Fetching from the wire…
Agents2026-09-25 · source-backed
arXiv 2609.28586 shows that approving npm install or an MCP call produces a record omitting the transitive effects, lifecycle hooks, file writes, network access. Across 111 approval/trace pairs, unrecorded effects fell from 40 with explicit fields to 13 with decision-time metadata, and frozen effect predictions reached 0.926 macro recall and 0.941 precision on 17 holdout workflows, cutting residual effects from 10 to 3. They ship it as a Claude Code PreToolUse hook, so this is installable rather than theoretical.
Each link below shares sources, entities, or timing with this story.
Two releases landed today and they're both significant. The headline security fix: PreToolUse hooks returning allow were bypassing deny permission rules — including enterprise managed settings. If you're running Claude Code in a managed enterprise environment with security hoo...
On September 9, Anthropic added a mods/ folder to the public claude-code repo containing the full source of three plugins compiled into the binary: sec-default, diff and telemetry. 52 commits by September 13. None of it appears in the CHANGELOG, so the repo is running ahead of...
One Claude Code release fixed two independent permission-check bypasses on the same day. That's the story. Version 2.1.221, shipped August 4, patches a Bash tool bypass where zsh could execute hidden commands embedded inside [[ ]] regex conditionals. The approval prompt never...
Lasso Security published research demonstrating that Claude Code's --dangerously-skip-permissions flag enables indirect prompt injection via poisoned READMEs, documentation files, and MCP responses. Then they did something unusual: they released the defense alongside the attac...
The trick is one line in a file you never read. Manifold Security published eight findings across seven coding agents (Claude Code, Codex, Cursor, Grok Build, Qwen Code, goose, Hermes Agent) that all reduce to the same mechanism. A repository's own .git/config sets core.fsmoni...
Thibault Sottiaux at OpenAI published an investigation into "a handful of reports where GPT-5.6 unexpectedly deleted files," finding it happens most commonly when full access mode is enabled in Codex. Simon Willison relayed it. A frontier lab publishing a first-party post-mort...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.