OpenHands: separating the software agent from the sandbox it works in
A new healthy-local-backend fallback makes the project’s larger argument concrete: the thing that helps a person steer an agent must stay legible even when the agent is running somewhere else.
More From This Edition
All editions ›The Harness Was Taking the Test Too
Builder Work: A Sandbox Is Reusable Only After It Forgets
API Discovery: Make the Model Own Its Web Search
Recent Editions
Full history ›A Child Agent Can't Promise Its Watcher to the Parent
Hermes now makes a child wait, kill, or formally hand over background work before it returns—ending one treacherous kind of progress report.
A Computer-Using Agent Needs a Room, Not a House Key
OpenWork’s merged macOS 14+ preview gives a desktop-driving agent one person-approved window and a short-lived native session—a meaningful boundary, but not an operating-system sandbox.
No Mail Server Is Not a Free Pass
QM’s new admin-login route lets an already authorized administrator open a portal before outbound email exists—but only through a five-minute, origin-bound, one-use handoff that gets checked again at the door.
An Agent’s ‘No’ Needs a Way Back—But Not a Shortcut
Qwen Code now offers one manual review only for the exact action its AUTO mode blocked—turning a false positive into an accountable decision instead of a workaround hunt.
How AI Agents Work
The long-form map behind the daily paper: context, tools, loops, memory, delegation, safety, interface, and trust.