Agent Sandboxes Are Learning Their Cleanup Rules
Fresh Codex and Hermes commits point to a practical agent shift: the local machine is becoming part of the runtime contract, with workspace roots, filesystem denies, Docker persistence, orphan cleanup, and lifecycle commands written down in code.
Edition File
All editions ›Recent Editions
Full history ›An Agent's Sign-In Link Is Not a Timeout
OpenWork's newest MCP work carries a provider's structured authorization link through a failed tool call, so the person who owns the account can act instead of watching an agent retry the wrong problem.
The Diff Can't Be Guesswork Once an Agent Writes
OpenClaw is making a simple rule explicit: when an agent writes a file, a review surface should show the patch it can prove—and show uncertainty when it cannot.
A Computer-Use Agent Needs a Second Meaning of Success
Hermes now tells a desktop-driving agent whether an input merely reached a driver or was actually confirmed to have changed the interface—and it makes foreground escalation a separate decision.
Gemini CLI’s Caretaker Has Permission to Read, Not to Act
Gemini CLI’s new issue-triage worker gives its model a read-only repository view, then keeps labels, comments, retries, and escalation in a separate validated program.
How AI Agents Work
The long-form map behind the daily paper: context, tools, loops, memory, delegation, safety, interface, and trust.