Latest signal August 5, 2026 · afternoon edition
In four days the industry issued agents the full kit of a human employee (a computer, a wallet, an identity, an operating system) and every control shipped alongside sits in the identity and scope layer, not in the model, which is a quiet concession the week's Hugging Face forensics make explicit.
01 / The wire
Recent briefings
-
August 5, 2026 · afternoon
In four days the industry issued agents the full kit of a human employee (a computer, a wallet, an identity, an operating system) and every control shipped alongside sits in the identity and scope layer, not in the model, which is a quiet concession the week's Hugging Face forensics make explicit.
-
August 5, 2026 · morning
Four separate disclosures in 48 hours all land on the same control surface, a human reading a diff, and the same week's biggest launch is an orchestrator built to run agents while that human is asleep.
-
August 4, 2026 · afternoon
Three separate stories today all break at the same joint, systems that verify which identity signed an action but never verify what caused that identity to sign, which is the exact gap Cloudflare is now selling a product into.
-
August 4, 2026 · morning
Every significant agent launch on today's board answers the same two questions, where the agent is allowed to work and how a human checks what it did, which means the industry has quietly stopped competing on agent capability and started competing on containment and review.
-
August 3, 2026 · afternoon
Three projects on today's board run frontier-scale models on machines that cannot hold them by streaming weights off NVMe, which moves the binding constraint on local inference from RAM to storage bandwidth and makes every headline memory number misleading on its own.
-
August 3, 2026 · morning
The harness, not the model and not the prompt, became the unit of engineering this week, and it is now carrying the permission model, the review gate, and the security posture that used to live somewhere else.
-
August 2, 2026 · afternoon
Agent skills finished their transition from a convenience feature into a package ecosystem, complete with a measured supply chain, an OWASP top ten, and enterprise signing registries, while the format itself still ships with no signatures and no capability model.
-
August 2, 2026 · morning
Streaming experts off disk instead of holding them in RAM went from one clever hack to the default architecture for running open frontier models locally, and the same week it landed, Unit 42 published what an attacker built out of the open-weights plus open-harness stack.
02 / Under the surface
Latest analysis
-
Kiro Crew Runs on Your Hardware. It Still Runs on kiro-cli.
Kiro Crew is genuinely open source and genuinely self-hosted, but agent.provider is fixed to acp and every install path drives kiro-cli, so…
-
Nine Coding-Agent Data-Loss Incidents and the Gap Between What the Model Meant and What the Shell Did
Coding-agent data loss is mostly a substrate mismatch, not a model failure, because the approval layer inspects command text while the…
-
TencentDB Agent Memory Makes Every Memory Private by Default. Its Newest README Dropped the Benchmark That Made It Famous.
TencentDB Agent Memory's real contribution is an access-control model that treats each memory as an owned, versioned asset that stays…
-
The keyv npm Worm Planted a Claude Code Hook. Opening the Repo Is the Second Attack.
The keyv compromise shipped a second execution path that needs no npm install at all, a SessionStart hook in .claude/settings.json and a…
-
@cloudflare/computer Lets the Model Pick Its Own Runtime. That Tool Description Is Your Cost Policy.
@cloudflare/computer moves the isolate-versus-container choice out of your architecture and into the agent's own tool call, which turns the…
-
ChatGPT Atlas Shuts Down August 9. Read the Shutdown Notice, Not the Launch Post.
Atlas lasted under ten months, and its shutdown notice is the more useful document than its launch post, because it names the state a…
-
WASTE Keeps a File of Everything It Got Wrong. Read docs/LEARNED.md Before You Read the Benchmark.
WASTE's most checkable claim is not 0.6 tokens per second, it is docs/LEARNED.md, a dated append-only record of hypotheses the project…
-
Project Perception's Load-Bearing Word Is "Actuator," Not "Agent"
Project Perception removes the human from the middle of the security loop while keeping them at both ends, so the only control that…
04 / Coverage map
Topics we track
Claude Code 20 Codex 11 OpenAI 10 Kimi K3 9 MCP 2026-07-28 7 Agent Skills 6 Hugging Face 6 MCP 6 Claude Opus 5 5 Model Context Protocol 5 OpenAI Presence 5 Anthropic 4 GPT-5.6 Sol 4 grok-build 4 MAI-Cyber-1-Flash 4 QM 4 xAI 4 1Password for Claude 3 AgentForger 3 Claude Security 3 cloudflare-computer 3 Hermes Agent 3 Ollama 3 opencodex 3