Agent Runtimes Move Trust To The Exit Gate
OpenClaw, Codex, and Hermes all changed runtime trust surfaces this week, making the last moment before a tool call, secret handoff, or approval the place operators need to inspect.
More From This Edition
All editions ›Builder Work: Ralphy Gives Coding Agents A Video Runtime
LangChain Stops Retries From Eating Interrupts
API Discovery: Ma Cantine Turns Lunch Rules Into Agent Checklists
Recent Editions
Full history ›An Agent’s ‘No’ Needs a Way Back—But Not a Shortcut
Qwen Code now offers one manual review only for the exact action its AUTO mode blocked—turning a false positive into an accountable decision instead of a workaround hunt.
Hermes Decides That a Preference Can Have a Home
Hermes is redrawing a deceptively important line: a correction learned while doing one task belongs with that task's skill, while persistent memory is for facts that should matter everywhere.
Before Codex Trusts a Workspace, It Stops Letting the Workspace Choose Its Helpers
A merged Codex change moves automatic pre-trust helper lookups to known system locations, sanitizes plugin-sync Git, and makes diagnostics inspect a workspace-influenced path without running what they find.
A Child Agent’s Approval Request Shouldn’t Hide in Another Tab
Openwork now brings a child session’s blocked permission into the parent task; fresh Goose state-machine work shows why seeing the ask is only half the control.
How AI Agents Work
The long-form map behind the daily paper: context, tools, loops, memory, delegation, safety, interface, and trust.