Latest signal August 2, 2026 · afternoon edition
Agent skills finished their transition from a convenience feature into a package ecosystem, complete with a measured supply chain, an OWASP top ten, and enterprise signing registries, while the format itself still ships with no signatures and no capability model.
01 / The wire
Recent briefings
-
August 2, 2026 · afternoon
Agent skills finished their transition from a convenience feature into a package ecosystem, complete with a measured supply chain, an OWASP top ten, and enterprise signing registries, while the format itself still ships with no signatures and no capability model.
-
August 2, 2026 · morning
Streaming experts off disk instead of holding them in RAM went from one clever hack to the default architecture for running open frontier models locally, and the same week it landed, Unit 42 published what an attacker built out of the open-weights plus open-harness stack.
-
August 1, 2026 · afternoon
Agent state that used to live somewhere invisible is being dragged into the open, by the MCP spec that deleted the hidden session, by YC scoping memory and permissions per person and per room, and by two disclosures where the exploit was configuration and text the operator never saw.
-
August 1, 2026 · morning
Three separate disclosures this week put the failure at the harness layer rather than the model layer, with Anthropic classifying its own real-world breaches as an operational failure, AI Now showing no model update fixes the README injection class, and a GitHub board led entirely by skill routers and connector gateways.
-
July 31, 2026 · afternoon
The model stopped being the product this week, with the biggest cost win credited to a harness rewrite rather than a new checkpoint, a hyperscaler putting its own model family on life support, and a GitHub board led by skills, connectors, and packaging.
-
July 31, 2026 · morning
Four separate disclosures and shipments in seventy-two hours all turned on the same question, what an agent can reach on the network and whether anyone checked that boundary before the agent went looking.
-
July 30, 2026 · afternoon
Three unrelated shipments on the same day attacked the price of a token from opposite ends, vendor price cuts, enterprise spend guardrails, and a local runtime that removes the meter entirely.
-
July 30, 2026 · morning
Three shipments in 48 hours moved capability out of the model and into the harness around it, and the same 48 hours priced the harness as the new attack surface.
02 / Under the surface
Latest analysis
-
WASTE Runs Kimi K3's 2.78 Trillion Parameters on a Laptop, and the Bottleneck Moved to Your SSD
WASTE proves a 2.78-trillion-parameter model no longer has to fit in RAM, but it relocated the constraint rather than removing it, from…
-
Unit 42's Autonomous AI Attack Report Is a Configuration Audit, Not a Capability Warning
Every control the attacker disabled in Unit 42's autonomous-attack campaign is a documented, supported setting in harnesses developers…
-
YC Open-Sourced the Agent It Runs Its Company On. Read QM's SECURITY.md First.
The most valuable file in YC's newly open-sourced QM harness is SECURITY.md, because it enumerates in plain language the twelve places its…
-
reverse-skill Is a Security Skill Router. Its RULES.md Is Built to Overrule Your Agent's Caution
Reverse-skill's copyable idea is not its security content but its RULES.md, which pre-declares authorization, writes itself into your…
-
Anthropic Wants Mandatory Safety Testing for Every Capable Model. Its Own Testing Broke Into Three Companies
Mandatory pre-release safety testing is the control almost everyone now agrees on, and Anthropic's own eval postmortem three days after…
-
The Azure DevOps MCP Server Ships a Prompt-Injection Guardrail. One Tool Doesn't Use It.
Microsoft built the prompt-injection defense for its Azure DevOps MCP server and applied it to wiki and build-log tools but not to the one…
-
Ruflo's CVSS 10 Bug Got Patched in a Day. The Poisoned Agent Memory Did Not
Seven of the eight steps in the RufRoot attack chain die with the patch and a key rotation, but the poisoned AgentDB pattern store survives…
-
OpenConnector Hands Your Agent 8,310 SaaS Actions. Credential Encryption Is Off by Default.
OpenConnector's value is the credential boundary rather than the provider count, and that boundary ships unlocked because encryption, the…
04 / Coverage map
Topics we track
Claude Code 17 Codex 9 OpenAI 9 Kimi K3 7 MCP 2026-07-28 7 Agent Skills 6 Hugging Face 6 MCP 6 Claude Opus 5 5 Model Context Protocol 5 OpenAI Presence 5 Anthropic 4 GPT-5.6 Sol 4 grok-build 4 xAI 4 1Password for Claude 3 AgentForger 3 Claude Security 3 Hermes Agent 3 Ollama 3 opencodex 3 TurboFieldfare 3 AgentENV 2 AI-Infra-Guard 2