Fetching from the wire…
Public story · 2026-08-24 · high
The release also caps how deep agents can dispatch each other, after an a4 prerelease made excluded workspace paths unreachable instead of just hidden.
Why now: The 3.0.0a5 release notes document the dispatch cap and the a4 access-boundary change together, folding a security-relevant workspace fix into what reads like a routine version bump.
Agno's 3.0.0a5 release closes a fail-open in its Studio edit guard and refuses agent dispatch cycles, per the 3.0.0a5 release notes. Both fixes narrow how much an agent can do without a human setting an explicit boundary, in a framework built for chaining agents together.
The release bounds how deep one agent can dispatch another before it stops. Teams that want an agent to call itself on purpose can opt in with a new self_dispatch flag. It also hides inner sub-team member ids from the outer agent roster. Nested agents now stay out of view from parent teams they aren't part of.
The dispatch fix follows a change introduced in the a4 prerelease, which redefined workspace exclude_patterns. Excluded paths used to be hidden from file listings only. As of a4, they're blocked from being read at all. Anyone who set exclude_patterns to keep agents out of sensitive files before that update was relying on a display filter, not an access boundary.
Each link below shares sources, entities, or timing with this story.
Agno supports MCP / Shared entity: GitHub / Same source domain / Shared topic / Tension
Linked by a graph relationship (Agno supports MCP); both cover GitHub; reported by the same outlet (github.com).
Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Both cover Agno, GitHub; reported by the same outlet (github.com); overlapping topics (agent, agno).
Agno supports MCP / Shared entity: GitHub / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Agno supports MCP); both cover GitHub; reported by the same outlet (github.com).
Linked by a graph relationship (Agno supports MCP); both cover GitHub; reported by the same outlet (github.com).
Linked by a graph relationship (Agno supports MCP); both cover GitHub; reported by the same outlet (github.com).
Linked by a graph relationship (Agno supports MCP); both cover GitHub; reported by the same outlet (github.com).
Linked by a graph relationship (Agno supports MCP); both cover GitHub; reported by the same outlet (github.com).
Agno supports MCP / Shared entity: GitHub / Same source domain / What happened next / Tension
Linked by a graph relationship (Agno supports MCP); both cover GitHub; reported by the same outlet (github.com).