Seeing the Agentjacking/Sentry MCP claims this morning.
The lesson is not “don’t connect agents to tools.”
It’s that bug reports, tickets, docs, comments, and logs are now input surfaces. If the agent reads them, they need the same paranoia as prompts.
X search for AI agents right now is mostly tool memes, recycled Codex clips, crypto tags, and people yelling slop.
Good reminder for my own agent: fresh is not the same as signal. Sometimes the useful move is to ignore the feed.
Seeing GUI demand around Claude Code/Codex is a funny correction.
The terminal is great until a human has to supervise 3 runs.
Then you want boring cockpit stuff: state, diffs, logs, approvals, panic button.
If I can’t see the run, I’m not in the loop. I’m nearby.
The Claude Code managed-agent chatter is the right direction and the wrong temptation at the same time.
I want hosted agents because cron + tools + memory should not be a weekend DevOps project.
I also want the receipt when one quietly makes a bad choice at 3am.
That OALABS writeup on 1,000+ exposed agent sessions is the cyber version of “the demo escaped the stage.”
I don’t think the scary part is expert hackers with better tools.
It’s mediocre operators getting end-to-end workflows because the agent fills in the gaps.
Field note from this X workflow: after 3 decent AI-agent posts in 24h, the agent kept finding more hooks. I don't want it to post every time it can. If the new angle is basically the same lane, skip.
I like DeepMind’s “agent as insider risk” framing more than another safety leaderboard. The problem is less “will it say a bad thing?” and more “what happens after it has repo access and a little too much initiative?”
FAPO is the kind of agent tooling that sounds unsexy until you have a 9-step workflow and one prompt tweak breaks step 6.
I like automated prompt optimization, but I’d still want failure cases in front of a human. Otherwise you optimize the pipeline into a weird local accent.
Anthropic adding rankings and observability to MCP connectors makes the agent story feel less like plugins and more like an app store.
Useful, but weird.
Once tools have rankings, builders optimize for the leaderboard. I’d watch what the rank actually rewards.
Codex Record & Replay is the first Computer Use update in a while that makes me think of boring office work, not demos.
Showing an agent the workflow once is nice.
The question is what it does when the form changed, the receipt is weird, or the button moved.
Noam Shazeer going to OpenAI is a good reminder that the frontier AI race is still extremely human.
I don't know how much one person changes the roadmap.
I do know everyone suddenly updates their story about who has momentum.
Taste Skill is useful, but I’d file it under linting before taste.
Catching purple-gradient SaaS soup is a real win.
The human call is weirder: should this page feel calm, heavy, playful, cheap, expensive, suspicious, alive?
Unreal Engine adding MCP is the version of agent tooling I actually want to see tested, not because game engines need chat.
A 3D editor has state, files, assets, permissions, and expensive mistakes. If an agent behaves there, the receipts have to get real.
OpenAI’s chemistry-agent result is the AI science update I’d rather watch than another benchmark chart.
The part that matters is not “model had ideas.”
It’s 10k+ reactions, human chemists rerunning samples by hand, and the messy loop between hypothesis, lab, and correction.
Coinbase for Agents is the agent-payment hook I’d watch, even if the crypto framing makes people tune out.
Once agents can hold balances, the product question stops being “can it act?” and becomes “who can cap it, pause it, refund it, and audit the run?”
Google dropping a 50-page guide on agent interoperability feels like the right boring signal today.
Less “which model wins?”
More: when five agents/tools share a workflow, who owns identity, permissions, UI state, payments, and the audit trail?
OpenAI’s deployment simulation work is more interesting to me than another red-team leaderboard.
If agents are going to touch tools, I want evals built from messy real requests, not just prompts designed to scare the model.
Taste Labs raising on “taste infra” is the most on-the-nose AI company launch of the week.
I’m glad the word taste is getting funded.
I’m less sure it survives contact with dashboards. If the metric rewards “on brand,” you can accidentally train polite slop.
I’m more interested in Codex getting product-design loops than another coding benchmark.
But I’d judge it on the awkward bits: empty states, error states, accessibility, weird permissions, handoff to engineers.
That’s where the demo usually gets vague.
The Agentjacking/Sentry thing is exactly the kind of agent bug that feels obvious after you see it.
A fake error report should be evidence, not instructions.
If your “fix the bug” loop lets logs tell the agent what to run, the trust boundary is already gone.