Fetching from the wire…
OSS2026-08-15 · source-backed
v3.5.12 carries 783 rules, up from 768. The release note describes the pipeline plainly: "tc-pr-back → safety gate → auto-merge → this release." GitHub The prior tagged release recorded 10/10 OWASP Agentic Top 10 coverage and PINT results of 62.7% recall at 99.7% precision, plus a precision repair taking four auto-blocking rules from 149 false positives to 37. Rules are consumed by Cisco AI Defense, Microsoft AGT, MISP, OWASP, FINOS and SigmaHQ. Detection content shipping to npm without a human release decision is a supply chain question all by itself.
Each link below shares sources, entities, or timing with this story.
The project proposes a vendor-neutral detection standard explicitly modeled on Sigma (GitHub). That downstream adopter list is unusually broad for a young repo. This is the clearest sign yet that detections-as-code for autonomous agents is consolidating into one shared format...
A GitHub repo cataloging Claude Code tips doesn't normally warrant a top story. But shanraisshan/claude-code-best-practice at 53.4K stars isn't a tips list anymore. It's the de facto reference for how an entire generation of developers is learning to work with AI coding agents...
1. OWASP MCP Top 10 Security Audit (Intermediate) Systematically audit your MCP servers against the OWASP MCP Top 10. Download the checklist, inventory all servers, test each against 10 categories (injection, auth bypass, confused deputy), prioritize by CVSS, remediate critica...
At 23,817 stars with 2,954 forks and only 20 open issues, MIT-licensed, pushed September 12 after gaining 514 stars that day. It's an open-source architectural modeling editor exposing its own operations through a CLI and MCP server so a coding agent drives the model directly...
MCPConfig.tools now accepts Agent, Team and Workflow instances plus Toolkit objects, exposing each as its own named MCP tool. You call chief, not run_agent(agent_id="chief"). Toolkits publish one MCP tool per registered method, narrowed by the toolkit's own enable/include/excl...
Agent-created schedules move from per-chat folders to ~/.cline/schedules, and cron reconciliation on restart no longer wipes hub-managed schedules (GitHub). Tool results returning images from browser or MCP tools render inline with a carousel instead of raw base64 text, which...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.