Latest signal September 18, 2026 · afternoon edition
Five separate actors published evidence this week that the parts nobody picked on purpose, the context manager, the image decoder, the build dependency, the rate limiter, are where both the remaining performance and the entire blast radius now live.
01 / The wire
Recent briefings
-
September 18, 2026 · afternoon
Five separate actors published evidence this week that the parts nobody picked on purpose, the context manager, the image decoder, the build dependency, the rate limiter, are where both the remaining performance and the entire blast radius now live.
-
September 18, 2026 · morning
The judgment calls buried inside coding harnesses, risk gating and compaction and model routing, are being unbundled into a cheap external decision model, and the community rebuilt them in seventy-two hours.
-
September 17, 2026 · afternoon
Agent memory and agent instructions are converging on plain files a human can read and Git can diff, and four vendors published an instance of that in 48 hours.
-
September 17, 2026 · morning
The layer between the model and the task, the harness and the handoff artifacts it writes, is where this week's cost and risk numbers landed, from a doubled bill for the same success rate to compaction summaries that carry instructions nobody wrote.
-
September 16, 2026 · afternoon
The day's launches stopped asking whether an agent can do the task and started asking whether it will do it again, so the new products are measurements of repeatability and deterministic rails around the model rather than smarter models.
-
September 16, 2026 · morning
Tuesday's launches from Cloudflare, Anthropic, and TypeSafe all replace an all-or-nothing switch with a typed, scoped control, while the day's security story shows the old switches still leaking.
-
September 15, 2026 · afternoon
The same week the labs escalated the story that agents are becoming dangerous threat actors, three independent outside reads pushed back, and the gap between the catastrophe framing and the agents you can actually observe got wide enough to see through.
-
September 15, 2026 · morning
Supervision of agents is leaving the prompt and becoming a separate runtime component with its own veto, whether that is a per-command network allowlist, a guard model trained on execution events, or a validating agent that is never the one that found the bug.
02 / Under the surface
Latest analysis
-
ZCode Uploads Your Entire Git History, and No Agent Permission Setting Can Stop It
The workspace exfiltration in ZCode runs as a host-level sidecar outside the agent tool loop, so the permission model everyone audits is…
-
Hister Indexes Everything You Read and Hands It to Your Agent. Its Own Docs Explain Why That Is a Problem.
Hister is an MCP server where every record is attacker-authored by construction, and its answer is to label untrusted content rather than…
-
The Coding Agent Feature Your Model Never Calls, and the 176-Setting Study That Measured It
An affordance is only real if the model reaches for it, and the first component-level harness ablation shows recoverable context elision is…
-
fast-jev-compaction Deletes Your Context Instead of Summarizing It, and That Is the Safer Failure
Deleting a tool result is a recoverable loss because the agent can re-run the tool, while summarizing one is unrecoverable, which makes…
-
Skills Over MCP vs Specialist Agents: Microsoft's Own Trace Says Fewer Calls, More Tokens
A specialist agent is usually a SKILL.md and three tools wearing a model, and Microsoft's own trace shows that removing the model halves…
-
PRAXIST Hit #1 on GitHub Trending Under a License Called Fair Source That Never Converts to Open Source
PRAXIST's license borrows the Fair Source name, drops the delayed open-source publication that fair.io's definition requires, and adds a…
-
HarnessTax Says Your Coding Agent Harness Costs 2x for 2 Points, and the Bill Starts on the First Call
Harness choice is a cost decision that has been sold as a feature decision, and HarnessTax shows the cheapest place to measure it is the…
-
funes Keeps the Original Passage: Why Hugging Face's Coding-Agent Memory Refuses to Summarize
Funes bets that coding-agent memory should be a rebuildable index of verbatim transcript passages rather than model-written summaries, and…
04 / Coverage map
Topics we track
Claude Code 58 OpenAI 24 Anthropic 20 Codex 17 Agent Skills 15 Hugging Face 13 DeepSeek Harness 12 Model Context Protocol 12 Kimi K3 11 MCP 8 METR 8 Claude Code auto mode 7 GitHub Copilot 7 GPT-5.6 Sol 7 MCP 2026-07-28 7 GPT-5.6-Cyber 6 Ollama 6 Anthropic Frontier Red Team 5 Claude Fable 5.1 5 Claude Opus 5 5 GLM-5.3 5 GPT-6 Astra 5 grok-build 5 LangChain 5