Subscribe

New hot repos every week β€” don't miss the next drop.

β™₯
Like

It tells YouTube to show this to more builders like you.

✎
Comment

Tell me which repo you'll try first β€” or what to cover next.

THAT'S THE TOP 10 Β· OCTOBER 2, 2026

Thanks for watching.
The Next New Thing.

New hot repos every week. Subscribe so you never miss the next drop.