Edition History

Past Daily Editions

Every issue of The Git Reporter is grouped by publication date, with each day's lead story, companion articles, and evidence trails kept together.

September 5, 2026

An Agent’s ‘No’ Needs a Way Back—But Not a Shortcut

Qwen Code now offers one manual review only for the exact action its AUTO mode blocked—turning a false positive into an accountable decision instead of a workaround hunt.

3 stories 9 source signals 1 repo
September 4, 2026

Hermes Decides That a Preference Can Have a Home

Hermes is redrawing a deceptively important line: a correction learned while doing one task belongs with that task's skill, while persistent memory is for facts that should matter everywhere.

3 stories 11 source signals 2 repos
September 3, 2026

Before Codex Trusts a Workspace, It Stops Letting the Workspace Choose Its Helpers

A merged Codex change moves automatic pre-trust helper lookups to known system locations, sanitizes plugin-sync Git, and makes diagnostics inspect a workspace-influenced path without running what they find.

3 stories 13 source signals 4 repos
September 2, 2026

A Child Agent’s Approval Request Shouldn’t Hide in Another Tab

Openwork now brings a child session’s blocked permission into the parent task; fresh Goose state-machine work shows why seeing the ask is only half the control.

3 stories 17 source signals 5 repos
September 1, 2026

A Completed Agent Run Is Not a Successful One

OpenHands now treats a finished process and a successful task as different facts—so an automation can be completed, blocked, and operationally failing at the same time.

3 stories 11 source signals 3 repos
August 31, 2026

The Company Can Host the Agent. The AI Account Can Still Be Yours.

QM is separating the place an agent is operated from the account that pays for and authorizes one person’s model turn—while deliberately leaving background work on organization credentials.

2 stories 8 source signals 2 repos
August 30, 2026

The Last Click Shouldn’t Redirect an Automation

OpenWork has stopped a scheduled Automation from silently following whichever workspace a person activated last; a job can now carry its intended place with it.

4 stories 36 source signals 4 repos
August 29, 2026

A Restricted Workspace Should Not Start Its Own Tools

Gemini CLI now gives an explicitly restricted or untrusted workspace a narrower configuration path: repository-defined tools, MCP servers, policies and telemetry no longer accompany its A2A server into startup.

2 stories 6 source signals 1 repo
August 28, 2026

The Old Proxy Is Gone. OpenWork's Cloud Has One Door Now.

OpenWork has deleted its standalone cloud-worker proxy; the public replacement makes a fresh signed preview the access-resolution seam while keeping a stable route for clients that cannot hold an expiring address.

1 story 3 source signals 1 repo
August 27, 2026

Before Docker Reads the File

Headlong’s Docker broker is treating the pre-render Compose file as an authority boundary—because a path is no longer safe to inspect after the renderer has already opened it.

2 stories 6 source signals 1 repo
August 26, 2026

A Shared Terminal Is Not Shared Permission

OpenClaw’s new terminal-input path separates an agent being allowed to see an operator’s terminal from being allowed to send a keystroke into it.

3 stories 13 source signals 1 repo
August 25, 2026

Codex Puts a Broker Between the Agent and the Secret

A newly merged Codex change says a project file can describe the work, but it should not be able to switch on the credential broker or choose the provider context that reaches an agent shell.

3 stories 13 source signals 1 repo
August 24, 2026

Unsloth Built a Benchmark That Can Veto Its Own Speed Claims

The new StudioBench is designed to make a performance result fail before it makes a flattering headline.

2 stories 6 source signals 1 repo
August 23, 2026

Before Cline Replaces an Agent Hub, It Starts Saying No

Cline’s Hub can now refuse new mutable work, wait for accepted sessions to settle, and replay a durable event stream to reconnecting clients before an upgrade swaps the service underneath them.

3 stories 9 source signals 3 repos
August 22, 2026

A Release Should Not Fetch Its Rules From a Moving Main

OpenClaw is making a narrow release promise: when the product is frozen, the workflow allowed to publish it must stay identifiable even after main changes.

1 story 5 source signals 1 repo
August 21, 2026

Qwen Code Saves the Shape of a Finished Workflow

Qwen Code is teaching a finished multi-agent run to leave behind a reviewable shape—rather than a pile of logs that dies with the terminal.

1 story 6 source signals 1 repo
August 20, 2026

Cline Lets an Agent Schedule Work—But Not Anywhere It Likes

Cline's new durable task system lets an agent make work recur after the chat ends, but its public implementation keeps asking the harder question: which workspace gave that job authority?

2 stories 10 source signals 1 repo
August 19, 2026

An Approval Must Keep Its Denials

Codex is tightening the rules beneath its approval layer: a broad remembered grant must not reopen a denied child path, an unfamiliar shell must identify itself, and a stale reviewer score should be visible as stale.

1 story 3 source signals 1 repo
August 18, 2026

An Agent Can’t Review the Wrong Tree

Qwen Code has made a workflow subagent’s linked worktree part of the job itself—a small API change with a large warning for anyone resuming, reviewing, or testing code across branches.

3 stories 10 source signals 2 repos
August 17, 2026

When a Context Limit Drops the User’s Turn

OpenClaw found a required Codex compaction preflight treating an intentional no-op as a fatal failure—so an overlong session could lose the incoming user turn before the model ever answered.

3 stories 9 source signals 3 repos
August 16, 2026

A Sandbox Isn’t Finished Until the Repository Says So

Mastra Factory is making one understated agent-system choice explicit: before a session workspace is scrubbed, pooled, or destroyed, the repository can say how its own worktree should be put away.

1 story 4 source signals 1 repo
August 15, 2026

Codex Stops a Thread’s Permission From Leaking Into a Read-Only Environment

A new Codex regression test makes the sharpest promise in its permissions work: a selected environment configured read-only must stay read-only even when the surrounding thread can write.

2 stories 6 source signals 1 repo
August 14, 2026

A Forgotten Tool Is No Longer Callable in Pydantic AI

After compaction hides how a deferred tool reached an agent, Pydantic AI now makes the agent put that evidence back before the call can go through.

1 story 3 source signals 1 repo
August 13, 2026

A Session Approval Needs Something to Hold On To

Two fresh code changes make the same point: a human’s “yes” is only useful when an agent can name exactly what that yes still authorizes.

3 stories 9 source signals 2 repos
August 12, 2026

OpenClaw’s shared channels gain a per-requester login

A new opt-in OAuth mode for HTTP MCP servers lets a trusted sender connect their own account instead of letting the whole room run on one operator credential.

3 stories 15 source signals 3 repos
August 11, 2026

Coding Agents Are Building Themselves—But Git Can Prove Only Part of It

Across 40,345 unique commits in ten public agent codebases, coding-agent credit becomes sharply more visible in 2026—and the missing receipts matter as much as the names that appear.

1 story 9 source signals 10 repos
August 10, 2026

In Mastra’s Approval Queue, the Second Yes Needs Its Own Address

An open Mastra core pull request treats a human approval as a per-tool-call decision, not a vague signal attached to an entire agent run.

3 stories 9 source signals 3 repos
August 9, 2026

Cline gives a finished agent answer a diff receipt

Cline’s restored “View Changes” control makes a completed agent turn point to a checkpointed file delta—not just its own verdict.

4 stories 25 source signals 4 repos
August 8, 2026

Hermes now stops agents from quietly rewriting their own instructions

A new Hermes Agent write gate treats project instruction files as a persistence surface: even an auto-approved agent must ask a human before it changes the text that can steer tomorrow’s work.

2 stories 6 source signals 2 repos
August 7, 2026

A Denied Agent Answer Should Not Survive in Memory

Microsoft’s experimental Agent Hooks adapter treats a rejected response as a session-history problem too: the verdict is meant to arrive before the reader sees it and before the affected context becomes durable.

1 story 4 source signals 2 repos
August 6, 2026

Permissions now travel with Codex’s work environment

Codex is moving a permission choice out of the thread’s background and into the selected environment that runs the command, applies the patch, sees the image, and carries work to another agent.

2 stories 7 source signals 2 repos
August 5, 2026

Tau Will Ask Before It Reads a Project’s AGENTS.md

Tau’s new Project Trust layer turns local instructions, skills, prompts, themes, and extension candidates into a directory-specific decision before they become ambient agent input.

2 stories 6 source signals 2 repos
August 4, 2026

The Agent Can Refile a Worktree, Not Rewrite the Filing Cabinet

Kilo Code’s new Agent Manager move gives an agent a way to reorganize parallel work—only through a live inventory, a targeted command, and a hard boundary around the recovery file.

1 story 4 source signals 1 repo
August 3, 2026

Agent Behavior wants to make good conduct a versioned artifact

Braintrust and Basis propose a tiny BEHAVIOR.md standard as the answer key between runtime instructions and agent evals. The file is easy; writing conduct that remains observable across real trajectories is the actual work.

2 stories 15 source signals 2 repos
August 2, 2026

An Approval Cannot Outlive the Conversation That Asked for It

Cline fixed a small but revealing failure in its VS Code extension: change a message while a command approval is waiting, and the old run could keep waiting forever—then catch answers meant for the new one.

1 story 5 source signals 1 repo
August 1, 2026

QM is trying to turn the personal agent into company infrastructure

Y Combinator's new open-source harness does not win its case by running Codex or Claude in Slack. Its more consequential bet is that every person and room needs a clearly owned memory, workspace, permission set, schedule, and durable computer.

2 stories 15 source signals 7 repos
July 31, 2026

Browser Use: the control boundary between an agent and the live web

Browser Use’s latest harness release and its own session examples make a harder point than a benchmark: browser automation only becomes legible when profile, destination, and data authority are named controls.

2 stories 9 source signals 5 repos
July 30, 2026

OpenHands: separating the software agent from the sandbox it works in

A new healthy-local-backend fallback makes the project’s larger argument concrete: the thing that helps a person steer an agent must stay legible even when the agent is running somewhere else.

4 stories 34 source signals 12 repos
July 29, 2026

An Agent Framework Can Carry Your Request—Not Your Responsibility

Microsoft Agent Framework's newest A2A and BYOK samples make one quiet operating rule visible: let a caller's configuration cross the boundary, but leave the host's policy and the provider's obligations where they belong.

3 stories 15 source signals 5 repos
July 28, 2026

When an Agent Sees Two MCP Servers Called Docs

OpenClaw’s Code Mode has a new answer to a quietly consequential question: when several connected machines offer a server called docs , how does an agent know which one it is calling?

3 stories 13 source signals 3 repos
July 27, 2026

Before Goose Runs a New Model, Pick Its Permission Mode

Goose has mapped Claude Opus 5 into its runtime. Before a new model reaches local tools, the operator still has to decide whether the session runs automatically, asks first, uses risk-based approval, or stays in chat.

2 stories 7 source signals 1 repo
July 26, 2026

An Agent’s Answer Begins in the Harness

The model only sees the task after a runtime has edited its context, carried forward state, and decided what survived the last turn—so the first question after a bad run is what the harness made it see.

5 stories 17 source signals 6 repos
July 23, 2026

The 67,000-Star Repo That Changed What It Was

Open Interpreter’s GitHub audience remembers a Python computer agent. The code behind the same counter is now a Rust fork of Codex—and almost all of the stars arrived before that switch.

3 stories 12 source signals 6 repos
July 21, 2026

An Agent's Sign-In Link Is Not a Timeout

OpenWork's newest MCP work carries a provider's structured authorization link through a failed tool call, so the person who owns the account can act instead of watching an agent retry the wrong problem.

3 stories 8 source signals 3 repos
July 20, 2026

The Diff Can't Be Guesswork Once an Agent Writes

OpenClaw is making a simple rule explicit: when an agent writes a file, a review surface should show the patch it can prove—and show uncertainty when it cannot.

3 stories 10 source signals 3 repos
July 19, 2026

A Computer-Use Agent Needs a Second Meaning of Success

Hermes now tells a desktop-driving agent whether an input merely reached a driver or was actually confirmed to have changed the interface—and it makes foreground escalation a separate decision.

2 stories 7 source signals 2 repos
July 18, 2026

Gemini CLI’s Caretaker Has Permission to Read, Not to Act

Gemini CLI’s new issue-triage worker gives its model a read-only repository view, then keeps labels, comments, retries, and escalation in a separate validated program.

2 stories 8 source signals 2 repos
July 17, 2026

The Hard Part of an Agent Protocol Rewrite Is Yesterday

Tau is replacing its legacy agent protocol with Pi-compatible shapes, but its more consequential promise sits at the JSONL boundary: old sessions are meant to cross without pretending the old runtime still exists.

3 stories 11 source signals 2 repos
July 16, 2026

Codex Keeps the Prompt After You Interrupt It

A new Codex TUI change treats an interrupted request as part of the record, then gives the next instruction a clean composer.

2 stories 7 source signals 2 repos
July 15, 2026

Background Agent Work Needs a Receipt

Hermes and OpenClaw are fixing different failure windows in the same promise: delegated work has to arrive somewhere a person can use it.

4 stories 9 source signals 4 repos
July 14, 2026

Codex Makes Thread History a Rebuildable View

Two fresh commits separate a coding agent’s durable JSONL record from its fast SQLite history view—and teach that view how to catch up after it falls behind.

3 stories 19 source signals 7 repos
July 13, 2026

OpenWork Gives MCP Failures a Useful Address

A new diagnostics layer separates DNS, TLS, HTTP, OAuth, protocol, and provider failures, then returns a bounded reference and the person who can act—without logging the raw connection secret trail.

2 stories 10 source signals 2 repos
July 12, 2026

Hermes Turns Health Checks Into a Runtime Contract

A new authenticated readiness endpoint checks the parts of an agent gateway that can make it unreliable—without reading payloads, leaking configuration, or trying to repair anything.

5 stories 23 source signals 2 repos
July 11, 2026

Entire Gives Agent Work a Separate Git Address

The CLI stores prompts, tool calls, touched files, and now images on a checkpoint branch—making an AI coding session resumable, and potentially shareable by accident.

4 stories 21 source signals 3 repos
July 10, 2026

OpenWork Makes MCP Sessions Durable

OpenWork's July 9 commits changed cloud auth and MCP client state so agent connections can survive refresh, offline access, and cross-origin client paths.

5 stories 28 source signals 8 repos
July 9, 2026

Agent Runtimes Move Trust To The Exit Gate

OpenClaw, Codex, and Hermes all changed runtime trust surfaces this week, making the last moment before a tool call, secret handoff, or approval the place operators need to inspect.

4 stories 17 source signals 4 repos
July 8, 2026

Gemini CLI Turns Issue Triage Into A Caretaker Worker

Gemini CLI added a caretaker triage worker and GitHub egress handler, moving issue sorting toward an agent-run workflow with locks, retries, labels, comments, and human handoff states.

6 stories 25 source signals 11 repos
July 7, 2026

OpenClaw Makes Agent Audit Trails A Runtime Contract

OpenClaw added a metadata-only audit ledger on July 6, giving operators a way to inspect agent run events, native-search outcomes, tool actions, statuses, and errors without opening full transcripts.

4 stories 23 source signals 3 repos
July 6, 2026

Hermes Makes Yolo Obey User Deny Rules

Hermes added `approvals.deny` on July 5, giving users glob rules that block terminal commands even when the agent is running in yolo or approvals-off mode.

5 stories 30 source signals 4 repos
July 5, 2026

OpenCode Turns OpenAPI Into Agent Tool Contracts

OpenCode merged a CodeMode OpenAPI adapter on July 4, giving hosts a way to turn API specs into model-visible tools while keeping credentials and unsupported operations outside the agent's reach.

4 stories 18 source signals 2 repos
July 4, 2026

OpenWork Makes Team Memory A Governed Agent Surface

OpenWork's July 2 Memory Bank merge turns saved agent context into a user-scoped, searchable capability with tests, schema checks, and explicit no-secrets guidance.

4 stories 19 source signals 2 repos
July 3, 2026

OpenCode Turns Agent Review Into A First-Class Work Surface

A July 2 review-panel overhaul moves OpenCode's agent output closer to a readable control surface for changed files, comments, media, and stability checks.

4 stories 21 source signals 2 repos
July 2, 2026

OpenClaw Lets Agents Wake After A Command Exits

OpenClaw added an on-exit cron schedule so a gateway-owned watcher can wake an agent after a watched process finishes.

4 stories 15 source signals 3 repos
July 1, 2026

Hermes Makes Agent Approvals Thread-Local

Hermes replaced a shared approval flag with thread-local state, then paired that control with secret redaction and delegation-budget tests.

5 stories 28 source signals 4 repos
June 30, 2026

OpenClaw Narrows Who Can Wake An Agent

A cluster of OpenClaw commits put scheduled wakes, ACP runtime controls, and browser proxy invocation behind narrower target and scope checks.

4 stories 14 source signals 4 repos
June 29, 2026

Tau Turns Agent Architecture Into Onboarding

A Tau documentation rewrite moved the coding-agent project from build-log internals toward a public quickstart, reference, package, and license surface.

4 stories 14 source signals 4 repos
June 28, 2026

Codex Makes Plugin Trust Runtime Policy

A new Codex plugin patch turns marketplace source restrictions into runtime filtering, loading, and cache-refresh behavior.

2 stories 11 source signals 2 repos
June 27, 2026

Agent Safety Gates Catch Edge Cases

Gemini CLI, OpenClaw, and Hermes all turned ordinary boundary mistakes into explicit control failures.

2 stories 10 source signals 3 repos
June 26, 2026

Mistral Vibe Makes ACP Compatibility A Release Contract

Mistral Vibe 2.18.0 turns ACP behavior, editor setup, auth cleanup, and fork-session limits into release-visible evidence.

2 stories 11 source signals 2 repos
June 25, 2026

OpenWork Puts Self-Hosting On The Checklist

OpenWork's June 24 code changes make deployment configuration, readiness, packaging, and user-flow proof visible as project maturity work.

2 stories 11 source signals 2 repos
June 24, 2026

Model Catalogs Get Plain-English Receipts

LangChain and Pi are making model/provider changes easier to inspect before they become hidden assumptions inside agent runtimes.

2 stories 13 source signals 3 repos
June 23, 2026

Agent Control Hints Become Runtime Contracts

Fresh OpenClaw, Codex, and Hermes changes show agent projects turning speed modes, chat metadata, and worker instructions into explicit runtime surfaces.

2 stories 18 source signals 5 repos
June 22, 2026

Agent Tools Get Back-Pressure Surfaces

Fresh Gemini CLI and OpenWork patches show agent products turning hangs, publish failures, voice quotas, and provider outages into explicit runtime behavior.

2 stories 12 source signals 3 repos
June 21, 2026

Agent Runtimes Are Learning When To Stop

Fresh OpenCode, Codex, OpenClaw, and Hermes Agent patches show agent tools turning long-running work into bounded, traceable runtime state.

2 stories 11 source signals 4 repos
June 20, 2026

Agent Tools Are Getting Capability Switches

Fresh Codex, Hermes Agent, and Pi patches show agent projects narrowing when external skills, MCP tools, and package surfaces become visible.

2 stories 13 source signals 3 repos
June 19, 2026

Agent Control Panels Move Into The Terminal

Hermes Agent, OpenClaw, and Codex all moved user-facing control surfaces closer to the agent runtime, from billing and provider setup to structured MCP prompts.

2 stories 11 source signals 3 repos
June 18, 2026

Mistral Vibe Turns Release Claims Into Trust Boundaries

The v2.16 release line says workspace trust, resume speed, diff rendering, SSE parsing, and backend reasoning behavior are no longer only UX claims; several now have code and tests behind them.

2 stories 11 source signals 2 repos
June 17, 2026

OpenWork Turns OpenCode Into A Team Workbench

The OpenCode-powered project is building a local-first desktop and server layer so agent work can be run, shared, permissioned, and audited from one product surface.

2 stories 11 source signals 2 repos
June 16, 2026

Agent Tools Are Moving Safety Into Boundaries

Gemini CLI, LangChain, and Codex landed fresh patches that put agent safety in filesystem checks, type gates, pending-tool waits, and permission-path parsing.

2 stories 8 source signals 3 repos
June 15, 2026

Agent Clients Are Learning Where Work Belongs

Fresh Codex, OpenCode, and Pi patches show agent interfaces routing threads, draft sessions, and terminal setup by local context before the user acts.

2 stories 10 source signals 3 repos
June 14, 2026

Agent Sessions Are Getting Recovery Paths

Fresh OpenClaw, OpenCode, Hermes Agent, and Codex patches show agent tools treating interruption and recovery as runtime work, not edge-case cleanup.

2 stories 8 source signals 4 repos
June 13, 2026

Agent Context Gets Filesystem Boundaries

Fresh Crush, Codex, OpenClaw, and OpenCode changes show agent runtimes separating user memory, project context, and sandbox paths before work starts.

2 stories 16 source signals 5 repos
June 12, 2026

Agent Tools Are Getting Credential Boundaries

Fresh OpenCode, OpenClaw, Hermes Agent, and Codex commits show tool access becoming a credential and trust-routing problem, not only a menu of callable functions.

2 stories 9 source signals 4 repos
June 11, 2026

Agent Tooling Gets Runtime Guardrails

Fresh OpenCode, LangChain, Gemini CLI, Codex, and OpenClaw commits show agent projects tightening the machinery around tools, sessions, streams, and approvals.

2 stories 14 source signals 5 repos
June 9, 2026

Agent Trust Is Moving Before the First Tool Call

Fresh Pi, OpenClaw, and Codex changes point to a quieter layer of agent safety: decide what a project may load, what a gateway may carry, and what execution context a thread owns before the model starts acting.

2 stories 22 source signals 3 repos
June 8, 2026

Agent Automation Is Becoming Scheduled Operations

Fresh OpenClaw, Codex, and Hermes Agent commits show agent work moving beyond the foreground chat turn into scheduled jobs, background threads, heartbeat runs, and provenance-aware session rotation.

1 story 6 source signals 3 repos
June 7, 2026

Agent Setup Is Becoming Runtime Onboarding

Fresh OpenClaw, Hermes Agent, and Codex commits show agent tools trying to erase the gap between "this capability exists" and "a user can actually run it."

1 story 6 source signals 3 repos
June 6, 2026

Agent Control Is Moving Into the Live Interface

Fresh OpenClaw, Crush, Hermes Agent, and Codex commits show approvals, steering, and configuration errors moving from background policy into the moments where a human can actually change an agent run.

2 stories 12 source signals 6 repos
June 5, 2026

Agent Identity Is Becoming Runtime Infrastructure

Fresh Hermes Agent, OpenClaw, and Codex commits show profile, credential, and model-choice state moving out of setup screens and into live agent runtime controls.

2 stories 22 source signals 5 repos
June 4, 2026

Agent Events Are Getting Return Addresses

Fresh Hermes Agent, Crush, OpenClaw, and Codex commits show agent runtimes attaching correlation, provenance, and client identity to events so the right run, session, surface, or device receives them.

2 stories 25 source signals 6 repos
June 3, 2026

Agent Failure States Are Becoming Instructions

Fresh LangChain, Crush, Gemini CLI, and OpenClaw commits show agent tools turning denial, fallback, routing, and policy drift into explicit next steps.

2 stories 14 source signals 8 repos
June 2, 2026

Agent Work Is Getting a Back Button

Fresh Codex and Hermes commits show a practical shift in agent tooling: longer-running work now needs recovery rails, not just more controls.

1 story 4 source signals 2 repos
June 1, 2026

Agent Policy Is Moving Into Delivered Layers

Fresh Codex and Hermes commits point to a new control-plane pressure: the rules an agent follows are starting to arrive as cloud bundles, layered requirements, and entitlement-aware tool setup instead of only local config choices.

1 story 5 source signals 2 repos
May 31, 2026

Agent Tool Menus Are Becoming Runtime Infrastructure

Fresh Codex and Hermes commits show a quieter agent shift: the visible list of tools is becoming a runtime contract about what can be suggested, enabled, discovered, and checked without breaking the session.

1 story 5 source signals 2 repos
May 30, 2026

Agent Control Settings Are Becoming Session State

Fresh Codex and Hermes commits show a quieter agent shift: permissions, tool behavior, lineage, approval context, and auth fallbacks are being treated as state that has to survive the next turn.

1 story 6 source signals 2 repos
May 29, 2026

Agent Sandboxes Are Learning Their Cleanup Rules

Fresh Codex and Hermes commits point to a practical agent shift: the local machine is becoming part of the runtime contract, with workspace roots, filesystem denies, Docker persistence, orphan cleanup, and lifecycle commands written down in code.

1 story 7 source signals 2 repos
May 28, 2026

Agent UI Is Becoming the Control Room

Fresh commits in Codex, Hermes, and Gemini CLI point to a practical agent shift: the human interface is turning into the place where long-running work gets linked, stopped, switched, and steered.

1 story 5 source signals 3 repos
May 27, 2026

Agent Context Becomes Runtime State

Fresh commits in Codex, Gemini CLI, and Hermes point to a quieter agent shift: context is being stored, routed, measured, and traced instead of merely stuffed into prompts.

1 story 8 source signals 3 repos
May 25, 2026

Agent Reliability Is Moving Into the Test Rig

The newest source-readable trail points away from model mystique and toward the workflows that test, trace, serialize, and maintain agent behavior.

1 story 5 source signals 2 repos
May 24, 2026

Agent Runtimes Are Learning Where to Say No

After shipping more visible control planes, agent projects are now tightening the places where tools, plugins, credentials, chat context, and test runs are allowed to flow.

1 story 6 source signals 3 repos
May 23, 2026

Agent Runtimes Are Learning to Ship Their Control Plane

A set of Codex, Hermes Agent, Gemini CLI, and Crush commits shows agent tools packaging the machinery around the model: shells, platform adapters, context profiles, and skill catalogs.

1 story 13 source signals 5 repos
May 22, 2026

Agent Runtimes Are Making Their Limits Explicit

Recent Crush and LangChain changes show agent infrastructure turning hidden boundaries - shell permission, context overflow, and model token limits - into runtime contracts that users and developers can see.

1 story 8 source signals 2 repos
May 21, 2026

Agent Goals Are Becoming Runtime State

Recent Codex and Hermes Agent changes show coding agents turning goals from chat commands into durable metadata, resumable session state, and queued work control.

1 story 7 source signals 2 repos
May 20, 2026

Agent Runtimes Are Moving State Out of the Shadows

Recent Codex and Gemini CLI changes show coding agents treating settings, queued input, subagent starts, and terminal streams as explicit runtime state instead of invisible side effects.

1 story 9 source signals 2 repos
May 19, 2026

Agent Runtimes Are Learning to Audit Their Own Tools

Fresh Codex and Gemini CLI changes show agent projects treating tool calls, plugins, MCP servers, and subagents as auditable runtime events instead of invisible helper work.

1 story 8 source signals 2 repos
April 1, 2026

Agent CLIs Are Turning Permissions Into a Conversation

The next shift in terminal agents is not just better tools or tighter sandboxes. It is that permissions are becoming live workflow state: negotiated mid-task, scoped to the action, and remembered with just enough structure to keep work moving.

2 stories 8 source signals 4 repos
March 31, 2026

The Real Agent Feature Is Not Losing the Plot

The next terminal-agent moat is not just better tools or bigger models. It is continuity: whether the system can keep plans, transcripts, and working context coherent as sessions stretch, compress, resume, and hit real-world friction.

2 stories 2 source signals 5 repos
March 30, 2026

The CLI Is Becoming an Agent Workbench

The real shift in terminal agents is not bigger models or flashier demos. It is that planning, task state, plugins, and long-lived runtime context are turning the CLI into a place where work gets organized, not just requested.

2 stories 8 source signals 3 repos
March 29, 2026

From Tool Chatter to Chapters: Agent CLIs Are Inventing a Narrative Layer

The interesting shift this week isn’t just that Codex and Gemini CLI can do more. It’s that they’re getting better at explaining themselves while they work —turning raw tool noise into something a human can actually follow.

2 stories 25 source signals 3 repos
March 28, 2026

The Next Agent UX Moat Isn’t Speed. It’s Backpressure.

The hard problem in terminal agents is no longer just getting them to do more. It’s deciding what happens when the human tries to steer while the runtime is already busy.

2 stories 12 source signals 3 repos
March 27, 2026

Subagents Aren’t Just Getting Smarter. They’re Getting Contained.

The next terminal-agent upgrade is not more helpers. It’s better walls: isolation, cleanup, bounded autonomy, and fewer chances for delegated work to spill across the room.

2 stories 12 source signals 4 repos
March 26, 2026

The CLI Is Quietly Becoming an Agent Router

The next terminal-agent shift is not another flashy planning demo. It is the quieter, harder job of helping remote agents actually connect: across protocols, proxies, auth flows, and messy metadata.

2 stories 8 source signals 4 repos
March 25, 2026

The New CLI Moat Isn’t UX. It’s How Agent Skills Get Shipped

This week’s most strategic terminal-agent shift is not another demo flourish. It’s the quiet work of turning capabilities into things that can be packaged, cached, moved, and trusted.

2 stories 5 source signals 5 repos
March 24, 2026

The Next CLI UX Battle Is Agent Forensics

The most important agent upgrade this week is not another tool. It’s the growing ability to reconstruct why an agent touched files, spent tokens, and arrived at a code change in the first place.

2 stories 6 source signals 3 repos
March 23, 2026

Codex forks it, Gemini threads it: execution context becomes first-class

The next big agent primitive is not another tool call. It’s the bundle of permissions, environment, policy, and wiring that tells an agent how to exist for this turn, in this loop, right now.

1 story 3 source signals 2 repos
March 22, 2026

Parallel agents are getting real addresses

This week’s most important agent upgrade isn’t more raw intelligence. It’s workplace logistics. Gemini CLI is giving parallel sessions separate rooms. Codex is giving subagents names you can actually point at.

1 story 4 source signals 2 repos
March 21, 2026

AI agents are getting better at saying “here’s what I finished”

The real upgrade this week isn’t bigger context or flashier autonomy. It’s something more human: when an agent stalls, waits, delegates, or times out, it’s starting to leave behind a useful trail instead of a shrug.

1 story 1 source signal 3 repos
March 20, 2026

Before the Prompt Lands: Codex and Gemini Turn Hooks Into Agent Control Planes

Terminal agents are growing a new kind of muscle: not just better tools, but better middleware. In both Codex and Gemini CLI, the moment right after you hit Enter is becoming programmable territory.

1 story 2 source signals 2 repos
March 19, 2026

Gemini Lets the Model Schedule Parallel Tools. Codex Makes the Runtime Decide.

Terminal agents are learning the same trick — run more tools at once — but Gemini CLI and OpenAI Codex disagree on who should be in charge of that decision. One pushes dependency control up into the prompt and tool schema. The other keeps it down in runtime metadata and locks.

1 story 4 source signals 2 repos
March 18, 2026

Subagents Grow Up: Gemini Isolates Tool Boundaries While Codex Shares Trust by Default

Two agent platforms shipped subagent changes within hours of each other. One tightened what a child agent can see and use . The other tightened what a child agent can teach the rest of the system to trust . Same category. Very different instinct.

1 story 5 source signals 3 repos
March 15, 2026

OpenViking Turns Agent Memory into a Filesystem — and That Changes the Game

Agent memory has felt like a junk drawer: we throw context in, pray the model finds it, and hope the glue holds. OpenViking’s bet is bolder — treat memory like an operating system, not a sho...

1 story 1 source signal 2 repos
March 14, 2026

Gemini CLI Turns File Tools into Context Sensors — Right as A2UI Trends

Today’s GitHub Trending list says the same thing twice in different languages. A2UI is climbing because teams want UI‑level schemas that keep agents from guessing. At the same time, Gemini C...

1 story 3 source signals 1 repo
March 13, 2026

Gemini CLI Built the Ask‑User UI That MCP Elicitation Still Needs

Elicitation is the moment an agent has to stop and ask you a question — a human speed bump that keeps automation honest. This week, Gemini CLI users reported MCP servers failing with a “Meth...

1 story 4 source signals 2 repos
March 12, 2026

Page Agent’s MacroTool Makes In‑Browser Agents Resilient to Messy Tool Calls

GitHub’s trending list has been noisy with “agent frameworks,” but Alibaba’s page-agent stands out because it runs inside the web page instead of driving a separate headless browser. That ar...

1 story 2 source signals 3 repos
March 11, 2026

Gemini CLI Makes MCP List-Changed Notifications Resilient

Gemini CLI’s PR #21050 fixes a rough edge in MCP notifications: tools/list_changed updates could be missed, leaving clients out of sync with what a server actually offers. The client now reg...

1 story 2 source signals 1 repo
March 10, 2026

Codex Makes Memories a First-Class Writable Root—and Stops Cleaning Through Symlinks

Codex just turned its “memories” folder from a side alley into a well-lit main road. And it put a lock on the janitor’s closet so cleanup can’t accidentally bulldoze someone else’s house. Th...

1 story 1 source signal 1 repo
March 9, 2026

Gemini CLI tightens MCP tool discovery: debounced list_changed refresh, trailing queue, and resilient retries

Gemini CLI’s MCP integration has been steadily gaining real-time awareness of server-side tool changes. A local search trail points to early MCP notifications support landing on 2026-01-08 (...

1 story 1 source signal 2 repos
March 8, 2026

Codex Rust CLI Update: Memory Writes Now Fit “workspace-write” and Safer Clears Land in f72ab43

The Codex Rust CLI just got a small but meaningful quality-of-life upgrade—one that also tightens safety around memory cleanup. In PR openai/codex#13467 (commit f72ab43fd193b31208cd3c306293b...

1 story 1 source signal 1 repo
March 7, 2026

Gemini CLI Makes a “Generalist” Sub-Agent the Default Delegate

TheGitReporter — In a recent core change, Gemini CLI quietly shifted delegation from an opt-in feature to a baseline capability. Gemini CLI has landed a new default behavior: a built-in gene...

1 story 1 source signal 1 repo
March 6, 2026

Gemini CLI and Codex Level Up MCP Safety and Setup: Trust Prompts vs Auto-Install Skills

Two CLI assistants walk into the same tooling bar. One checks IDs at the door; the other quietly installs the band’s gear before the show starts. Gemini’s new “trust, but verify” moment Gemi...

1 story 2 source signals 2 repos
March 5, 2026

Persistence vs Freshness: Codex and Gemini CLI Tighten Two Different Boundaries for Agent Workflows

On March 4, 2026, two quiet merges landed on opposite sides of the agentic tooling ecosystem—both aimed at making “hands-off” workflows less surprising. OpenAI’s Codex and Google’s Gemini CL...

1 story 2 source signals 2 repos