Stack layer / Threat pattern
Cline Leaves the IDE: a Standalone Desktop Agent That Imports Claude Code and Codex Sessions and Schedules Recurring PR Reviews
Cline GitHub releases (launch reported by RuntimeWire, version cadence verified on the repo)
Policy dependency / Stack layer
Claude Code adds omitClaudeMd so subagents can run without inherited CLAUDE.md, and a sha256 plugin-install accept flag
GitHub
Stack layer / Threat pattern
Snyk put its agent-skill scanner behind a free web page called Skill Inspector
Snyk Labs
Policy dependency / Stack layer
Pattern: four coding-agent CLIs shipped sandbox or trust work in the same week
GitHub
Stack layer / Threat pattern
Codex carves out a 'Guardian' review subsystem in four hours of merges and fixes a context-reset leak in it
GitHub
Stack layer / Contrast
Claude Code lowers the medium dynamic-workflow guideline from 15 agents to 10, and defaults Pro plans to small
Claude Code Changelog
Stack layer / Threat pattern
SkillSecurer Finds Latent Prompt-Injection Vulnerabilities in More Than 17% of Popular Published Agent Skills
arXiv 2609.14079
Stack layer / Threat pattern
SkillAtlas Publishes 3,014 Agent-Skill Attack Cases, and 42.5% Only Succeed After a Failed First Round
arXiv 2609.13353