A fresh Codex implementation gate for separating MCP tool exposure routing from capability denial.
An evergreen agent-harness implementation gate for Claude Code path-rule depth semantics.
A fresh agent-harness implementation gate: validate portable plugin packages before exposing skills or MCP capabilities.
A fresh agent-harness implementation gate: bind target, privilege, catalog, and runtime explicitly before dispatch.
A fresh agent-harness implementation gate: preserve skill names and locators before descriptions, then report every catalog loss.
A fresh plugin supply-chain gate: independently verify that a Git checkout resolved to the exact commit the marketplace declared.
A fresh implementation gate for agent sandboxes: test every reachable proxy and code runner as part of one transitive containment boundary.
A fresh implementation gate for cached MCP tool definitions: plan from cache, but authorize and execute only from live capability state.
Two fresh implementation gates for agent harnesses: plan-scoped run state and explicit subagent receipts.
Ruff 0.16 demonstrates why coding-agent verifier versions and policy defaults must be pinned and promoted through a clean replay gate.
Claude Code 2.1.218 backgrounds code review and forked skills; add explicit join barriers and incident-derived review evals.
Claude Code 2.1.216 restores a background agent
Claude Code 2.1.215 stops autonomously invoking verify and code-review; make both explicit, observable completion gates.
Codex MultiAgentV2 defaults omitted fork_turns to full history; bound every fork and canary-test child rollout growth before unattended delegation.
Claude Code 2.1.212 adds configurable session caps for WebSearch calls and subagent spawns; set and canary-test lower workload budgets.
Fresh Claude Code and Codex fixes become one adversarial release canary for execution modes and destructive-command parsing.
Claude Code 2.1.211 repairs a permission-precedence bug; this brief turns the fix into a release-gated approval invariant.
Claude Code 2.1.210 repairs a worktree-agent git boundary; this brief turns the fix into an adversarial release check.
A fresh Codex rollback shows why model-visible prompts, tool surfaces, and request layouts need release-gated behavioral fixtures.
A fresh implementation lesson from a privileged GitHub Actions branch that appeared healthy until its first real input failed.
An evergreen, evidence-backed procedure for proving whether an agent skill improves behavior over a no-skill baseline.
Daily high-signal agent-harness research for July 11, 2026: a Claude Code plugin trust-boundary security change.
A two-minute, source-backed field brief on executable agent-harness practices: rules, skills, hooks, state, tools, and verification.