Policy dependency / Stack layer
'Do this as quickly as possible' repeatedly got a Claude session flagged by a corporate security director
r/ClaudeAI
Stack layer / Threat pattern
Zvi reads Anthropic's misuse report and says the real threat is Chinese labs distilling Claude, not any of the six other categories
Don't Worry About the Vase (Zvi Mowshowitz)
Policy dependency / Stack layer
Commerce Department Ordered Kalshi to Pull Its AI Compute Futures Curves, Then Denied Doing So
Semafor
Policy dependency / Stack layer
Python's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or Critical
arXiv 2609.14791
Policy dependency / Stack layer
Claude Code adds omitClaudeMd so subagents can run without inherited CLAUDE.md, and a sha256 plugin-install accept flag
GitHub
Policy dependency / Stack layer
Ordewell uses a read-only coding agent as planner, then spawns per-task agent sessions gated by a marker-based verdict engine
GitHub
Stack layer / Threat pattern
Cline Leaves the IDE: a Standalone Desktop Agent That Imports Claude Code and Codex Sessions and Schedules Recurring PR Reviews
Cline GitHub releases (launch reported by RuntimeWire, version cadence verified on the repo)
Stack layer / Threat pattern
Three security scanners disagree on 23,702 of the 61,990 agent skills they all cover, and 85% of readable skills carry privilege evidence
arXiv