GitSpawn: untrusted repo git configs can run code in coding agents
GitSpawn shows coding agents can run a repo’s git config helpers before trust prompts. Clones are safe; zips and shared folders are not.
GitSpawn shows coding agents can run a repo’s git config helpers before trust prompts. Clones are safe; zips and shared folders are not.
NVIDIA PAIR beta routes Ollama and LM Studio agent jobs across RTX, Spark, and Mac nodes on your LAN without a new agent API.
xAI’s Sep 3 design essay frames Grok Bot around named persistent agents, routines, and a cloud computer—while docs say every Bot shares one user-scoped VM.
ClaudeDevs is collecting GitHub feedback on unreleased Function Hooks; they have not shipped. Today’s control plane is still settings.json hooks (command, http, prompt, agent, mcp_tool).
MBZUAI’s IFM shipped K2 Horizon: six Apache-2.0 models from 0.9B to 375B, with open training artifacts aimed at coding and agents.
Claude Code 2.1.259 lets orgs provision HTTP/SSE MCP for every user and stops parallel sessions from wiping trust and MCP state.
OpenAI designates unreleased Astra as its first Critical cyber model and will gate advanced exploit tools to testers and Daybreak Blue.
Meta’s Muse Spark 1.3 is live in Muse Code and the Model API, targeting longer-horizon agent work with fewer tokens than 1.2.
A Runta bake-off holds the model fixed across coding harnesses and shows pass rates 50–67% with about a 17× median cost gap.
OpenClaw 2026.8.2 docks a Home agent beside current work, ships Linux .deb/AppImage, and hardens upgrades after 2026.8.1.
ToolJet’s MCP server lets Claude Code and Codex build internal apps by editing platform specs instead of generating React.
Google GA’d Gemini 3.8 Flash for long-horizon coding agents and gated 3.8 Flash Cyber to Fairwind partners for vuln find-and-fix.
Anthropic launches Claude Fable 5.1 and limited Mythos 5.1, cutting cache-read cost for agent loops and putting the model in Claude Code.
Arduino and Forgis demo a voice-driven robotic-arm agent on UNO Q with local inference and no cloud round trip.
OpenClaw brands v2026.8.1 as 2.0: guided install, rebuilt Control UI, and shared sessions—plus a contested upgrade path.
Hermes v0.21.0 ships Bot Mode, durable agent-to-agent chat, cron memory, and live subagent steering as the Pantheon release.
MoonBit open-sources SeekMoon, an agent-native ADE built around token and syntax-tree diffs instead of a classic IDE.
Anthropic’s Aug 31 post details sandbox classifiers, partner no-internet rules, and alignment findings after July unsafeguarded Claude cyber evals.
Drew Breunig’s August 30, 2026 essay argues sandbox “hacking” agents were trained to persist and coordinate—the same traits labs sell in coding models.
OpenClaw’s account says the wait is almost over, but the release index still lists v2026.8.1 as betas and v2026.7.1-2 as stable.
Murmell is a browser canvas where several coding agents share one cloud repo, claiming files before they write.
Google’s Cloud Run instances preview runs singleton always-on agents like OpenClaw for $5.70 at 1 vCPU and 1 GiB for 30 days.
A researcher shows Claude Code Opus 5 Auto Mode can run attacker code after a request to summarize a website.
Anthropic will replace Claude Code’s 50% weekly promo with a 25% baseline lift on Sept 14, a 17% cut versus current limits.
SkillRepo Skillsets let teams compose approved agent skill packs, gate publisher updates, and see per-repo drift.