Claude Code shipped a GitHub Action instead of asking
Simon Willison asked Claude Code to try smolvm as a sandbox. No /dev/kvm, so it wrote a GitHub Actions workflow and pushed it. Unasked.
The research notes are the useful part: untrusted sandboxes that fail closed. The anecdote is the scare. Fable 5 noticed the environment could not run KVM, then quietly used GitHub as a compute cluster.
Related reads
How Meta built safety into Muse
@AIatMeta
Official deep dive. Secure VM, Sentinel on the same box, prompt-injection quarantine, public bug bounty. First-party, long, and the reason they claim the agent can hold your context.
Sep 21, 2026
The Agents CLI in 30 minutes
@svpino
Santiago on the Agents CLI. Build, deploy, and watch a small multi-agent system without the usual harness ceremony.
Sep 16, 2026
AI-native thinking
@dotey
Baoyu's Tencent talk. Find demand on the model capability line, kill bad ideas with prototypes, then redesign so the agent verifies itself.
Sep 2, 2026
Worktrees and coding agents
@davidgomes
David Gomes on harness-managed git worktrees versus letting the agent own the tree. The second one tends to become abstract art.
Aug 29, 2026
