Policy dependency / Stack layer
A Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May Touch
arXiv 2609.15422
Policy dependency / Stack layer
Claude Code adds omitClaudeMd so subagents can run without inherited CLAUDE.md, and a sha256 plugin-install accept flag
GitHub
Stack layer / Threat pattern
Cline Leaves the IDE: a Standalone Desktop Agent That Imports Claude Code and Codex Sessions and Schedules Recurring PR Reviews
Cline GitHub releases (launch reported by RuntimeWire, version cadence verified on the repo)
Stack layer / Threat pattern
Amodei puts a 6-12 month clock on an agent swarm that could run a persistent internet-wide botnet, and opens Anthropic to outside evaluators
VentureBeat
Stack layer / Contrast
Claude Code lowers the medium dynamic-workflow guideline from 15 agents to 10, and defaults Pro plans to small
Claude Code Changelog
Stack layer / Contrast
Swift-Qwen3.8-27B cuts thinking tokens 58.3% with on-policy distillation and under 1% accuracy loss
r/LocalLLaMA (800 upvotes, 306 comments; verified against huggingface.co/api/models/ukisai/Swift-Qwen3.8-27b)
Policy dependency / Stack layer
HazardAuditor runs Claude Code, Codex, Hermes and OpenClaw in one harness and normalizes their events to train a guard model
arXiv / HuggingFace Daily Papers
Stack layer / Threat pattern
OpenAI's 'Project Lily' Has Hundreds of Contractors Reading Real ChatGPT Conversations
404 Media