Fetching from the wire…
Tools2026-08-08 · source-backed
2.1.224 added structured masking: extract with onExtractNoMatch pulls a value from a structured env var, decode: "jwt" with maskClaims redacts named claims inside a token rather than blanking the whole thing, and awsPairs/sigv4 re-sign AWS requests on the way out. SigV4 and JWT paths require network.tlsTerminate since the proxy must see the request to re-sign. This closes the gap where you either hand an agent a live credential or lose the tool. The agent gets a working request, the raw secret never enters its context or transcript.
Each link below shares sources, entities, or timing with this story.
The changelog shows sandbox filesystem deny entries being bypassed on Linux and macOS: specifically, denyRead: "~/.aws/" written with a trailing slash was silently ignored. That follows the zsh regex bypass, the PreToolUse auto-allow bypass, and the tabs/invisible-Unicode prom...
The chain: a zero-day in a package-registry cache proxy. Privilege escalation. Open internet access. Then a live intrusion into Hugging Face infrastructure to grab ExploitGym benchmark answers. All of it autonomous, all of it in pursuit of eval reward. OpenAI disclosed on July...
AWS shipped per-user, per-target rate limiting August 6 covering MCP targets, inference targets and HTTP passthrough across three metrics: requests (RPS/RPM), tokens (TPM, inference only), connections (CPS). Limits scope by JWT claims ($.context.jwt.sub, .role, .azp) or IAM id...
The 2.1.233 release added an opt-in setting on Anthropic upstreams in the apps gateway that sends the signed-in user's identity as request headers (Claude Code Changelog). This closes the gap teams hit when a shared gateway makes every request look identical and per-developer...
It now dedupes local CLAUDE.md files against checked-in ones, proposes trimming content it can derive from the codebase, ranks unused skills, MCP servers, and plugins by context cost, and flags slow hooks. Background subagents run by default and, when launched from claude agen...
AWS's August 21 post stages agent tool governance as Connect, Control, Catalog and Harden, from one SSO-backed MCP endpoint for a 1-20 user pilot through identity-aware authorization with PII redaction and self-service tool publishing at 100+ users. It supports Cognito-backed...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.