Agent Tools Are Getting Credential Boundaries
Fresh OpenCode, OpenClaw, Hermes Agent, and Codex commits show tool access becoming a credential and trust-routing problem, not only a menu of callable functions.
More From This Edition
All editions ›Recent Editions
Full history ›An Agent Framework Can Carry Your Request—Not Your Responsibility
Microsoft Agent Framework's newest A2A and BYOK samples make one quiet operating rule visible: let a caller's configuration cross the boundary, but leave the host's policy and the provider's obligations where they belong.
When an Agent Sees Two MCP Servers Called Docs
OpenClaw’s Code Mode has a new answer to a quietly consequential question: when several connected machines offer a server called docs , how does an agent know which one it is calling?
Before Goose Runs a New Model, Pick Its Permission Mode
Goose has mapped Claude Opus 5 into its runtime. Before a new model reaches local tools, the operator still has to decide whether the session runs automatically, asks first, uses risk-based approval, or stays in chat.
An Agent’s Answer Begins in the Harness
The model only sees the task after a runtime has edited its context, carried forward state, and decided what survived the last turn—so the first question after a bad run is what the harness made it see.
How AI Agents Work
The long-form map behind the daily paper: context, tools, loops, memory, delegation, safety, interface, and trust.