Latest signal August 31, 2026 · afternoon edition
Four separate agent stories today each rest on one headline number, and in every case the number is accurate while the system underneath it behaves differently, starting with a commissioned 0.00 percent prompt-injection score that coexists with a working remote code execution chain.
01 / The wire
Recent briefings
-
August 31, 2026 · afternoon
Four separate agent stories today each rest on one headline number, and in every case the number is accurate while the system underneath it behaves differently, starting with a commissioned 0.00 percent prompt-injection score that coexists with a working remote code execution chain.
-
August 31, 2026 · morning
Five days of releases and papers all pushed on the same component, the agent's working context, making it shared between people, durable across sessions, and editable by the model, while the failure story everyone passed around this morning is six months old and turns on that context quietly dropping a rule.
-
August 30, 2026 · afternoon
The week's sharpest stories all turn on a setting nobody chose, and in most of them the only way to discover the setting was to read a diff.
-
August 30, 2026 · morning
Five vendors shipped changes in the same 48 hours that all stop accepting a claim about identity or permission at face value, and start demanding proof at the moment of the call.
-
August 29, 2026 · afternoon
Four institutions drew the line between machine autonomy and human responsibility this week, each in a different place, and the one that assumed the line already existed found out it was imaginary.
-
August 29, 2026 · morning
Access to models and to agents is now decided at the identity and ownership layer rather than the API layer, and four separate moves inside 48 hours pushed that gate in different directions.
-
August 28, 2026 · afternoon
Every significant thing shipped in the last 48 hours is an argument about the execution boundary, where an agent's reach stops, and two of the biggest arguments point in opposite directions on the same afternoon.
-
August 28, 2026 · morning
Three labs on three continents published the same finding inside 48 hours, that agent capability now compounds in reusable skill files written outside the weights, and the GitHub trending board spent the same day proving it commercially.
02 / Under the surface
Latest analysis
-
K-Dense's Scientific Agent Skills Repo Is MIT. Two of the Skills Inside It Say All Rights Reserved.
Scientific-agent-skills is MIT at the repository level while each SKILL.md declares its own license, including noncommercial and…
-
ContextPilot Trains an Agent to Delete Its Own Context, and the Reward Never Asks What It Deleted
ContextPilot's terminal reward is answer correctness plus format plus an invalid-call penalty, with no term for whether a given deletion…
-
ChatGPT Work Mounts One Filesystem Into Every Session You Have Running
ChatGPT Work Cloud's /workspace is one writable volume shared across sessions, and a write that lands there crosses no sandbox boundary, so…
-
Claude Code's Auto Mode Approved the Malware. Then It Blocked the Command to Kill It.
Claude Code's auto mode classifier approved the process that started the malware and then denied the command Claude wrote to kill it, which…
-
tokentab Prices Your Coding Agents Offline, From a Table Someone Maintains by Hand
Tokentab produces something that looks like a bill for your coding agents but is a reconstruction, because the token counts come from…
-
Omarchy Spent Fifteen Months Putting Every Desktop Process One Command Away From Root
Your agent's blast radius is set by the Unix groups your login shell inherited, not by the permission settings in its harness, and…
-
Claude Code Just Patched Its Third Symlink Deny-Rule Bypass in Eleven Months
A deny rule in an agent harness is not one policy but a separate implementation inside every part of the harness that touches the…
-
Busbar Calls Itself an Execution Boundary for AI. Read the Block Quote Before You Plan Around It.
Busbar's README promises an execution boundary across models, MCP tools, and A2A agents, and its own callout says only the model plane is…
04 / Coverage map
Topics we track
Claude Code 40 OpenAI 19 Codex 16 Agent Skills 14 Anthropic 12 DeepSeek Harness 12 Hugging Face 11 Model Context Protocol 10 Kimi K3 9 MCP 8 Claude Code auto mode 7 GPT-5.6 Sol 7 MCP 2026-07-28 7 GPT-5.6-Cyber 6 METR 6 Anthropic Frontier Red Team 5 Claude Opus 5 5 GLM-5.3 5 OpenAI Presence 5 Claude Code self-hosted environments 4 Cordis 4 FreeToken 4 GLM 5.2 4 GPT-5.6 Luna 4