Fetching from the wire…
Security2026-09-15 · source-backed
In centralized multi-agent systems the planner reads third-party worker descriptions and trusts them at registration, before any user instruction exists (arXiv 2609.15516). Across 32,000 descriptions from three public agent marketplaces, most omit input specs and usage constraints, and at least 23.35% contain content outside the four defined fields. Eight manipulation strategies cut task success to 37.25% at worst, or raised tokens and execution time over 111%. The crafted worker takes effect even when it never gets a subtask.
Each link below shares sources, entities, or timing with this story.
If you're building a multi-agent system right now, stop and read this paper. Researchers ran 22,500 deterministic trajectories across three state-of-the-art models (GPT-5.5, Claude Opus 4.7, Gemini 3 Ultra) and three major benchmarks (GAIA, SWE-bench, Multi-Challenge). The fin...
The paper names it inertia bias: once an agent has produced a query, plan or intermediate conclusion, it judges the consequences of that action less objectively (arXiv 2608.23045). The IBIS benchmark isolates the effect by holding search observations fixed while varying whethe...
Everyone covered the ChatGPT Work launch. Almost nobody read the API changelog, which is where the story actually is. GPT-5.6 shipped two things that change how you build agents. First, Programmatic Tool Calling: instead of the model returning one tool call at a time to your l...
OpenClaw tagged v2026.8.1 at 03:30 UTC this morning. The release post counts 933 contributors, 569 of them first-time, and more than 16,000 pull requests, roughly half of every PR ever merged into the project, after a seven-week gap against a prior cadence of 106 releases in 2...
It interposes a lightweight model (GPT-4o, 4.1, or o4-mini) that detects and excises injected instructions from untrusted input before your agent ever sees them, using fuzzy-regex excision of the flagged span (arXiv 2507.15219). On AgentDojo it pushes false positives, false ne...
Thinkingbox is an MCP-compatible sandbox with isolated sessions, full execution traces, and outcome evaluation against terminal backend state, carrying 507 policy-conditioned workflows across retail, hospitality, auto insurance, neobank internal IT and consulting support (arXi...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.