# Inside the Loop > Field notes on agentic anything: Claude Code, Codex, Cursor and whatever ships next. Every page returns markdown when requested with `Accept: text/markdown`, and each post is also at `/posts/.md`. Content may be used for search, AI answers and AI training (see Content-Signal in /robots.txt). ## Tool pages Living pages for the command-line tools coding agents run: latest version with its UTC release date, upgrade command, what changed, commands and flags added or removed (our own sandbox diff of `--help`), breaking changes and reproduced errors. Hub: https://insidetheloop.dev/tools ([Markdown](https://insidetheloop.dev/tools.md), [JSON](https://insidetheloop.dev/tools.json)). URL pattern: `/tools/`, `/tools/.md`, `/tools/.json`. - [ASC CLI](https://insidetheloop.dev/tools/asc) ([Markdown](https://insidetheloop.dev/tools/asc.md), [JSON](https://insidetheloop.dev/tools/asc.json)): latest 5.13.0, released 2026-10-07 00:02 UTC; verified 2026-10-07; updated 2026-10-07T12:39:57Z - [Claude Code](https://insidetheloop.dev/tools/claude-code) ([Markdown](https://insidetheloop.dev/tools/claude-code.md), [JSON](https://insidetheloop.dev/tools/claude-code.json)): latest 2.1.292, released 2026-10-06 18:59 UTC; verified 2026-10-07; updated 2026-10-07T14:18:20Z - [Codex CLI](https://insidetheloop.dev/tools/codex) ([Markdown](https://insidetheloop.dev/tools/codex.md), [JSON](https://insidetheloop.dev/tools/codex.json)): latest 0.160.1, released 2026-10-05 18:29 UTC; verified 2026-10-07; updated 2026-10-07T12:39:57Z - [Wrangler](https://insidetheloop.dev/tools/wrangler) ([Markdown](https://insidetheloop.dev/tools/wrangler.md), [JSON](https://insidetheloop.dev/tools/wrangler.json)): latest 4.148.0, released 2026-10-06 18:33 UTC; verified 2026-10-07; updated 2026-10-07T12:39:57Z ## Fix pages One exact CLI error per page: the cause in one sentence, the fix as commands, the affected versions and a reproduction we ran in a fresh Linux sandbox. Hub: https://insidetheloop.dev/fixes ([Markdown](https://insidetheloop.dev/fixes.md), [JSON](https://insidetheloop.dev/fixes.json)). URL pattern: `/fixes/`, `.md`, `.json`. Search by error text: `GET https://insidetheloop.dev/fixes.json?q=` or the MCP tool search_fixes. - [`Error: --stars must be passed after the subcommand name (asc reviews list [flags])`](https://insidetheloop.dev/fixes/asc-flag-must-be-passed-after-subcommand) ([Markdown](https://insidetheloop.dev/fixes/asc-flag-must-be-passed-after-subcommand.md), [JSON](https://insidetheloop.dev/fixes/asc-flag-must-be-passed-after-subcommand.json)): ASC CLI 5.11.0 and later. Fix: Put every flag after the leaf subcommand: `asc reviews list --stars 1 --app 123`, `asc builds list --app 123`. Updated 2026-10-07T14:15:32Z - [`image has an alpha channel or transparency; re-export it as RGB PNG or JPEG without alpha`](https://insidetheloop.dev/fixes/asc-png-alpha-channel-rejected) ([Markdown](https://insidetheloop.dev/fixes/asc-png-alpha-channel-rejected.md), [JSON](https://insidetheloop.dev/fixes/asc-png-alpha-channel-rejected.json)): ASC CLI 5.13.0 and later. Fix: Flatten the image onto a background and drop the alpha channel (RGB PNG), or export it as JPEG, then upload again. Updated 2026-10-07T14:15:32Z - [`error: unexpected argument '--full-auto' found`](https://insidetheloop.dev/fixes/codex-exec-full-auto-removed) ([Markdown](https://insidetheloop.dev/fixes/codex-exec-full-auto-removed.md), [JSON](https://insidetheloop.dev/fixes/codex-exec-full-auto-removed.json)): Codex CLI 0.147.0 and later. Fix: Replace `--full-auto` with `--sandbox workspace-write`. Updated 2026-10-07T14:15:32Z - [`Not inside a trusted directory and --skip-git-repo-check was not specified.`](https://insidetheloop.dev/fixes/codex-exec-not-inside-trusted-directory) ([Markdown](https://insidetheloop.dev/fixes/codex-exec-not-inside-trusted-directory.md), [JSON](https://insidetheloop.dev/fixes/codex-exec-not-inside-trusted-directory.json)): Codex CLI all versions we ran (0.129.0 to 0.160.1). Fix: Run `codex exec` inside a Git repository (any subdirectory works), run `git init` first, or add `--skip-git-repo-check`. Updated 2026-10-07T14:15:32Z - [`The "legacy_env" field is no longer supported, so please remove it from your configuration file.`](https://insidetheloop.dev/fixes/wrangler-legacy-env-no-longer-supported) ([Markdown](https://insidetheloop.dev/fixes/wrangler-legacy-env-no-longer-supported.md), [JSON](https://insidetheloop.dev/fixes/wrangler-legacy-env-no-longer-supported.json)): Wrangler 4.111.0 and later. Fix: Delete `legacy_env` from `wrangler.jsonc` / `wrangler.toml` and drop any `--legacy-env` flag. With `legacy_env = false`, each environment now deploys as its own Worker named `-`. Updated 2026-10-07T14:15:32Z ## Posts - [GitHub MCP Server 2.0.0 hides output schemas from older clients](https://insidetheloop.dev/posts/github-mcp-server-2-0-structured-output) ([Markdown](https://insidetheloop.dev/posts/github-mcp-server-2-0-structured-output.md)) (2026-10-07): GitHub MCP Server 2.0.0 advertises outputSchema and structuredContent only to supported MCP 2026-07-28 clients; older clients keep text. - [What does Claude Code 2.1.292 change about subagent effort and local MCP?](https://insidetheloop.dev/posts/claude-code-2-1-292-effort-and-mcp-2026-07-28) ([Markdown](https://insidetheloop.dev/posts/claude-code-2-1-292-effort-and-mcp-2026-07-28.md)) (2026-10-07): Claude Code 2.1.292 adds Agent-tool effort levels and defaults local stdio MCP negotiation to protocol 2026-07-28, with a legacy opt-out. - [Where does Cursor Remote Control run the agent loop?](https://insidetheloop.dev/posts/cursor-ios-remote-control-local-agents) ([Markdown](https://insidetheloop.dev/posts/cursor-ios-remote-control-local-agents.md)) (2026-10-07): Cursor's changelog says Remote Control keeps agents local, while its mobile docs say the agent loop is in the cloud and tools stay local. - [Personal Agent Protocol is an OAuth session, but its v0.1 specification is not published](https://insidetheloop.dev/posts/personal-agent-protocol) ([Markdown](https://insidetheloop.dev/posts/personal-agent-protocol.md)) (2026-10-07): PAP uses one OAuth session across web, API, and company-agent routes, but its v0.1 specification and payment extensions are not published. - [How Claude edits open Google Docs, Sheets, and Slides](https://insidetheloop.dev/posts/claude-google-workspace-docs-sheets-slides) ([Markdown](https://insidetheloop.dev/posts/claude-google-workspace-docs-sheets-slides.md)) (2026-10-07): Claude edits the open Google file from a sidebar, with approval modes, version-history rollback, and a six-minute task limit. - [Why Mistral Large 4's blog post and model card disagree on its size](https://insidetheloop.dev/posts/mistral-large-4-public-preview) ([Markdown](https://insidetheloop.dev/posts/mistral-large-4-public-preview.md)) (2026-10-07): Mistral's 2026-10-06 announcement says 49B active and 1T total parameters; its model card says 52B active and 1.05T total. - [WebMCP reaches the browser agent. A remote MCP reaches the CLI.](https://insidetheloop.dev/posts/webmcp-versus-a-remote-mcp-for-a-blog) ([Markdown](https://insidetheloop.dev/posts/webmcp-versus-a-remote-mcp-for-a-blog.md)) (2026-10-07): WebMCP gives browser agents client-side tools in Chrome 149, while a remote Streamable HTTP MCP server gives CLI agents direct search without scraping. - [Where should an agent's correction go if the next agent will read the page?](https://insidetheloop.dev/posts/agent-correction-queue-not-the-comment-thread) ([Markdown](https://insidetheloop.dev/posts/agent-correction-queue-not-the-comment-thread.md)) (2026-10-07): Send agent corrections to a private feedback queue, not a public comment thread that may be rendered into markdown for later agents. - [A Web Bot Auth signature names a key directory, not a person you should auto-publish](https://insidetheloop.dev/posts/what-a-signature-agent-url-does-not-prove) ([Markdown](https://insidetheloop.dev/posts/what-a-signature-agent-url-does-not-prove.md)) (2026-10-07): A Web Bot Auth signature proves that a host published the signing key, not that the agent is honest, authorized, or suitable for automated publication. - [AI coding agent CLI pricing and usage limits, October 2026](https://insidetheloop.dev/posts/ai-coding-agent-cli-pricing-limits-october-2026) ([Markdown](https://insidetheloop.dev/posts/ai-coding-agent-cli-pricing-limits-october-2026.md)) (2026-10-06): Paid tiers start at ₹649/month in India or $10/month for Copilot Pro; heavy-use tiers reach $100–$500/month. Cursor publishes pools, not dollar allowances. - [Which sites search engines surface for 50 AI-agent questions: our October 2026 measurement](https://insidetheloop.dev/posts/which-sites-search-surfaces-for-50-ai-agent-questions) ([Markdown](https://insidetheloop.dev/posts/which-sites-search-surfaces-for-50-ai-agent-questions.md)) (2026-10-06): For 50 AI-agent questions, Google gave community sites 30.4% of candidate rows; Perplexity gave them 1.6%, with more vendor documentation and GitHub. - [Git conflicts and dirty worktrees with AI coding agents: what Aider, Claude Code, and Codex actually do](https://insidetheloop.dev/posts/git-conflicts-dirty-worktrees-ai-coding-agents) ([Markdown](https://insidetheloop.dev/posts/git-conflicts-dirty-worktrees-ai-coding-agents.md)) (2026-10-06): Aider 0.86.2 commits dirty changes, Claude Code 2.1.292 snapshots files, and Codex CLI 0.160.1 isolates parallel work in Git worktrees. - [How ASC CLI 5.12.0 adds iPhone Duo and Asset Library workflows for agents](https://insidetheloop.dev/posts/asc-cli-5-12-0-iphone-duo-asset-library) ([Markdown](https://insidetheloop.dev/posts/asc-cli-5-12-0-iphone-duo-asset-library.md)) (2026-10-06): ASC CLI 5.12.0 adds iPhone Duo screenshot and preview validation alongside Asset Library image uploads and placements for automated App Store publishing. - [Whistle puts speech-to-text for on-device agents in 16.9 MB](https://insidetheloop.dev/posts/cactus-whistle-on-device-speech-to-text) ([Markdown](https://insidetheloop.dev/posts/cactus-whistle-on-device-speech-to-text.md)) (2026-10-06): Cactus Whistle packages 7-language speech recognition into a 16.9 MB CPU file that pairs with Needle to emit structured tool calls directly from audio. - [Synara 1.0.0 moves Oh My Pi onto the stable app](https://insidetheloop.dev/posts/synara-1-0-0-stable-oh-my-pi) ([Markdown](https://insidetheloop.dev/posts/synara-1-0-0-stable-oh-my-pi.md)) (2026-10-06): Synara 1.0.0 puts Oh My Pi, Inbox, provider accounts, handoffs, and Auto-fix CI in Stable; Hubs and Tasks stay in Beta. - [Tale 0.5.72 runs GPT-6 Astra tool calls through the Responses API](https://insidetheloop.dev/posts/tale-0-5-72-gpt-6-responses-api) ([Markdown](https://insidetheloop.dev/posts/tale-0-5-72-gpt-6-responses-api.md)) (2026-10-06): Tale 0.5.72 routes GPT-6 Astra tool calls through OpenAI's Responses API and restricts tasks using it to Codex, while subscriptions remain task-only. - [HyperFrames Studio puts the agent on the same timeline](https://insidetheloop.dev/posts/hyperframes-studio-shared-timeline) ([Markdown](https://insidetheloop.dev/posts/hyperframes-studio-shared-timeline.md)) (2026-10-06): HyperFrames Studio lets a person and a coding agent edit the same project through a visual timeline and direct source-file writes. - [OpenHands 1.25.0 stops embedding the local session key](https://insidetheloop.dev/posts/openhands-1-25-0-local-session-key) ([Markdown](https://insidetheloop.dev/posts/openhands-1-25-0-local-session-key.md)) (2026-10-06): OpenHands 1.25.0 defaults local launchers to loopback and removes the session key from off-loopback HTML unless an operator opts in. - [What does echoVic/orca-agent v0.5.6 add for MCP?](https://insidetheloop.dev/posts/orca-0-5-6-mcp-cli) ([Markdown](https://insidetheloop.dev/posts/orca-0-5-6-mcp-cli.md)) (2026-10-06): echoVic/orca-agent v0.5.6 adds CLI MCP management, streamable HTTP, parallel startup, OAuth, and read-only tool approval. - [Devin stores what it learned in a git repo, then dreams on it](https://insidetheloop.dev/posts/devin-memory-drive-and-agent-memory-repo) ([Markdown](https://insidetheloop.dev/posts/devin-memory-drive-and-agent-memory-repo.md)) (2026-10-06): Devin stores cross-session memory in a Git repo with a MEMORY.md index, rejects stale concurrent writes, and runs a daily dreaming pass to consolidate notes. - [How Cursor bills Auto after the split into Cost, Balance, and Intelligence](https://insidetheloop.dev/posts/how-cursor-bills-auto-mode) ([Markdown](https://insidetheloop.dev/posts/how-cursor-bills-auto-mode.md)) (2026-10-06): All Cursor Auto modes bill at the routed model's list price; eligible third-party routes add $0.25 per million tokens on Teams and Enterprise. - [What does a ChatGPT plan meter when Codex and Work share it?](https://insidetheloop.dev/posts/what-a-chatgpt-plan-meters-for-codex) ([Markdown](https://insidetheloop.dev/posts/what-a-chatgpt-plan-meters-for-codex.md)) (2026-10-06): ChatGPT Work and Codex share one agentic allowance, with local and cloud usage, weekly limits, and credits counted by model and task. - [What Claude Code plan mode, auto mode, and bypass mode still allow](https://insidetheloop.dev/posts/claude-code-plan-auto-and-bypass-modes) ([Markdown](https://insidetheloop.dev/posts/claude-code-plan-auto-and-bypass-modes.md)) (2026-10-06): Plan mode blocks edits until approval, auto mode classifies risky actions, and bypass still prompts or denies six action classes. - [How do Claude Pro and Max limits reset for Claude Code?](https://insidetheloop.dev/posts/claude-code-usage-limits-and-resets) ([Markdown](https://insidetheloop.dev/posts/claude-code-usage-limits-and-resets.md)) (2026-10-06): Claude Code shares Claude's five-hour and weekly limits; use Settings > Usage on the web or Desktop to apply an available free reset. - [Why a remote MCP server answers 405 after the 2026-07-28 revision](https://insidetheloop.dev/posts/mcp-2026-07-28-stateless-and-the-405) ([Markdown](https://insidetheloop.dev/posts/mcp-2026-07-28-stateless-and-the-405.md)) (2026-10-06): A legacy SSE fallback sends GET to a POST-only 2026-07-28 MCP endpoint, so its 405 can hide an earlier connection failure. - [Which instruction file do Claude Code, Codex, Cursor, and Gemini CLI load?](https://insidetheloop.dev/posts/which-instruction-file-each-coding-agent-reads) ([Markdown](https://insidetheloop.dev/posts/which-instruction-file-each-coding-agent-reads.md)) (2026-10-06): Claude Code uses CLAUDE.md before AGENTS.md; Codex uses AGENTS.md; Cursor loads root AGENTS.md and CLAUDE.md; Gemini CLI uses GEMINI.md. - [MCP, A2A, and the two protocols called ACP, explained](https://insidetheloop.dev/posts/mcp-a2a-and-the-two-acps) ([Markdown](https://insidetheloop.dev/posts/mcp-a2a-and-the-two-acps.md)) (2026-10-06): MCP connects agents to tools, A2A connects agents to agents, and ACP names either Zed's editor protocol or IBM's archived protocol. - [AXI is ten rules for CLIs that agents run](https://insidetheloop.dev/posts/axi-ten-principles-four-official-clis) ([Markdown](https://insidetheloop.dev/posts/axi-ten-principles-four-official-clis.md)) (2026-10-06): AXI defines ten design principles for agent-run CLIs across four official tools: gh-axi, chrome-devtools-axi, lavish-axi, and quota-axi. - [Lavish keeps the HTML and sends the pointing back to the agent](https://insidetheloop.dev/posts/lavish-axi-html-review-loop) ([Markdown](https://insidetheloop.dev/posts/lavish-axi-html-review-loop.md)) (2026-10-06): Lavish Editor pairs a local HTML file with a browser review UI, returning element and text annotations to a polling agent loop without cloud servers. - [Pi 1.0.4 lets you pick MCP tools with a pattern](https://insidetheloop.dev/posts/pi-1-0-4-mcp-tool-patterns) ([Markdown](https://insidetheloop.dev/posts/pi-1-0-4-mcp-tool-patterns.md)) (2026-10-06): Pi 1.0.4 lets --tools and --exclude-tools match MCP tools with *, adds --no-mcp, and keeps MCP tools unless a pattern starts with mcp__. - [The /kun skill downloads its instructions from GitHub on every run](https://insidetheloop.dev/posts/kun-skill-pulls-main-every-run) ([Markdown](https://insidetheloop.dev/posts/kun-skill-pulls-main-every-run.md)) (2026-10-06): The /kun skill downloads a Node script from GitHub main on each invocation, caches root docs locally, then reads ENTRY.md to answer. - [Copilot CLI 1.0.92 keeps ambient GITHUB_TOKEN out of sandboxed shells](https://insidetheloop.dev/posts/copilot-cli-1-0-92-sandbox-github-token) ([Markdown](https://insidetheloop.dev/posts/copilot-cli-1-0-92-sandbox-github-token.md)) (2026-10-06): Copilot CLI 1.0.92 strips ambient GITHUB_TOKEN from sandboxed shells while Git can use masked credentials when sandbox authentication is enabled. - [GitHub ReviewBench scores AI code review agents on 219 pull requests](https://insidetheloop.dev/posts/github-reviewbench-code-review-agents) ([Markdown](https://insidetheloop.dev/posts/github-reviewbench-code-review-agents.md)) (2026-10-06): GitHub ReviewBench compares AI code review agents on 219 pull requests with grounded and augmented precision, recall, and F1 metrics. - [MCP TypeScript SDK 2.3.1 checks token audience on the legacy server](https://insidetheloop.dev/posts/mcp-typescript-sdk-2-3-1-expected-resource) ([Markdown](https://insidetheloop.dev/posts/mcp-typescript-sdk-2-3-1-expected-resource.md)) (2026-10-06): MCP TypeScript SDK 2.3.1 adds expectedResource to server-legacy, rejecting mismatched or missing audiences with HTTP 401 invalid_token. - [How pstack stacks agent-built pull requests with gh or Origin](https://insidetheloop.dev/posts/pstack-skills-for-agent-prs) ([Markdown](https://insidetheloop.dev/posts/pstack-skills-for-agent-prs.md)) (2026-10-06): pstack's autopilot-stack lets workers build PRs in parallel while one coordinator owns the linear stack, using gh or Origin without requiring Graphite. - [Pi Durable checkpoints the turn, then resumes it](https://insidetheloop.dev/posts/pi-durable-checkpoints) ([Markdown](https://insidetheloop.dev/posts/pi-durable-checkpoints.md)) (2026-10-06): Pi Durable commits model and tool work to storage, then resumes unfinished tasks after a process restart. - [LangGraph 1.2.13 keeps an old checkpoint update out of other branches](https://insidetheloop.dev/posts/langgraph-1-2-13-checkpoint-fork) ([Markdown](https://insidetheloop.dev/posts/langgraph-1-2-13-checkpoint-fork.md)) (2026-10-06): LangGraph 1.2.13 forks superseded checkpoints, isolates older update_state writes, preserves DeltaChannel counters, and filters answered get_state interrupts. - [Cloudflare runs Pi inside a Durable Object, and the meter is wall-clock time](https://insidetheloop.dev/posts/pi-harness-on-a-durable-object) ([Markdown](https://insidetheloop.dev/posts/pi-harness-on-a-durable-object.md)) (2026-10-06): Cloudflare's PiHarness beta runs Pi Durable in a SQLite-backed Durable Object and meters its allocated 128 MB by wall-clock compute duration. - [GitHub Agentic Workflows 0.91.0 runs dynamic workflows on Claude Code and Copilot](https://insidetheloop.dev/posts/github-agentic-workflows-0-91-0) ([Markdown](https://insidetheloop.dev/posts/github-agentic-workflows-0-91-0.md)) (2026-10-06): GitHub Agentic Workflows 0.91.0 adds dynamic workflows for Copilot CLI and Claude Code, plus issue-backed work queues and trusted worker dispatch. - [What does pstack 0.15.13 change about /poteto-help?](https://insidetheloop.dev/posts/pstack-0-15-13-poteto-help) ([Markdown](https://insidetheloop.dev/posts/pstack-0-15-13-poteto-help.md)) (2026-10-06): pstack 0.15.13 updates the guide for /poteto-help; the skill was added in 0.15.10 and made typed-only in 0.15.11. - [Anthropic published the Claude Code symlink-write CVE; the patch shipped in May 2026](https://insidetheloop.dev/posts/claude-code-cve-2026-103435-symlink-write) ([Markdown](https://insidetheloop.dev/posts/claude-code-cve-2026-103435-symlink-write.md)) (2026-10-06): CVE-2026-103435 affects Claude Code before 2.1.129; version 2.1.129 fixed the write race on 2026-05-06, before disclosure on 2026-10-05. - [Cohere North 2 keeps agent memory and caps token spend](https://insidetheloop.dev/posts/cohere-north-2-agent-spend-memory) ([Markdown](https://insidetheloop.dev/posts/cohere-north-2-agent-spend-memory.md)) (2026-10-06): Cohere North 2 adds cross-session agent memory and North Admin flow control, with request and token-rate tiers for users and groups. - [What changed in Claude Code 2.1.290's WebFetch and WebSearch?](https://insidetheloop.dev/posts/claude-code-2-1-290-webfetch-websearch) ([Markdown](https://insidetheloop.dev/posts/claude-code-2-1-290-webfetch-websearch.md)) (2026-10-06): Claude Code 2.1.290 pages WebFetch past 100,000 characters, refills WebSearch at 100 calls/hour, and blocks project-level Chrome enablement. - [OpenAI will watermark Codex and ChatGPT text in the EU](https://insidetheloop.dev/posts/openai-textgrain-codex-eu) ([Markdown](https://insidetheloop.dev/posts/openai-textgrain-codex-eu.md)) (2026-10-06): OpenAI will add invisible statistical watermarks to eligible ChatGPT and Codex text in the EU, while API customers worldwide can opt in for select models. - [Instinct's group-chat agent works for people without an account](https://insidetheloop.dev/posts/instinct-group-chat-agent) ([Markdown](https://insidetheloop.dev/posts/instinct-group-chat-agent.md)) (2026-10-05): Instinct lets friends without accounts join a group agent, while personal agents ask before sharing data or pending replies. - [Why robots.txt Cannot Stop Grok Bot](https://insidetheloop.dev/posts/why-robots-txt-cannot-stop-grok-bot) ([Markdown](https://insidetheloop.dev/posts/why-robots-txt-cannot-stop-grok-bot.md)) (2026-10-05): robots.txt cannot block Grok Bot's browser session; it can only guide crawlers that identify themselves and follow the Robots Exclusion Protocol. - [How Meta Muse and Stripe Link handle autonomous purchases](https://insidetheloop.dev/posts/meta-muse-stripe-link-agent-wallets) ([Markdown](https://insidetheloop.dev/posts/meta-muse-stripe-link-agent-wallets.md)) (2026-10-05): Muse gets a user-approved Link spend request, then uses a one-time card or Link Pay Token while the agent never sees the user's real card details. - [What a System One model decides, and what it refuses](https://insidetheloop.dev/posts/system-one-models-and-jev) ([Markdown](https://insidetheloop.dev/posts/system-one-models-and-jev.md)) (2026-10-05): System One models return typed probabilities for bounded questions and refuse free-form text, code, and reasoning explanations. - [Rex public testing is a free macOS terminal with persistent sessions](https://insidetheloop.dev/posts/superlogical-rex-terminal-public-testing) ([Markdown](https://insidetheloop.dev/posts/superlogical-rex-terminal-public-testing.md)) (2026-10-05): On 2026-10-05 Rex opened macOS public testing as a free, self-hostable terminal with persistent sessions; Linux, Windows, and iOS are outside the test. - [Clef, Clef-flash, or Jev: which decision model belongs on the agent hot path?](https://insidetheloop.dev/posts/clef-versus-jev-for-agent-routing) ([Markdown](https://insidetheloop.dev/posts/clef-versus-jev-for-agent-routing.md)) (2026-10-05): Use Clef-flash for speed and vision, Clef for a larger model and context window, or Jev for low-cost text routing. - [Do AI agent orchestrators charge for model tokens?](https://insidetheloop.dev/posts/bring-your-own-subscription-orchestrators) ([Markdown](https://insidetheloop.dev/posts/bring-your-own-subscription-orchestrators.md)) (2026-10-05): Most independent orchestrators charge for workspace features, while you bring the Claude, Codex, or other provider account that pays for inference. - [Liquid's d1 now answers from an image](https://insidetheloop.dev/posts/liquid-d1-vision-decision-model) ([Markdown](https://insidetheloop.dev/posts/liquid-d1-vision-decision-model.md)) (2026-10-05): Liquid AI added vision to its d1 decision model on 2026-10-05, returning calibrated probabilities at $0.04 per million input tokens with zero output tokens. - [How AI agents sign HTTP requests with Web Bot Auth](https://insidetheloop.dev/posts/web-bot-auth-signed-agents) ([Markdown](https://insidetheloop.dev/posts/web-bot-auth-signed-agents.md)) (2026-10-05): Web Bot Auth uses RFC 9421 signatures and a published key directory so sites can verify signed agent requests. - [The MCP Registry: what it is, who reads it, and how to list a server](https://insidetheloop.dev/posts/mcp-registry-explained) ([Markdown](https://insidetheloop.dev/posts/mcp-registry-explained.md)) (2026-10-05): The MCP Registry stores MCP server metadata, while aggregators read it and publishers add ownership proofs, server.json, and a public package or endpoint. - [Who reviews the work when the lead is also an agent?](https://insidetheloop.dev/posts/who-reviews-when-agents-ship) ([Markdown](https://insidetheloop.dev/posts/who-reviews-when-agents-ship.md)) (2026-10-05): Agent leads can delegate and review, but merges, delivery status, and budget gates stop at a human or an explicit automation rule. - [Inside Gemini Spark: Tasks, Schedules, and Chrome Auto Browse](https://insidetheloop.dev/posts/google-gemini-spark-chrome-auto-browse-architecture) ([Markdown](https://insidetheloop.dev/posts/google-gemini-spark-chrome-auto-browse-architecture.md)) (2026-10-05): Gemini Spark splits automation into tasks, schedules, and skills, using local Chrome when available and a separate remote browser when it is not. - [Git worktrees keep agents apart until the merge](https://insidetheloop.dev/posts/git-worktrees-do-not-stop-merge-conflicts) ([Markdown](https://insidetheloop.dev/posts/git-worktrees-do-not-stop-merge-conflicts.md)) (2026-10-05): Git worktrees give agents separate files and indexes, but divergent branches can still conflict when they are merged. - [Microsoft ran 1,024 coding agents with no lead](https://insidetheloop.dev/posts/agensh-no-lead-agent) ([Markdown](https://insidetheloop.dev/posts/agensh-no-lead-agent.md)) (2026-10-05): Microsoft's Agensh ran 1,024 coding agents without a lead and lifted pandoc's test-pass rate from 33.89% to 55.06%. - [Codex will ship something or reset, every day for 28 days](https://insidetheloop.dev/posts/codex-28-day-ship-or-reset) ([Markdown](https://insidetheloop.dev/posts/codex-28-day-ship-or-reset.md)) (2026-10-05): For 28 days, Codex will ship a broadly useful improvement each day or issue a full usage reset; Day 1 was a roughly 50% speedup. - [Reflection Beam: 501B open-weight model, weights later in October 2026](https://insidetheloop.dev/posts/reflection-beam-open-weight-agent-model) ([Markdown](https://insidetheloop.dev/posts/reflection-beam-open-weight-agent-model.md)) (2026-10-05): Reflection Beam is a 501B sparse MoE with 23B active parameters for coding and agent tasks; Reflection plans Apache 2.0 weights later in October 2026. - [Claude Code 2.1.289 stops a mod from overriding a shell deny rule](https://insidetheloop.dev/posts/claude-code-2-1-289-mod-sandbox-fix) ([Markdown](https://insidetheloop.dev/posts/claude-code-2-1-289-mod-sandbox-fix.md)) (2026-10-05): Claude Code v2.1.289 blocks mod-approved nested shell commands when deny or ask rules match, and fixes sandbox variable-prefix parsing. - [Five ways a lead agent runs a crew](https://insidetheloop.dev/posts/lead-agent-orchestrators-2026) ([Markdown](https://insidetheloop.dev/posts/lead-agent-orchestrators-2026.md)) (2026-10-05): Multi-agent crews run as star liaisons, peer teams, issue-routed squads, corporate org trees, or leaderless swarms depending on state and communication rules. - [How OpenAI Dots navigate the web: cloud browsers and local fallback](https://insidetheloop.dev/posts/openai-dots-cloud-computer-and-local-browser-fallback) ([Markdown](https://insidetheloop.dev/posts/openai-dots-cloud-computer-and-local-browser-fallback.md)) (2026-10-05): OpenAI Dots use a persistent cloud browser first, then a separate local task when a connected computer can reach a site the cloud browser cannot. - [Codex CLI 0.160.1 preserves Windows environment variables for remote MCP](https://insidetheloop.dev/posts/codex-cli-0-160-1-windows-remote-mcp) ([Markdown](https://insidetheloop.dev/posts/codex-cli-0-160-1-windows-remote-mcp.md)) (2026-10-05): Codex CLI 0.160.1 preserves SYSTEMROOT, TEMP, and TMP when Unix hosts spawn remote stdio MCP servers on Windows executors with custom environments. - [Cursor SDK can steer an agent mid-run](https://insidetheloop.dev/posts/cursor-sdk-steer-running-agents) ([Markdown](https://insidetheloop.dev/posts/cursor-sdk-steer-running-agents.md)) (2026-10-05): Cursor SDK's run.steer() delivers input to a live local TypeScript turn, moving a foreground subagent into the background if needed. - [Who can connect custom MCP servers in ChatGPT without developer mode?](https://insidetheloop.dev/posts/chatgpt-custom-mcp-without-developer-mode) ([Markdown](https://insidetheloop.dev/posts/chatgpt-custom-mcp-without-developer-mode.md)) (2026-10-05): Eligible ChatGPT users can add custom MCP servers from Plugins without Developer mode; full write-capable MCP access still depends on plan and workspace policy. - [Herdr runs terminal agents while Herdr GPUI embeds browser tabs](https://insidetheloop.dev/posts/herdr-and-herdr-gpui) ([Markdown](https://insidetheloop.dev/posts/herdr-and-herdr-gpui.md)) (2026-10-05): Herdr owns terminal agent sessions; unaffiliated Herdr GPUI connects to its daemon and adds macOS and Windows browser tabs with human-to-agent annotations. - [What changed in Claude Code during September 2026?](https://insidetheloop.dev/posts/claude-code-changes-september-2026) ([Markdown](https://insidetheloop.dev/posts/claude-code-changes-september-2026.md)) (2026-10-05): September 2026 added Opus 5.5, Sonnet 5.5, server-side auto-mode checks, AGENTS.md fallback, and tighter subagent controls. - [Google Docs edits Markdown files in place without file conversion](https://insidetheloop.dev/posts/google-docs-native-markdown) ([Markdown](https://insidetheloop.dev/posts/google-docs-native-markdown.md)) (2026-10-05): Google Docs edits and comments on Markdown files in place, while Google Drive renders previews, starting 2026-10-05 for Workspace and personal accounts. - [GPT-5.6 Sol, Terra, and Luna: which tier to use for agent work](https://insidetheloop.dev/posts/gpt-5-6-sol-terra-luna-for-agents) ([Markdown](https://insidetheloop.dev/posts/gpt-5-6-sol-terra-luna-for-agents.md)) (2026-10-05): Use Sol for multi-agent reasoning and long context, Terra as the default for coding at 40% of the cost, and Luna only for short, high-volume tasks. - [What changed in the Codex CLI refresh of September 2026](https://insidetheloop.dev/posts/codex-cli-refresh-september-2026) ([Markdown](https://insidetheloop.dev/posts/codex-cli-refresh-september-2026.md)) (2026-10-05): The September 2026 Codex CLI refresh made fullscreen transcripts default, added voice and worktrees, and added GPT-6.1 Sol plus max and ultra reasoning. - [llms.txt and llms-full.txt: what they are, who reads them, and how to generate them](https://insidetheloop.dev/posts/llms-txt-llms-full-txt-explained) ([Markdown](https://insidetheloop.dev/posts/llms-txt-llms-full-txt-explained.md)) (2026-10-05): llms.txt is a Markdown index IDE agents and MCP servers fetch to navigate a site; llms-full.txt embeds the full text. AI search bots largely ignore both. - [What Cloudflare turns on for AI bots on a new domain](https://insidetheloop.dev/posts/cloudflare-ai-bot-blocking-defaults-2026) ([Markdown](https://insidetheloop.dev/posts/cloudflare-ai-bot-blocking-defaults-2026.md)) (2026-10-05): New Cloudflare domains allow Search, Training, and Agent. If onboarding says the site shows ads, Training is Disallow AI Training and Agent blocks on ad pages. - [IndexNow on Cloudflare Workers: key file, submission, and what it feeds](https://insidetheloop.dev/posts/indexnow-cloudflare-workers-setup) ([Markdown](https://insidetheloop.dev/posts/indexnow-cloudflare-workers-setup.md)) (2026-10-05): IndexNow lets a Cloudflare Worker prove site ownership and notify search engines, but it does not guarantee indexing or direct AI-search inclusion. - [Workers Analytics Engine records the AI agent requests that page analytics miss](https://insidetheloop.dev/posts/track-ai-agent-visits-workers-analytics-engine) ([Markdown](https://insidetheloop.dev/posts/track-ai-agent-visits-workers-analytics-engine.md)) (2026-10-05): Page analytics misses AI agents that never run JavaScript. This Worker writes each request to Analytics Engine so SQL can count it by class. - [Serving markdown to AI agents from Cloudflare Workers with Accept: text/markdown](https://insidetheloop.dev/posts/serve-markdown-to-ai-agents-cloudflare-workers) ([Markdown](https://insidetheloop.dev/posts/serve-markdown-to-ai-agents-cloudflare-workers.md)) (2026-10-05): Paid Cloudflare zones can serve Accept: text/markdown with Markdown for Agents. Workers Free and Paid can convert HTML with env.AI.toMarkdown(). - [Cloudflare Content Signals in robots.txt: what search, ai-input, and ai-train mean](https://insidetheloop.dev/posts/cloudflare-content-signals-robots-txt) ([Markdown](https://insidetheloop.dev/posts/cloudflare-content-signals-robots-txt.md)) (2026-10-05): Content-Signal in robots.txt lets site owners declare whether crawlers may use content for search indexing, AI retrieval/grounding, or model training. - [How AI agents fetch web pages: user agents, IP ranges, and fetch origins](https://insidetheloop.dev/posts/how-ai-agents-fetch-web-pages-user-agents) ([Markdown](https://insidetheloop.dev/posts/how-ai-agents-fetch-web-pages-user-agents.md)) (2026-10-05): AI crawlers fetch from vendor datacenters using published IP ranges, while CLI coding agents fetch directly from developer workstations via local IPs. - [How to pass every isitagentready.com check for a content site](https://insidetheloop.dev/posts/isitagentready-content-site-checks) ([Markdown](https://insidetheloop.dev/posts/isitagentready-content-site-checks.md)) (2026-10-05): Passing the seven isitagentready.com content checks requires a valid robots.txt, sitemap, Link headers, markdown negotiation, Content Signals, and DNS-AID. ## For agents: tools - MCP (read-only, Streamable HTTP, stateless): https://insidetheloop.dev/mcp with tools search_posts, get_post, list_recent_posts, list_tools, get_tool, search_fixes, get_fix. - Report an outdated or wrong claim: POST https://insidetheloop.dev/api/feedback with JSON {"post": "", "kind": "outdated|incorrect|broken-link|missing-source|other", "claim": "", "evidence_url": "", "note": ""}. Reports go to a private editor queue and are never published. - Record that you cited a post: POST https://insidetheloop.dev/api/cited with JSON {"post": "", "cited_at_url": ""}. Count: GET https://insidetheloop.dev/api/cited?post=. ## Optional - [Full text of every post](https://insidetheloop.dev/llms-full.txt) - [RSS feed](https://insidetheloop.dev/rss.xml) - [Sitemap](https://insidetheloop.dev/sitemap.xml)