Fetching from the wire…
Public story · 2026-08-26 · high
The same release also fails closed on daemon shutdown, adds a health check, and lets you hide the Cloud live viewer.
Why now: The fix is in the August 26 release of browser-harness, version 0.1.10.
browser-harness 0.1.10 redacts CDP credentials from daemon logs, closing a leak that put full control of a browser session into any file, aggregator, or console that captured those logs. A CDP endpoint isn't a read-only debug hook. Whoever holds those credentials can drive the browser directly, click, type, read cookies, pull whatever's on screen.
The rest of the release is cleanup, not new capability. Orchestrator-owned daemons now fail closed on shutdown, so a killed parent process can't leave an unmanaged daemon running. There's a machine-readable health check for daemon status. The screenshot response timeout is split from the IPC connect timeout, so a slow screenshot no longer trips the same clock as a dead connection. You can also turn off the Cloud live viewer.
Five changes, and each one narrows something rather than adding to it, unusual for a point release this size. It reads like a team that found one real problem and swept the code for anything sitting next to it.
The release notes don't say how far back the plaintext logging goes, so treat any browser-harness daemon deployed before August 26 as having written raw CDP credentials to disk for its entire run. If those logs went to a shared aggregator, rotate whatever session tokens were live and pin 0.1.10 before running it again.
Each link below shares sources, entities, or timing with this story.
browser-use/browser-harness is a deliberately thin layer over the Chrome DevTools Protocol where the agent writes and edits its own helper functions at runtime. When it hits a missing capability (file upload is the canonical example), it edits the harness code and adds the fun...
Google Cloud moved seven Gemini Enterprise Agent Platform features to GA on July 29, including Agent Identity as a native SPIFFE-based IAM type with least-privilege enforcement and non-repudiable auditing, plus Gateway, Registry, Evaluation, Observability, Memory Bank, and a R...
Moonshot AI ($4.8B valuation) launched Kimi Claw, a cloud-native OpenClaw platform running entirely in the browser with zero local setup. Powered by Kimi K2.5 (1T parameter MoE), includes 5,000 community skills via ClawHub, 40GB cloud storage, and persistent 24/7 agent environ...
Intercepts every agent action (file writes, shell commands, network requests) against a configurable policy. Fails closed if control plane unreachable. Browser dashboard, cryptographic audit ledger, budget controls, container sandboxing. GitHub
google/skills sits at 16,460 stars, Apache-2.0, +327 on August 8's trending page, organized into three product families with a .claude-plugin directory and plugins tree. August 5-7 commits show real curation: a migrated and validated GKE TPU dynamic-slices monitoring skill, a...
Shipped August 1: the call listed the vector store once instead of paginating, so on any account with more memories than a single page (most vector stores default to ~100) the rest survived while the call reported success. Also caps Supabase search/list top_k at the vecs limit...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.