Policy dependency / Stack layer
CROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated Intent
Product Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)
Stack layer / Threat pattern
16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shell
arXiv
Policy dependency / Stack layer
Paul Christiano Joins the OpenAI Foundation Board and Its Safety and Security Committee
OpenAI Blog
Stack layer / Threat pattern
block/goose 1.50.0 deletes fast model routing and the managed model registry for local inference
GitHub
Stack layer / Threat pattern
Vibe Coding Cut Task Time 27% and Raised Security Vulnerabilities in the Same Trial
arXiv 2609.09560
Stack layer / Threat pattern
RAGFlow 0.27.2 rewrites its Agentic RAG retrieval framework and patches a starlette CVE
GitHub
Policy dependency / Stack layer
Pattern: the agent config layer is being treated as an unmanaged dependency graph, and three independent sources said so this week
arXiv
Policy dependency / Stack layer
Retrieval that crosses into your dependencies' source, not just your repo, adds up to 6.3% pass@1 and survives version changes
arXiv 2609.09987