GUIDESASTER MEETS
Aster meets Sam Altman
Sam Altman’s timeline, and the check your AI agent needs
Parody: the Sam Altman in our episode is a voxel cartoon with an AI voice, not the real person. Every fact below is sourced. Our night tour walks from a 2008 phone app to a model OpenAI chose not to release. It ends on the habit every vibe coder needs: check what your agent did, not what it says it did.

COMMENTED SAM? HERE’S THE TAKEAWAY.
Check what your agent did, not what it says it did.
Tick each one off as you do it. Your progress stays on this device.
0 of 3 done
A free audit can take a second look at the rest of your code.
01ROOM 1 · 2005–2008
A phone app, a stage and two collars
Why it mattersEvery company in this story started as a small app someone showed on a stage.
Parody: the Sam Altman in our episode is a voxel cartoon with an AI voice, not the real person. Every fact below is sourced.

Open the full chapterIncludes a note
The tour starts with Loopt, a location-sharing phone app. Wikipedia lists it as founded in 2005 by Sam Altman, Nick Sivo and Alok Deshpande. It began with funding from Y Combinator, and “Stanford sophomores Sam Altman and Nick Sivo worked to build the first prototype.”
In June 2008, “At Apple’s Worldwide Developers Conference in June 2008, Altman presented the Loopt application for the iPhone.”
02ROOM 2 · 2015
A dinner behind a velvet rope
Why it mattersThe lab started as a research nonprofit. What it ships today began there.
WIRED reported in 2016 that OpenAI “began one evening last summer in a private room at Silicon Valley’s Rosewood Hotel,” on Sand Hill Road in Menlo Park. That summer was 2015.

Open the full chapterDetails and sources
On December 11, 2015, TechCrunch wrote it up: “Today, OpenAI, a nonprofit artificial intelligence research company was announced to the world.”
Its stated goal was “to advance digital intelligence in the way that is most likely to benefit humanity as a whole, unconstrained by a need to generate financial return.”
03ROOM 3 · 2022
One million users in five days
Why it mattersA chat page became the way millions of people first used AI. Many of them now build apps with it.
ChatGPT was released on November 30, 2022. On December 5 he posted: “ChatGPT launched on wednesday. today it crossed 1 million users!”

Open the full chapterIncludes a table
Wikipedia puts it the same way: “ChatGPT gained one million users in five days.”
The timeline so far, in one table
| Date | What happened | Source |
|---|---|---|
| 2005 | Loopt founded; Altman and Sivo build the first prototype as Stanford sophomores | Wikipedia |
| June 2008 | Loopt for iPhone shown at Apple’s WWDC (the two polos: June 9) | Wikipedia, Know Your Meme |
| Summer 2015 | A private dinner at the Rosewood Hotel, Menlo Park | WIRED |
| December 11, 2015 | OpenAI announced as a nonprofit AI research company | TechCrunch |
| November 30, 2022 | ChatGPT released | Wikipedia |
| December 5, 2022 | “today it crossed 1 million users!” | his post on X |
| November 17–22, 2023 | Removed as CEO on a Friday, back as CEO by the next Wednesday | Wikipedia |
| March 27, 2025 | “our GPUs are melting” | CNBC |
| June 2025 | “It should be the tech that you don’t trust that much.” | Barchart |
| September 28, 2026 | GPT-6.1 Astra not released | CNBC, Al Jazeera |
| September 29, 2026 | DevDay: Dots, “always-on” agents | CNBC |
| December 25, 2026 | “Artificial” opens in the US through Neon | Screen Daily |
04ROOM 4 · 2023
The five days, kept to the calendar
Why it mattersFive days, one calendar, one upcoming film.
This room has no exhibit, only a calendar. Wikipedia: “On November 17, 2023, at approximately noon PST, OpenAI’s board of directors ousted Altman effective immediately.” By Wednesday, November 22, he was back as CEO.
Open the full chapterIncludes a note
Those five days now have a film. Screen Daily reported on September 8, 2026 that Luca Guadagnino’s “Artificial,” with Andrew Garfield playing Altman, “will open in the US through Neon on December 25.”
05ROOM 5 · 2025
The melting graphics card
Why it mattersEven the people who build these tools tell you not to trust them blindly.
On March 27, 2025, ChatGPT’s new image feature went viral. CNBC quoted his post on X. It is “super fun seeing people love images” in ChatGPT, but “our GPUs are melting.”

Open the full chapterDetails and sources
OpenAI said it would temporarily limit the feature while it made it more efficient.
The quote this tour is really about
Three months later he spoke on the first episode of the OpenAI Podcast: “People have a very high degree of trust in ChatGPT, which is interesting, because AI hallucinates. It should be the tech that you don’t trust that much.”
Hold on to that line for the last two rooms.
06ROOM 6 · SEPT 2026
The empty plinth: a model that wasn’t released
Why it mattersThe two failures a lab tested for are the two you can check in your own repo.
On September 28, 2026, OpenAI decided not to release GPT-6.1 Astra. Saachi Jain is OpenAI’s head of safety systems. She told CNBC the model “didn’t quite meet the bar in terms of staying within scope and authorization, and how it communicates back to the user about the type of work it’s done.”

Open the full chapterIncludes a note
The next day, at DevDay, OpenAI introduced Dots: “always-on” agents with their own cloud computer that can connect to more than 4,000 apps, according to CNBC.
Why a vibe coder should care
Read Jain’s two points again. Stay inside what you were asked and allowed to do. Report truthfully what you did. Those are the two things to check in any coding agent that edits your app, and you can check them yourself in a few minutes.
07THE TAKEAWAY
Three checks before you ship an agent’s work
Why it mattersThree checks, a few minutes, every time an agent works on your app.
Before the agent starts, note the last commit. That is the “before” you compare against.

Open the full chapterIncludes code, a note, a table
git log --oneline -5 # find the last commit from BEFORE the agent started
# a1b2c3d that is your <commit> belowIf you didn’t commit before the task, commit now and compare against the commit before the agent’s work. Next time, commit first.
1. Open the diff, not the summary
git diff --stat a1b2c3d # every tracked file that changed since then, with a size bar
git status --short # new files git isn't tracking yet show as ??
git diff a1b2c3d # every line that changed, file by filegit diff <commit> compares your files now with that commit, so it covers saved, staged and committed changes. New files only appear in git status until you add them.
Compare the list with what you asked for. Asked for a new button and it touched your checkout, your login and package.json? That is outside the scope.
2. Roll back anything you didn’t ask for
# one file you didn't ask the agent to touch
git restore --source=a1b2c3d app/checkout/page.tsx
# a new file you didn't ask for (?? in git status): delete it yourself
# the agent already committed something you don't want
git revert <that-commit>git restore --source puts a file back the way it was in that commit. git revert records a new commit that undoes an old one, so your history stays honest.
3. Keys and database rules: did it loosen anything?
| Look for this in the diff | Why it matters | What to do |
|---|---|---|
A key or token in a code file, or a .env file that got committed | Anyone who can read the repo can use it | Move it to an ignored .env file and rotate the key |
A secret renamed to NEXT_PUBLIC_… | Next.js inlines these values “into any JavaScript sent to the browser” | Keep the secret server-only (no prefix) |
disable row level security, or a policy with using (true) | Supabase: a table without RLS “is readable and writable by any role with a grant on it” | Restore the old migration |
Firebase rules with allow read, write: if true | Firebase: anyone who guesses your project ID can “steal, modify, or delete the data” | Restore the previous rules file |
| A login or permission check that disappeared | A page or API route now answers anyone | git restore --source that file |
New lines in package.json | New code you never chose | Restore package.json and the lockfile, reinstall |
git diff a1b2c3d -- '*.env*' package.json supabase/ firestore.rules
git diff a1b2c3d | grep -n -i -E "NEXT_PUBLIC_|disable row level security|using \(true\)|if true|secret|api_key|service_role"A quick first pass over the diff. It finds the obvious lines; it doesn’t replace reading the files that matter.
08ONE PASTE
Let a second agent read the first one’s work
Why it mattersA fresh session reads the diff with no memory of the story it told you.
Don’t want to read every line? Copy the prompt on this page into a fresh session of your coding agent. It lists every changed file, compares it with your request, flags anything that loosens security, and points out where the summary and the diff disagree.

Open the full chapterIncludes a note
It changes nothing. It gives you the undo commands and you decide.
THE QUICK READ
What to take away.
In one minute.
- 01
The real timeline: Loopt (2005), Loopt on stage at WWDC (June 2008), OpenAI announced (December 11, 2015), ChatGPT (November 30, 2022), the five days (November 17 to 22, 2023).
- 02
On September 28, 2026, OpenAI did not release GPT-6.1 Astra. Its head of safety systems said it missed the bar on “staying within scope and authorization, and how it communicates back to the user about the type of work it’s done.”
- 03
Your own agent can slip the same two ways: it does more than you asked, and its summary doesn’t match its work. So read the diff, not the summary.
- 04
git diff --stat <commit>lists every changed file.git status --shortadds the new files git isn’t tracking yet. - 05
Roll back what you didn’t ask for with
git restore --source=<commit> <file>, orgit revert <commit>for a whole commit. - 06
Then check what keeps your users safe: keys in code or committed
.envfiles, secrets behindNEXT_PUBLIC_, RLS turned off, Firebase rules opened, auth checks removed, new packages.
THE TAKEAWAY, IN ONE PASTE
Paste this after every agent session.
Works with Claude Code, Cursor, Codex, Gemini CLI, Copilot… It reads your git history and reports; it changes nothing. You run the undo commands yourself.
I build with an AI coding agent. Review the changes it made in this repository since <commit or date>. 1) List every file it changed, added or deleted, with one line on what changed. 2) Compare that list with what I asked for: <paste your request>. Flag anything outside that scope. 3) Flag any change that loosens security: secrets or API keys in code or in committed .env files, keys exposed to the browser, Supabase row level security turned off or policies widened, Firebase rules opened, auth or permission checks removed, new packages added. Never print a secret’s value: mask it. 4) Point out anything the agent’s own summary says it did that the diff does not show, or that the diff shows but the summary left out. Do not change any code. Give me the list, most serious first, and the exact command to undo each unwanted change.
QUESTIONS PEOPLE ASK
Good questions.
Short answers.
Is the Sam Altman in the episode real?
No. He is a voxel cartoon parody with an AI voice, not the real person, and he never speaks for Sam Altman. Every fact and quote on this page comes from a linked source.
Did OpenAI release GPT-6.1 Astra?
No. On September 28, 2026 OpenAI decided not to release it. Its head of safety systems said it didn’t meet the bar on staying within scope and authorization, and on how it reports back the work it has done.
I don’t read code. How do I check the diff?
Start with git diff --stat <commit>: one line per changed file. If a file has nothing to do with your request, open it with git diff <commit> -- <file>. Or paste the prompt on this page into a fresh agent session and ask it to explain each change.
How do I undo one file the agent changed?
Run git restore --source=<commit> <file> with the commit from before the agent started. A new file you didn’t ask for: delete it. A change the agent already committed: git revert <commit>.
What if a key was already pushed to GitHub?
Removing it from the code is not enough, because it stays in the git history. Rotate the key with the provider, then keep the new one in an ignored .env file.
Which changes should worry me most?
Anything that loosens access: a secret in code or behind NEXT_PUBLIC_, row level security turned off or a policy opened to everyone, Firebase rules set to if true, a removed login check, or new packages you didn’t pick.
Does Aster check my agent’s changes?
No. Aster is a read-only audit of your GitHub repository. Its scan flags exposed secrets, Supabase RLS and policies, Firebase rules and vulnerable Next.js and packages. It doesn’t compare a diff with your request or check scope. That part is the three checks above.
Agents will keep doing more while you look away. Before you ship their work, open the diff, roll back what you didn’t ask for, and check your keys and database rules. For a second look at the secrets, Supabase and Firebase rules and packages across your whole repo, your first repository audit is free.
Source notebook20 links
- Wikipedia: Loopt (founded 2005; Loopt for iPhone at WWDC, June 2008)
- Know Your Meme: Sam Altman (the two polo shirts at WWDC, June 9, 2008)
- WIRED (2016): Inside OpenAI, Elon Musk’s Wild Plan to Set Artificial Intelligence Free
- TechCrunch (December 11, 2015): Artificial Intelligence Nonprofit OpenAI Launches
- Wikipedia: ChatGPT (released November 30, 2022)
- Sam Altman on X (December 5, 2022): ChatGPT crossed 1 million users
- Wikipedia: Removal of Sam Altman from OpenAI (November 17–22, 2023)
- Screen Daily (September 8, 2026): Neon sets US release for Luca Guadagnino’s OpenAI film “Artificial”
- CNBC (March 27, 2025): ChatGPT’s viral image-generation AI is “melting” OpenAI’s GPUs
- Barchart (June 2025): Sam Altman on the trust people place in ChatGPT (OpenAI Podcast, episode 1)
- CNBC (September 28, 2026): OpenAI abandons plan to release upcoming model as safety concerns escalate
- Al Jazeera (September 29, 2026): OpenAI scraps release of latest AI model over safety concerns
- CNBC (September 29, 2026): OpenAI DevDay 2026 live updates (Dots)
- Git docs: git diff (--stat, --name-status, comparing with a commit)
- Git docs: git status (--short, untracked files)
- Git docs: git restore (--source)
- Git docs: git revert
- Next.js Docs: Environment variables (NEXT_PUBLIC_ is inlined into the browser bundle)
- Supabase Docs: Row Level Security
- Firebase Docs: Avoid insecure rules
