Agent Tools Are Moving Safety Into Boundaries
Gemini CLI, LangChain, and Codex landed fresh patches that put agent safety in filesystem checks, type gates, pending-tool waits, and permission-path parsing.
More From This Edition
All editions ›Recent Editions
Full history ›An Approval Cannot Outlive the Conversation That Asked for It
Cline fixed a small but revealing failure in its VS Code extension: change a message while a command approval is waiting, and the old run could keep waiting forever—then catch answers meant for the new one.
QM is trying to turn the personal agent into company infrastructure
Y Combinator's new open-source harness does not win its case by running Codex or Claude in Slack. Its more consequential bet is that every person and room needs a clearly owned memory, workspace, permission set, schedule, and durable computer.
Browser Use: the control boundary between an agent and the live web
Browser Use’s latest harness release and its own session examples make a harder point than a benchmark: browser automation only becomes legible when profile, destination, and data authority are named controls.
OpenHands: separating the software agent from the sandbox it works in
A new healthy-local-backend fallback makes the project’s larger argument concrete: the thing that helps a person steer an agent must stay legible even when the agent is running somewhere else.
How AI Agents Work
The long-form map behind the daily paper: context, tools, loops, memory, delegation, safety, interface, and trust.