Fetching from the wire…
Public story · 2026-08-17 · high
It also fixes two approval bugs and follows Hazmat's OS-level sandbox fix by a week.
Why now: This is the second sandbox-hardening release for AI agents in the same week, arriving a day after 0.21.0 and right behind Hazmat's OS-level fix.
OpenAI shipped Agents SDK 0.21.1 on August 16, one day after 0.21.0, adding Docker sandboxes that can disable networking entirely, per the GitHub release notes.
A network-disabled sandbox can't leak data even if the code inside turns hostile. That matters most for agents running with a user's full login and permissions.
The release also adds run-scoped sandbox working directories, model call timeouts and Modal sandbox resource options.
It fixes two approval bugs too. The core now honors exact call-approval decisions instead of guessing. It also rejects stacked anchors that only partially match instead of letting them slide through.
Hazmat closed the same kind of gap at the operating-system level a few days earlier. Neither project asks whether an agent needs to run with a person's full identity in the first place. Both just build a wall around it after the fact. Watch whether network-disabled sandboxes become the default in the next release, not a setting developers have to find.
Each link below shares sources, entities, or timing with this story.
Apache-2.0, rootless, single static binary, no daemon, claiming about 3.5ms container start against Docker's roughly 297ms and zero resident memory when idle (GitHub). It reads OCI images and docker-compose files but deliberately skips Docker's API, overlay networks and Swarm,...
Released August 26 with backports to v1.38.13 and v1.37.15 the next day, the vector database now runs its streamable MCP server stateless (GitHub). The same batch adds a DigitalOcean generative module, export and import endpoints for database user API-key hashes, pins a minimu...
A spec is a press release until someone who didn't write it implements it. GitHub made Agent Plugins 1.0 generally available on August 12 across VS Code, Copilot CLI, the Copilot SDK, and the Copilot app on all plans. The spec, published August 6, was co-authored by AWS, Anysp...
Eight thousand stars in a single day. That's what happened when Warp open-sourced its Rust-based, GPU-accelerated terminal on April 28. The repo shot to 47.9K total stars, making it the highest-velocity project on GitHub this week by a wide margin. But the interesting part isn...
Open-source framework for testing, evaluating, and red-teaming LLM prompts, agents, and RAG systems. Covers OWASP LLM Top 10. Used by 127 Fortune 500 companies. Now acquired by OpenAI but committed to continuing the open-source offering. The de facto standard for AI pentesting...
Released August 24, it adds native Anthropic passthrough for /v1/messages and serves the OpenAI Responses API natively for true OpenAI models, so existing SDK clients point at Onyx with no translation shim (GitHub). Also a /model switcher with current model in the status bar,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.