Policy dependency / Stack layer
Agents hallucinate tools that do not exist, a 675B model does it as often as a 7B one, and merging MCP servers adds new failure surfaces
arXiv 2609.19425
Policy dependency / Stack layer
Claude Code 2.1.277 reads AGENTS.md when there is no CLAUDE.md, and subagent output now carries an anti-spoofing header
Claude Code changelog
Stack layer / Threat pattern
MAGS routes coding-agent output through Dafny and reports 100% success at producing verified programs on 220 tasks
arXiv
Stack layer / Threat pattern
An Auto-Optimized Agent Harness Can Cheat the Whole Benchmark, Not Just the Tasks
arXiv 2609.18366
Stack layer / Threat pattern
Plugin4Shell: One SHA-Pinning Bug Gives Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLI
Help Net Security (corroborated by The Register)
Policy dependency / Stack layer
43 Machine-Checkable EU AI Act Criteria That Run in CI and Emit Article-Indexed Evidence
arXiv 2609.20016
Stack layer / Threat pattern
Recording an Agent Run at Its Non-Deterministic Boundaries Turns an Incident Into a CI Regression Test
arXiv 2609.20625
Policy dependency / Stack layer
ICML position paper: every agent framework has reimplemented an operating system badly, so build the OS layer
arXiv