Fetching from the wire…
Security2026-09-13 · source-backed
PR #45185, merged September 12, attaches direct-call records to outputs before they enter history and sets tool_calls_complete only when an invocation's arguments are fully recorded, regardless of whether the tool succeeded. It tracks call IDs that bypass dispatch specifically so their reuse can't establish completeness. Executed-call metadata is now stripped from app-server raw response notifications and excluded from Guardian history retention budgets. Six of Codex's last thirty hours of commits also went to a native Windows MXC sandbox (#45176 and three siblings), which refuses exec-server requests asking for a TTY, an arg0 override, managed networking or private desktop isolation, and refuses outright when native MXC is unavailable.
Each link below shares sources, entities, or timing with this story.
20.10.0 (September 11) adds a Claude Code plugin and marketplace, an installable Codex plugin, and a Cursor plugin for the remote MCP server and public skills, alongside span-level cost filtering and a completeness evaluator. 20.11.0 (September 12) serves the shared skills roo...
Two merged PRs, five hours apart, and together they change what agent tool approval means on macOS. PR #43624, merged at 00:15Z on September 8, implements macOS user verification using P-256 keys in the Secure Enclave, stored in the Data Protection Keychain, with biometric aut...
Released 01:58 UTC on September 1, demoting update_plan to opt-in, so you need tools.update_plan.enabled = true in config to get planning back (GitHub). It also adds output_token_limit per individual MCP tool with truncation that survives session resume, allows :, @, / and . i...
The result-interception hook (#41202) is a place to redact secrets or strip injected instructions out of untrusted MCP output before it enters context, which is the missing seam in every MCP setup I've built. Also: a configurable grace period for discovering tools from optiona...
The July 29 Rust release introduces Agent Plugins manifests, workspace plugin publishing, and additional marketplaces for Amazon Bedrock and Claude Code, meaning OpenAI's coding agent now consumes plugins from a competitor's ecosystem. Also: named and pinned sessions via /new...
Published September 7, it puts OpenAI Codex in the agent picker with a copy-ready ~/.codex/config.toml panel pointing Codex CLI and Desktop at Manifest over the Responses API (GitHub). Two compatibility fixes make it work: Responses-API role: "developer" instruction messages f...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.