Bookmarks

Top 10 GitHub Repos — September 4, 2026

AI Tools

Crawl4AI
Crawl4AI turns web pages into clean markdown for RAG pipelines and agent context, handling dynamic content and structured extraction along the way. Version 0.9.3, released this cycle, is a security-only patch closing five coordinated-disclosure advisories — an arbitrary file write, an SSRF hole, a denial-of-service path in PDF processing, and two XSS bugs in the Docker Playground — with 33 additional bug fixes and no new features. a huge share of RAG and agent stacks route their web ingestion through this one project, so a coordinated security release here matters well beyond its own repo.
Khoj
Khoj is a self-hostable personal AI that chats with any local or cloud model, pulls answers from your own documents, and reaches you through a browser, Obsidian, Emacs, WhatsApp, or a desktop app. Its newest addition, Pipali, is an open-source AI coworker that runs on your own machine rather than a hosted server — a step past retrieval-and-chat toward something that does ongoing work. one of the few personal-AI projects that stays genuinely self-hostable while still expanding what it can do, instead of quietly becoming a funnel to a paid cloud tier.
Scientific Agent Skills
This is a library of 163 validated agent skills paired with access to over 100 scientific databases across biology, chemistry, medicine, and drug discovery, documented in an accompanying arXiv paper. It works with Cursor, Claude Code, Codex, and any agent that follows the open Agent Skills standard, plus a companion desktop co-scientist app that keeps data local. it's the difference between an agent that can summarize a paper and one that can actually run a multi-step research workflow against real databases.

AI/ML

KTransformers
KTransformers optimizes LLM inference and fine-tuning across mixed CPU-GPU hardware, aiming to let a single consumer GPU run models that would otherwise need a rack. On August 26, 2026 the project added native GLM-5.3-flash support with a 1M-token context window on consumer GPUs, followed within days by AVX512 CPU-only LoRA fine-tuning for x86 servers that lack AMX. most inference-optimization projects announce support for a new model months after release — this one shipped it within days.
WebLLM
WebLLM runs LLM inference directly inside a browser tab using WebGPU, with no server call once the model is loaded, and it mirrors the OpenAI API closely enough that existing client code needs little rewriting. It supports streaming, JSON mode, and a growing list of open model families. it's still one of the only credible paths to a private, fully offline AI feature that ships as an ordinary web page.

Developer Tools

GitNexus
GitNexus indexes a codebase — GitHub, GitLab, Azure repos, or a local ZIP — entirely in the browser, building a knowledge graph of every dependency, call chain, and cluster without sending code to a server. It exposes that graph through MCP tools so an agent can trace impact and blast radius across files before touching anything, rather than inferring structure from a directory listing. it gives agents something closer to an actual mental model of a codebase, not just more text to search through.
Cursor Plugins
This is Cursor's own plugin specification plus its first batch of official plugins, each one a standalone directory with a `.cursor-plugin/plugin.json` manifest. The initial set covers things like automated branch review, incremental AGENTS.md memory updates, and a scaffolder for building new plugins. Cursor is formalizing an extension surface instead of leaving the pattern to whatever the community improvises.

AI Agents

AgentMemory
AgentMemory records what a coding agent did during a session, compresses it, and feeds the relevant parts back into the next one — across Claude Code, Copilot CLI, Cursor, Codex, and most other MCP clients. It combines BM25 keyword search, vector embeddings, and a knowledge graph rather than relying on any single retrieval method. persistent memory that survives a restart, instead of another status file the agent forgets to read.

Integrations

FreeLLMAPI
FreeLLMAPI aggregates free-tier access from 34 LLM providers behind a single OpenAI-compatible endpoint, covering 635 model endpoints and roughly 7.4 billion tokens a month. A router picks a live model per request and fails over automatically when one provider hits its cap, and the model catalog updates itself from a signed feed instead of requiring a fresh install. it solves the tedious part of running on free tiers — tracking which of thirty-some providers still has quota left — instead of just being one more provider.

Security

Shannon
Shannon is an autonomous pentester for web apps and APIs: it reads your source code, maps out attack paths, and runs real exploits against your own application to prove a vulnerability exists before it reaches production. Version 3.0, released this cycle, adds deeper source analysis, a rebuilt CLI, native CI/CD hooks, and SARIF and PDF report output aimed at security teams rather than a single terminal session. it turns "this endpoint looks risky" into a verified exploit chain, which is a different and more useful thing than a static scan.