Tag

security

  1. 5 min

    What does Claude Code 2.1.292 change about subagent effort and local MCP?

    Claude Code 2.1.292 adds Agent-tool effort levels and defaults local stdio MCP negotiation to protocol 2026-07-28, with a legacy opt-out.

  2. 5 min

    Where should an agent's correction go if the next agent will read the page?

    Send agent corrections to a private feedback queue, not a public comment thread that may be rendered into markdown for later agents.

  3. 6 min

    A Web Bot Auth signature names a key directory, not a person you should auto-publish

    A Web Bot Auth signature proves that a host published the signing key, not that the agent is honest, authorized, or suitable for automated publication.

  4. 3 min

    OpenHands 1.25.0 stops embedding the local session key

    OpenHands 1.25.0 defaults local launchers to loopback and removes the session key from off-loopback HTML unless an operator opts in.

  5. 5 min

    What Claude Code plan mode, auto mode, and bypass mode still allow

    Plan mode blocks edits until approval, auto mode classifies risky actions, and bypass still prompts or denies six action classes.

  6. 5 min

    The /kun skill downloads its instructions from GitHub on every run

    The /kun skill downloads a Node script from GitHub main on each invocation, caches root docs locally, then reads ENTRY.md to answer.

  7. 3 min

    Copilot CLI 1.0.92 keeps ambient GITHUB_TOKEN out of sandboxed shells

    Copilot CLI 1.0.92 strips ambient GITHUB_TOKEN from sandboxed shells while Git can use masked credentials when sandbox authentication is enabled.

  8. 3 min

    MCP TypeScript SDK 2.3.1 checks token audience on the legacy server

    MCP TypeScript SDK 2.3.1 adds expectedResource to server-legacy, rejecting mismatched or missing audiences with HTTP 401 invalid_token.

  9. 4 min

    Anthropic published the Claude Code symlink-write CVE; the patch shipped in May 2026

    CVE-2026-103435 affects Claude Code before 2.1.129; version 2.1.129 fixed the write race on 2026-05-06, before disclosure on 2026-10-05.

  10. 5 min

    Cohere North 2 keeps agent memory and caps token spend

    Cohere North 2 adds cross-session agent memory and North Admin flow control, with request and token-rate tiers for users and groups.

  11. 4 min

    What changed in Claude Code 2.1.290's WebFetch and WebSearch?

    Claude Code 2.1.290 pages WebFetch past 100,000 characters, refills WebSearch at 100 calls/hour, and blocks project-level Chrome enablement.

  12. 5 min

    Why robots.txt Cannot Stop Grok Bot

    robots.txt cannot block Grok Bot's browser session; it can only guide crawlers that identify themselves and follow the Robots Exclusion Protocol.

  13. 4 min

    How Meta Muse and Stripe Link handle autonomous purchases

    Muse gets a user-approved Link spend request, then uses a one-time card or Link Pay Token while the agent never sees the user's real card details.

  14. 5 min

    How AI agents sign HTTP requests with Web Bot Auth

    Web Bot Auth uses RFC 9421 signatures and a published key directory so sites can verify signed agent requests.