Fetching from the wire…
Tools2026-09-16 · source-backed
The September 15 release fixes a real hole for anyone running agents on untrusted repos: under permissions.blockReadsOutsideWorkingDirectories, a memory directory chosen by a repository's own settings is no longer loaded, recalled, indexed, or used by memory extraction. Same release fixes a subshell hiding a dangerous rm in bypass mode, and adds opt-in x-claude-code-* gateway hint headers exposing request class, agent type and compaction state behind CLAUDE_CODE_GATEWAY_HINT_HEADERS=1. That last one is the first time the CLI tells a proxy whether a call is a subagent turn or a compaction pass, which is enough to route or bill by agent type without parsing prompts.
Each link below shares sources, entities, or timing with this story.
Cline released @cline/sdk on May 13, an open-source TypeScript agent runtime that powers their CLI, VS Code, and JetBrains extensions. Running claude-opus-4.7, Cline CLI scores 74.2% on Terminal-Bench 2.0. Claude Code on the same model: 69.4%. Same model. Different harness. Al...
I check Product Hunt maybe once a week and usually regret it. Today's board is worth reading as market structure. The July 30 leaderboard: SKI at 277 upvotes (free voice input for Claude Code and Codex). AI Search Console at 249 (prompt analytics and citation mapping). Memmy A...
One Claude Code release fixed two independent permission-check bypasses on the same day. That's the story. Version 2.1.221, shipped August 4, patches a Bash tool bypass where zsh could execute hidden commands embedded inside [[ ]] regex conditionals. The approval prompt never...
A Rust local HTTP proxy that translates Anthropic API calls into Cursor agent CLI invocations, reading your Cursor auth token from the macOS keychain and spawning Claude Code with proxy env vars set. MIT, 37 stars, 2 commits. It disclaims affiliation with both Anthropic and An...
A paper from Xiao Yu, Baolin Peng, and Ruize Xu makes a claim that seems obvious once stated and is genuinely new as a training methodology: modern agents are inseparable from their inference harnesses, so training them in stripped-down RL sandboxes produces a train/serve mism...
AionUi (free, local, 24/7 across 20+ CLIs), HolyClaude (Claude Code plus web UI, 8 AI CLIs, headless browser, 50+ tools), and DeepChat all wrap multiple vendor CLIs behind one local interface. (AionUi) The pattern: developers don't want to pick one agent, they want a neutral c...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.