Fetching from the wire…
Tools2026-08-20 · source-backed
Roughly 245 commits, adding session forking, archive/restore from the TUI resume picker, full conversation export to Markdown or clipboard, and Amazon Bedrock Runtime as a built-in provider with AWS profile and region support. Hooks can now run commands asynchronously and invoke MCP tools, and /status shows estimated thread credits or cost for eligible workspaces. Sandbox restrictions now fail closed on denied or unreadable paths on Linux and Windows. (GitHub) Fail-closed on unreadable paths is the one to note; fail-open on a path you couldn't stat is a real hole.
Each link below shares sources, entities, or timing with this story.
cua-driver-rs v0.20.0, published August 24, ships a codesigned and notarized macOS universal binary plus a QwenCuaDriver.app, unsigned Linux x86_64/arm64 builds on a glibc 2.31 floor, and Windows builds, with a single @qwen-code/cua-sdk npm package built against those assets....
It's plain Markdown — an agent skill that strips preamble, recap and closers from output, replacing them with numbered action steps like "Run npm install jsonwebtoken@latest, then edit src/auth.ts:42". Ten rules including capping lists at 5 items, matter-of-fact error language...
Three things happened this month that only make sense together. Agent Plugins 1.0 shipped co-signed by six competitors: AWS, Anysphere, Microsoft, OpenAI, Vercel and Google (GitHub Changelog). It makes skills-plus-MCP bundles portable across clients. OpenAI's August 11 Codex c...
The agent-security topic holds 42 repos above 100 stars, four from large companies rather than startups: NVIDIA/SkillSpector (14,498 stars, scanning Claude Code/Codex/MCP skills for prompt injection), Tencent/AI-Infra-Guard (4,467, red-teaming with Many-Shot/PAIR/GOAT/ActorAtt...
msitarzewski/agency-agents added 446 stars today, packaging personas across "divisions" (frontend specialists, community experts, fact-checkers, reality checkers), each defined with a voice, a process, and concrete deliverables rather than a generic prompt template (GitHub). I...
One Claude Code release fixed two independent permission-check bypasses on the same day. That's the story. Version 2.1.221, shipped August 4, patches a Bash tool bypass where zsh could execute hidden commands embedded inside [[ ]] regex conditionals. The approval prompt never...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.