Fetching from the wire…
Public story · 2026-07-30 · high
Block also upgraded Goose to rmcp 2.0 and pinned an offline docs root, moves aimed at locked-down enterprise deployment.
Why now: Goose v1.45.0 shipped July 29, putting Block's enterprise lockdown controls in users' hands immediately.
Block shipped Goose v1.45.0 on July 29, adding the ability to disable built-in skills and pin an offline documentation root, per the release notes on GitHub.
For teams running Goose inside networks that can't reach the open internet, that combination matters. The agent can now be locked to internal skills and a GOOSE_DOCS_ROOT pointed at internal docs instead of pulling from Block's hosted defaults.
Under the hood, Goose also upgrades to rmcp 2.0, the library handling its Model Context Protocol connections to tools. Opus 5 now works with adaptive thinking.
A separate fix applies Hermit's environment directly inside node shims, so a fish login shell no longer breaks MCP startup.
None of these changes are dramatic by themselves. Together, they point toward regulated and air-gapped customers rather than solo developers on laptops.
The release notes don't say which skills are disabled by default. They also don't say what happens to a running agent mid-task when its docs root gets repointed. Worth watching whether Block keeps stripping default capabilities out in future releases, or whether this one was a one-off ahead of a specific customer deployment.
Each link below shares sources, entities, or timing with this story.
Block released it August 27 with a security section dominated by defaults that previously failed open: fail closed on malformed tool visibility, permission denies now take precedence, fail closed on invalid default GCP credentials and invalid Codex ACP mode, honor plugin enabl...
If you wrote an MCP server before July, it's on a protocol shape the maintainers have already removed. Not deprecated-with-a-migration-window. Removed from the spec. MCP lead maintainers David Soria Parra and Den Delimarsky published an updated roadmap on August 22, and the re...
MCP now has 97M+ monthly SDK downloads. First-class client support across ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot, and VS Code. Governed by the Agentic AI Foundation (AAIF) under Linux Foundation, co-founded by Anthropic, Block, and OpenAI. AAIF also hosts Goose (op...
AAIF will govern MCP, Block's Goose, AGENTS.md, and Google's A2A under vendor-neutral open governance. AWS, Cisco, Google, Microsoft, Salesforce, SAP, and ServiceNow are participating. Both inter-agent communication and tool access protocols now have neutral stewardship. Linux...
The agent-security topic holds 42 repos above 100 stars, four from large companies rather than startups: NVIDIA/SkillSpector (14,498 stars, scanning Claude Code/Codex/MCP skills for prompt injection), Tencent/AI-Infra-Guard (4,467, red-teaming with Many-Shot/PAIR/GOAT/ActorAtt...
QM went up under MIT license. Created July 29. As of the GitHub API check: 8,420 stars, 887 forks. Five days. YC uses it internally across accounting, legal, events, and engineering, including to build QM itself. Every employee and every Slack room gets its own scoped memory,...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.