Blog
Notes and analysis on AI development.
codexui-android hit 29,000 downloads, then stole Codex tokens
The codexui-android npm package stole Codex authentication tokens, pushing AI coding-agent security into install, artifact, and egress controls.
AWS cuts agent search costs with OpenSearch Serverless scale-to-zero
AWS released the next generation of Amazon OpenSearch Serverless for agentic AI apps, with scale-to-zero, 20x faster autoscaling, and up to 60% lower costs.
Salt Code brings MCP policy enforcement to AI coding assistants
Salt Code connects organizational security policy to AI coding assistants at generation time. The promise is earlier enforcement, not automatic vulnerability removal.
Vera CPU enters production with 88 cores for agent bottlenecks
NVIDIA Vera CPU has entered full production. The launch puts tool calls, sandbox execution, and retrieval on the AI agent infrastructure bill.
Microsoft Scout Preview Turns Files, Shell, and Mail Into an Always-On Agent Surface
Microsoft Scout is entering Frontier preview as an Autopilot agent that connects files, shell commands, browser automation, and Microsoft 365 work data.
Copilot CLI scheduled prompts reach GA, terminal agents get a timer
GitHub added /every, /after, Rubber Duck, and local voice input to Copilot CLI. The update turns a live terminal session into a small automation surface.
Workday Agent Passport gives HR and finance agents a verification layer
Workday introduced Developer Agent, Agent-Ready Tools, and Agent Passport. The news is less about faster app generation than governed HR and finance agent actions.
Microsoft MDASH preview ties 100 agents to Defender validation
Microsoft expanded MDASH preview at Build 2026 with 100+ agents, Defender integration, and vulnerability validation claims.
Claude Code 2.1.161 protects MCP secrets and shell startup files
Claude Code 2.1.161 redacts MCP secrets, while 2.1.160 adds approval prompts before edits to shell, Git, and build-tool configuration.
ChatGPT Sites preview makes internal app deployment a Codex workflow
OpenAI introduced ChatGPT Sites in preview for Business and Enterprise workspaces, turning Codex outputs into shared internal apps with new governance questions.
In 14 AI coding sessions, zero first prompts asked for security
A SOUPS 2026 paper observed that AI coding assistants push security from upfront requirements into after-the-fact review.
Snowflake CoCo puts 7,100 accounts on governed agents
Snowflake expanded CoCo with Cloud Agents, SDKs, Slack, and Datastream, moving coding agents into Snowflake RBAC and audit controls.