Policy dependency / Stack layer
A Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May Touch
arXiv 2609.15422
Policy dependency / Stack layer
HazardAuditor runs Claude Code, Codex, Hermes and OpenClaw in one harness and normalizes their events to train a guard model
arXiv / HuggingFace Daily Papers
Policy dependency / Stack layer
Claude Code adds omitClaudeMd so subagents can run without inherited CLAUDE.md, and a sha256 plugin-install accept flag
GitHub
Policy dependency / Stack layer
A Bun packaging quirk left a vulnerable undici in Cline after the CVE was supposedly remediated
GitHub
Policy dependency / Stack layer
PraisonAI's MCP auth policy validated credentials for api-key and bearer but waved through basic and OAuth
NVD
Stack layer / Threat pattern
Ponytail v4.10.0 adds native Cursor support through hooks.json and a Grok Build skills adapter
GitHub
Policy dependency / Stack layer
Python's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or Critical
arXiv 2609.14791
Stack layer / Threat pattern
Claude Code 2.1.271 Adds `claude plugin eval`, a Scored Reproducible Test Suite for Your Own Plugins
Releasebot (Anthropic Claude Code changelog mirror)