## The Risks of AI Tools: A Personal Security Review

On May 31, 2026, PewDiePie released Odysseus, a free and MIT-licensed self-hosted AI workspace. As someone who already self-hosts local models, I decided to run my own security review of the tool, alongside four independent AI models reviewing the codebase in parallel. Our findings were troubling: prompt injection leads to remote code execution, admin "wipe" operations lack tenant scoping, authentication is not properly set up, and there are numerous vulnerabilities throughout the system. I concluded that Odysseus should only be used locally by a single trusted user. 
