Policy dependency / Stack layer
A Bun packaging quirk left a vulnerable undici in Cline after the CVE was supposedly remediated
GitHub
Policy dependency / Stack layer
RIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persisting
arXiv 2609.12127
Stack layer / Threat pattern
Cline Leaves the IDE: a Standalone Desktop Agent That Imports Claude Code and Codex Sessions and Schedules Recurring PR Reviews
Cline GitHub releases (launch reported by RuntimeWire, version cadence verified on the repo)
Stack layer / Threat pattern
Snyk put its agent-skill scanner behind a free web page called Skill Inspector
Snyk Labs
Policy dependency / Threat pattern
A Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May Touch
arXiv 2609.15422
Stack layer / Threat pattern
Gemini CLI ships an external-context processor to stop indirect prompt injection through build files
GitHub
Policy dependency / Stack layer
CROSS-CATEGORY: Salesforce, Zendesk and Workable All Shipped Named Agent Portfolios on Sept 14, Each Metered in a Different Unit
Zendesk newsroom, Salesforce press release and Workable via GlobeNewswire (three independent Sept 14 announcements)
Stack layer / Contrast
Claude Code lowers the medium dynamic-workflow guideline from 15 agents to 10, and defaults Pro plans to small
Claude Code Changelog