Policy dependency / Stack layer
A Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May Touch
arXiv 2609.15422
Policy dependency / Stack layer
A Bun packaging quirk left a vulnerable undici in Cline after the CVE was supposedly remediated
GitHub
Stack layer / Threat pattern
Elva Launches Against Postman With Flat Workspace Pricing and Specs Generated From Repo Commits
Elva (surfaced via the Product Hunt daily leaderboard for 2026-09-14)
Policy dependency / Stack layer
Python's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or Critical
arXiv 2609.14791
Stack layer / Threat pattern
Gemini CLI ships an external-context processor to stop indirect prompt injection through build files
GitHub
Stack layer / Contrast
Constellation Research: Salesforce's Agent Pricing Is Confusing Buyers, With Spend Up 30% Against ~3% Productivity Gains
Constellation Research
Stack layer / Threat pattern
Cline Leaves the IDE: a Standalone Desktop Agent That Imports Claude Code and Codex Sessions and Schedules Recurring PR Reviews
Cline GitHub releases (launch reported by RuntimeWire, version cadence verified on the repo)
Policy dependency / Stack layer
Pattern: four coding-agent CLIs shipped sandbox or trust work in the same week
GitHub