Agent Tools Are Moving Safety Into Boundaries
Gemini CLI, LangChain, and Codex landed fresh patches that put agent safety in filesystem checks, type gates, pending-tool waits, and permission-path parsing.
More From This Edition
All editions ›Recent Editions
Full history ›The Cookie Jar Between Two Agent Sessions
Microsoft’s Agent Framework is changing what its Python HTTP clients remember. A new conversation can still inherit an old login when both use the same cookie jar.
The Fine Print Behind Kilo’s Swarm Default
Kilo’s main branch now enables a shared agent board by default. Its messages can carry findings across a team—but a successful post cannot summon a worker, prove it listened, or stop it.
A Child Agent Can't Promise Its Watcher to the Parent
Hermes now makes a child wait, kill, or formally hand over background work before it returns—ending one treacherous kind of progress report.
A Computer-Using Agent Needs a Room, Not a House Key
OpenWork’s merged macOS 14+ preview gives a desktop-driving agent one person-approved window and a short-lived native session—a meaningful boundary, but not an operating-system sandbox.
How AI Agents Work
The long-form map behind the daily paper: context, tools, loops, memory, delegation, safety, interface, and trust.