Category
Ai Agents
Latest
Don't Run That headersHelper Blind — Claude Code 2.1.238 Moves the MCP Trust Boundary
Starting in Claude Code 2.1.238, project and plugin headersHelper commands require folder trust and strip credential-like env vars. Treat shared .mcp.json as a shell execution surface — with a practical checklist.
Before @GitHub Ships From Slack — Code Channels and the Trust Boundary
GitHub’s 2026-08-21 Slack agentic preview. Lock write access, app-identity PRs, extra approvals, and cloud-agent budgets before the first @mention.
Don't Code the First Mock — What Claude Code /design Actually Changes
Claude Code's /design research preview (≈2026-08-17) adds editable UI artboards before implementation. Treat it as a review gate — not 'design system solved.'
Don’t Flip On MAI-Code-1.1-Flash From the Changelog Alone — Watch the September 10 Clock
MAI-Code-1.1-Flash rolled out in Copilot on Aug 11. Business policy is off by default; MAI-Code-1-Flash retires Sep 10. Don’t mix 0.25× with usage-based list prices.
Claude Code Flips to Auto Mode on August 14 — Set Your Boundaries Before It Does
Pro, Max, and Team new sessions default to auto mode. It is a classifier gate—not bypass. Pin ask rules and autoMode.environment before the flip.
When a Comment Wakes the Agent — Trust Handoff After Black Hat 2026
In Black Hat USA 2026 week, comment-triggered Copilot automations landed beside research showing GitHub text can hijack coding agents. Treat comments as untrusted tool input.
Small PRs for the Agent Era — GitHub Stacked PRs and Copilot Stacked Sessions
GitHub’s 2026-07-30 public preview of stacked PRs plus Copilot stacked sessions: make agent output reviewable layers with gh-stack, not one mega-diff.