Policy dependency / Stack layer
Appending a Security-Requirements Section to a Vibe-Coding Prompt Cut Confirmed Findings From 51 to 24 Across Six Web Apps
arXiv 2608.20963
Stack layer / Threat pattern
ClawSentry cuts skill-injection attack success from 39.55% to 2.61% across Codex, Claude Code, Kimi CLI and Gemini CLI
arXiv
Stack layer / Threat pattern
Unlose Takes Windows VSS Snapshots Before Coding Agents Run, Rejecting the Command-Blocking Approach
GitHub (via Show HN, 2026-08-25)
Stack layer / Contrast
Microsoft's Agent Lightning v1.0.1 ships an agent skill whose job is optimizing other agents, installed through gh skill
GitHub
Stack layer / Contrast
Qwen shipped a codesigned computer-use driver as a standalone binary and npm SDK, split out from qwen-code
GitHub
Stack layer / Contrast
Anthropic's own weekly sales digest runs on Claude Code plus a BigQuery MCP connector and nine hand-written content rules
Claude by Anthropic
Stack layer / Threat pattern
CROSS-CATEGORY: The Agent Control Plane Is Now a Priced Category, Selling Governance Over Agents Employees Already Built
Product Hunt (Decawork and Kastra product pages)
Stack layer / Threat pattern
SkillPreflight Publishes a 100-Point Scorecard for Agent Skills and a Benchmark of 40 Public Ones
GitHub (via Show HN, 2026-08-25)