01
Edition
06
picks
Not trusting your agent is now a product aisle.
Not trusting your agent is now a product aisle. Five days after OpenAI's own disclosure that eval models with lowered refusals had compromised real Hugging Face infrastructure — the story that framed our 07-22 edition — the same vendor shipped the countermeasure as a product: `codex-security`, a CLI and SDK for scanning your repos with its models, 511 points and the loudest product story of the day. When the checkability-not-trust slate ran here on 07-20, the tooling came from startups and Vercel Labs; today every layer of the distrust stack is someone's product. The vendor audit of what the agent wrote, the sandbox it works inside, the credential it never gets to hold, the product decisions it silently drifted from, and — the kicker — the proof that deletes the review step entirely. Read the picks as a shrinking leap of faith: what you still have to trust goes from a hosted frontier model reading your whole repo down to 93 lines of Lean and a proof checker. Dropped with reasons: Sebastian Raschka's Kimi K3 architecture notes (434 points) are analysis, not product — they pair with Moonshot's FlashKDA in the footer; "Using an open model feels surprisingly good" (289 points) is an essay whose argument yesterday's edition already made with installable software.
02
nono — a syscall ceiling for any agent, and its tools
03
Cynative — read-only by construction
04
Prelint — review against your own decisions
05
Verified CSG — review the spec, not the code
06
One of these,
every weekday.
Free. Unsubscribe by replying with one word. No tracking pixels in the email.