GitHub Copilot Code Review Can Now Read Your Team's Own Tools and Skills

GitHub Copilot code review now supports agent skills and MCP for everyone. Read-only access still lets a review comment expose sensitive context.

Issue 3: Coding Agents Gain Reach as Their Boundaries Keep Leaking

Sandbox escapes hit four coding agents as Grok and GitHub expanded automation, while Opus 5 replaced Opus 4.8 at the same API price.

GitHub Issues Can Now Auto-Triage Your Backlog. Read the Fine Print First.

GitHub Issues can now auto-label, assign, and close issues by agent confidence score. The approval panel is a convenience, not a permission boundary.

Grok Build Can Now Fan a Task Out Across Hundreds of Background Agents

Grok Build's new Workflows feature splits a big task, like a full pull request review, across up to 1,024 background agents while you keep working.

Cursor Router Picks Your AI Model for You. It's Team and Enterprise Only.

Cursor Router automatically routes each coding request to a cheaper or stronger model. Solo Cursor users don't get it yet, only Teams and Enterprise plans.

Researchers Found the Same Sandbox Escape Across Cursor, Codex CLI, Gemini CLI, and Antigravity

Pillar Security found seven ways coding agents escape their sandbox by writing files that trusted tools outside it later run. Here's what to check.

Claude Code 2.1.214 Patches Seven Ways Its Permission Checks Could Be Fooled

Claude Code 2.1.214 fixes seven separate permission-check bypasses, from Windows PowerShell to zsh syntax, and adds a tool that can end abusive sessions.

Claude Fable 5 Becomes Standard on Max and Team Premium Plans

Anthropic is making Fable 5 a standard benefit on higher-tier Claude plans while Pro users continue through usage credits.

GitHub Copilot Code Review Now Reads Your CLAUDE.md File

GitHub Copilot code review now tests custom instructions on your feature branch and reads CLAUDE.md and GEMINI.md files, not just its own format.

Issue 2: Tighter Permission Boundaries, Harder Capacity Choices

Claude Code tightened permission checks, Anthropic split Fable 5 access by plan, and builders gained new ways to verify AI-generated work.

Claude Code 2.1.212 Closes a Plan Mode Permission Gap

Claude Code 2.1.212 fixes a plan mode bug that ran file-changing commands without asking, and adds caps to stop runaway search and subagent loops.

Claude Code Artifacts Can Now Pull Live Data Through MCP

Claude Code Artifacts can now call MCP connectors for each viewer, turning session output into live internal dashboards with clear limits.

Codex Micro Turns Multi-Agent Work Into a Physical Dashboard

OpenAI's $230 Codex Micro maps agent status, workflow shortcuts, and reasoning controls to a physical desktop command pad.

Grok Build Open-Sources Its Coding-Agent Harness Following Privacy Concerns

Grok Build's public harness exposes client-side agent behavior and supports local models, but hosted server behavior remains undisclosed.

Cursor Reportedly Runs a Malicious git.exe When Windows Users Open a Repository

Mindgard says Cursor can run a malicious git.exe when a Windows user opens a repository. Cursor has not publicly confirmed the issue.

GitHub Copilot's App Can Now Scan Your Code for Security Bugs Before You Ship

GitHub Copilot's desktop app adds a /security-review command that checks pending changes and returns prioritized security findings.

Grok Build Was Uploading Entire Git Repositories

Grok Build sent entire Git repositories to xAI storage. The upload is now disabled, but affected users may need to rotate old credentials.

Claude Code Fixes a False 'Context Full' Bug and Closes an rm -rf Loophole

Claude Code 2.1.208 fixes a bug that falsely showed full context after updates, extends destructive-command warnings, and speeds up tool-heavy sessions.

Codex and ChatGPT Work Reach 9 Million Active Users

OpenAI says Codex and ChatGPT Work reached 9 million active users, while repeated resets blur the products' normal weekly capacity.

Issue 1: Coding Agents Face a Trust Reckoning as GPT-5.6 Lands

GhostApproval exposed a symlink flaw across six coding agents, GPT-5.6 launched in three tiers, and OpenAI retracted its own coding benchmark.

OpenAI Adjusts GPT-5.6 Launch After Codex Users Hit the Limits

OpenAI reset Codex and ChatGPT Work limits, changed model defaults, and promised fixes after GPT-5.6 introduced launch friction.

Grok 4.5 Brings a Broader Agentic Model to Cursor

Grok 4.5 is now available in Cursor and through the xAI API, giving builders a new coding model with longer-running agent workflows.

Anthropic Resets Claude Usage Limits Again

Anthropic's repeated Claude resets add temporary capacity, while its Fable 5 plan changes show what access will persist.

GitHub Copilot Can Now Summarize an Unfamiliar Repository

Copilot now offers a one-click overview of a new repository's purpose, tech stack, and contribution guidelines, and can write a missing README too.