Policy dependency / Stack layer
RIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persisting
arXiv 2609.12127
Stack layer / Threat pattern
A Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full Set
arXiv 2609.11814
Stack layer / Threat pattern
Pattern: Anthropic's own bar is that Claude-written production code gets reviewed harder than human-written code
Simon Willison
Stack layer / Contrast
Guillermo Rauch: 'the days of language or runtime choice based on human convenience are over'
X/Twitter (Guillermo Rauch)
Stack layer / Contrast
SureForge encodes a research-plan-verify-review gate sequence as a plain-text agent skill
GitHub
Policy dependency / Stack layer
Tarfio Launches a Budget and Metering Layer That Sits Between Agents and Paid MCP Tools
Tarfio via Hacker News Show HN (single source, private beta)
Stack layer / Threat pattern
787,562 Function Pairs Show AI Code Is Half the Size of Human Code With Different Defect Classes, Not Fewer
arXiv 2609.12708
Policy dependency / Stack layer
Pattern: four coding-agent CLIs shipped sandbox or trust work in the same week
GitHub