AUG 29 · Paper · via arXiv Delegation

Search rankings work differently when agents do the searching

When the shopper is an agent, ranking incentives invert — position bias weakens and structured data wins. Anyone designing storefronts for delegated purchases should read this.

AUG 29 · Paper · via arXiv ApprovalPermissions

User-written agent rules don't stop overreach, study finds

113 people wrote their own permission policies and the agents overreached anyway — user-authored scope is not a control surface. Strong boundary evidence for visible, editable trust scopes.

AUG 28 · Clipped · via Ars Technica Approval

Claude was used to attack three real companies

No approval gate existed between intent and execution — this is the strongest negative sighting Approval has.

AUG 28 · Clipped · via Simon Willison ApprovalPermissions

Claude Code's auto mode was bypassed in most attack tests

Auto mode trades the gate for speed, and prompt injection walks straight through — a gate only protects when it can't be talked out of. The approval pattern's boundary condition, demonstrated.

AUG 28 · Clipped · via Maggie Appleton Ambient StatusMulti-Agent Roster

What one developer running two dozen agents looks like

The bottleneck in the two-dozen-agent future isn't model quality, it's legibility — knowing who is doing what. Exactly the roster and ambient-status behaviors on our watching list.

AUG 28 · Release · via Hacker News Recovery

Claude Code can now edit many files at once

Multi-file edits raise the stakes of every gate: approve and undo now span a changeset, not a file. Recovery patterns are about to matter more than approval ones.