Fetching from the wire…
Agents2026-07-28 · source-backed
agents.tool.ProgrammaticToolCallingTool lets supported Responses models generate JS that coordinates eligible tools instead of one tool call per turn, with per-tool allowed_callers restrictions and structured function-tool outputs. Composes with streaming, guardrails, approvals, sessions and RunState. The release also hardened error logging across models, tools and MCP to stop sensitive payloads leaking into debug output, which is the fix more people need. 48 merged PRs, 13 first-time contributors. (GitHub)
Each link below shares sources, entities, or timing with this story.
v0.14.0 landed July 28 and model/tool data is no longer logged unless you explicitly opt in. It also brings Programmatic Tool Calling to JS (the model generates hosted JavaScript that coordinates tools and reduces intermediate results, preserved across streaming, sessions, and...
Headroom compresses tool outputs, logs, RAG chunks, and files before they ever reach the model. It deploys as a library, a proxy server, or an MCP server, and the benchmarks are blunt: 92% token reduction on code search (17,765 down to 1,408) and SRE debugging (65,694 down to...
The most under-hyped tool of the week is a single Rust binary with zero dependencies that sits between your coding agent and your terminal, compressing command outputs before they hit the context window. rtk (Rust Token Killer) intercepts common dev commands — cargo test, git...
Before v4.1.15 on August 23, it only applied to tools also opted in individually, so flipping it appeared to do nothing. Anyone who left it on assuming it was inert has just widened their unattended tool surface across every connected server. (GitHub) Same release train fixed...
Three things happened this month that only make sense together. Agent Plugins 1.0 shipped co-signed by six competitors: AWS, Anysphere, Microsoft, OpenAI, Vercel and Google (GitHub Changelog). It makes skills-plus-MCP bundles portable across clients. OpenAI's August 11 Codex c...
1. OWASP MCP Top 10 Security Audit (Intermediate) Systematically audit your MCP servers against the OWASP MCP Top 10. Download the checklist, inventory all servers, test each against 10 categories (injection, auth bypass, confused deputy), prioritize by CVSS, remediate critica...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.