August 29, 2026 / Daily Edition / 2 stories in this issue
Lead Story Sources +3

A Restricted Workspace Should Not Start Its Own Tools

Gemini CLI now gives an explicitly restricted or untrusted workspace a narrower configuration path: repository-defined tools, MCP servers, policies and telemetry no longer accompany its A2A server into startup.

Marker diagram showing a restricted-mode signal crossing out repository MCP, policy, tool and telemetry cards before an A2A server receives trusted configuration.
Diagram Punkrestricted should cut repository startup authority before the server sees it.
repo google-gemini/gemini-cli evidence
3 source signals 1 repo commit 0bd1d43
Evidence: commit 0bd1d43 / August 29, 2026 / Daily Edition
Read article + evidence

More From This Edition

All editions ›

Recent Editions

Full history ›
Agent Atlas

How AI Agents Work

The long-form map behind the daily paper: context, tools, loops, memory, delegation, safety, interface, and trust.

Open Atlas
2 articles 1 repo detected 6 source signals 10 atlas chapters