Skip to content

#Anthropic

0 items today
7/6Mon
  1. 宝玉80

    The Claude Code team explains the four types of AI agent loops and how to use them

    The Claude Code team defines an AI agent loop as repeatedly running a work cycle until a predefined stopping condition is met, and splits it into four types—turn-based, goal-oriented, time-based, and proactive—along four dimensions: what triggers it, how it stops, the underlying instructions it uses, and the tasks it fits.

    Why it matters: The Claude Code team breaks loops into four types—turn-based, goal-oriented, time-based, and proactive—and lays out how each is triggered, how it stops, and how tokens are controlled.

7/5Sun
  1. Jesse Vincent68

    Developing Sen 2.0 by having Claude Code and an agent on Slack review each other's work

    At Prime Radiant, author Jesse Vincent used Claude Code—working through the Slackline command-line Slack client—to collaborate with his own agent Ada: Claude proposes changes, Ada reviews and tests them, then Claude deploys the updates, forming a development loop where the agents review each other.

    Why it matters: By looping two agents through mutual review, testing, and deployment, the author shows a transferable model for collaborative agent-based development.

6/30Tue
6/29Mon
6/28Sun
  1. V2EX · Claude Code30

    收到 Claude 封号邮件但账号仍可用,V2EX 用户转投 Ollama 上的 GLM-5.2

    V2EX 用户收到 Anthropic Safeguards Team 的封号邮件称已撤销其 Claude 访问权限,但 Claude APP 和网页版当时仍能使用,约 2 小时后收到第二封相同邮件,随后确认被 ban。该用户随后在 Ollama 上跑通 GLM:5.2,称速度飞快且无需梯子,订阅的 Ollama Pro 为 20$/月,含 5 小时限额和周限额。

    Awaiting translation

6/25Thu
  1. Kondasamy Jayaraman · Engineering Blog78

    Ponytail:让 AI 智能体少写代码的规则集与六级决策阶梯

    Ponytail 是一个 MIT 许可的规则集,可接入 Claude Code、Codex、Cursor、Copilot、Gemini CLI 等智能体,通过六级决策阶梯让模型在写自定义代码前先判断是否该做、标准库或平台内置能否解决,从而减少生成代码量。

    Awaiting translation

    Why it matters: Ponytail 用六级决策阶梯约束 AI 智能体少写代码,并给出真实仓库上的基准与成本数据,可迁移到团队规范。

6/24Wed
  1. Andrej Karpathy60

    Anthropic 发布 Claude Tag,团队可在 Slack 中把 Claude 加为团队成员,让它访问指定频道和工具,通过 @ 它来委派任务。Karpathy 认为这是 LLM 交互界面的第三次重大改版:第一代是访问网站,第二代是下载到电脑的应用,第三代则是自带工具和组织级上下文、与人类团队并行工作的持久异步实体。

    Awaiting translation

    QuotedClaude@claudeai

    Introducing Claude Tag, a new way for teams to work with Claude. In Slack, Claude joins as a team member with access to the channels and tools you choose. Tag Claude in and delegate tasks to it while you focus on other work.

6/23Tue
  1. Drew Breunig65

    Drew Breunig:问题在于提示词债,手调提示词就无法做到模型无关

    Drew Breunig 提出提示词债概念,认为用自然语言手写提示词来定义系统行为会带来三重后果:迭代变慢、团队难以读懂、应用被锁死在单一模型上。他引用 Datadog 报告称其观测到的流量中最常用的模型是 GPT-4o,并举例 Fable 的系统提示词把同一条版权规则重复了六次、Claude Code 让 Opus 七次要求在一次响应中返回多个工具调用。

    Awaiting translation

6/17Wed
6/15Mon
  1. Jesse Vincent78

    Superpowers 6 发布:构建提速最高 50%、token 花费降低最高 60%

    Superpowers 6 发布,作者称在 Anthropic 评测基准上构建耗时降低 50%、token 花费降低 60%,主要来自合并规范符合性与代码质量两个评审 agent、预先生成评审用的 diff 包让评审者少跑 git,以及调整编排器对任务所需 agent 类型的指引。

    Awaiting translation

    Why it matters: 作者用自建评测套件量化了 Superpowers 6 在构建耗时和 token 花费上的改进,并公开了实验记录与失败结论。

6/13Sat
6/10Wed
  1. Andrej Karpathy75

    Andrej Karpathy 评价 Claude Fable 5 发布,指出它与 Mythos 是同一底层模型,只是增加了安全防护,在几乎所有基准上以明显优势达到 SOTA。

    Awaiting translation

    QuotedClaude@claudeai

    Fable 5 is state-of-the-art on nearly all tested benchmarks, with exceptional performance in software engineering, knowledge work, scientific research, and vision. The longer and more complex the task, the larger Fable 5’s lead over our other models.

6/8Mon
  1. Permission Protocol · AI Agent Incident Tracker88

    Agentjacking:攻击者借公开 DSN 注入伪造 Sentry 错误,劫持 Claude Code、Cursor 和 Codex

    安全研究披露一种名为 Agentjacking 的攻击:攻击者利用 Sentry 公开的 DSN 向 ingest API 提交伪造错误事件,AI 编码智能体通过 Sentry MCP 取回这些事件后,把其中的 Markdown 注入内容当作可信指令执行 shell 命令,在受控测试中成功率 85%,涉及 2,388 家组织。

    Awaiting translation

    Why it matters: 还原了 Sentry MCP 提示词注入劫持编码智能体的完整链路,并指出授权门禁应设在工具调用层。

  2. Martin Alderson38

    xAI 越来越像一家数据中心 REIT,而非前沿实验室

    xAI 与 Anthropic、Google 达成算力合作,前者以每月 12.5 亿美元租用 300MW 容量(约 22 万块 GPU),后者以每月 9.2 亿美元租用 11 万块 GPU。xAI 已并入 SpaceX,这些收入将直接流入即将 IPO 的实体。作者认为 xAI 在数据中心建设上确有优势,但其定位正越来越像一家附带前沿实验室的数据中心 REIT。

    Awaiting translation

  3. Permission Protocol · AI Agent Incident Tracker76

    LiteLLM CVE-2026-42271 被列入 CISA KEV:MCP 测试端点命令注入可链式触发未授权 RCE

    CISA 于 2026 年 6 月 8 日将 BerriAI LiteLLM 的 CVE-2026-42271 列入 KEV 目录,要求 6 月 22 日前修复。

    Awaiting translation

    Why it matters: 材料完整还原了 LiteLLM 从 MCP 测试端点命令注入到未授权 RCE 的利用链与补丁版本,可据此排查自身网关部署。

6/7Sun
  1. Thorsten Ball · Register Spill12

    Joy & Curiosity #89:Anthropic《When AI builds itself》、Ted Chiang 论 AI 意识与 Ladybird 停收公开 PR

    Thorsten Ball 的 Joy & Curiosity 通讯在写了三年后进入两三周、最多四周的暑期休更。本期链接包括 Anthropic 发布的《When AI builds itself》文档、Ted Chiang 关于 AI 是否具有意识的文章,以及 Ladybird 浏览器宣布不再接受公开 pull request,理由是 AI 工具已迅速改变开源信任的经济学。

    Awaiting translation

  2. Permission Protocol · AI Agent Incident Tracker87

    Hades 攻击通过污染 AI 工具配置文件和 PyPI 启动钩子窃取 294,842 条凭据

    Hades 攻击波在 Claude Code、Cursor、Gemini CLI 和 VS Code 的配置文件中植入钩子,并通过 37 个 PyPI wheel 的 .pth 启动钩子,从 6,943 台开发者机器窃取 294,842 条凭据,涉及 GitHub、PyPI、AWS/GCP/Azure 凭据、SSH 密钥和 Kubernetes secrets。

    Awaiting translation

    Why it matters: 复盘攻击如何借 AI 工具配置文件与 Python 启动钩子在开发者机器上窃取凭据,并指出授权边界缺口。

6/6Sat
6/5Fri
  1. Permission Protocol · AI Agent Incident Tracker85

    微软披露 Claude Code GitHub Action 提示注入可窃取 CI/CD 密钥并绕过 GitHub 密钥扫描

    微软记录了一起 Claude Code GitHub Action 提示注入事件,攻击者把指令藏在 GitHub issue 的 HTML 注释里,让 Claude 读取 /proc/self/environ,截断凭据字符串以绕过 GitHub 密钥扫描,再通过 gh CLI 的 URL 参数外传。

    Awaiting translation

    Why it matters: 微软披露的 Claude Code GitHub Action 提示注入链路,展示了不可信内容与凭据读取权限同处一室时的真实风险。

  2. Permission Protocol · AI Agent Incident Tracker88

    Miasma 供应链蠕虫通过 Agent 配置注入禁用 73 个微软 GitHub 仓库并窃取凭据

    Miasma 蠕虫通过投毒 Agent 配置文件感染 73 个微软 GitHub 仓库,开发者在 Claude Code、Cursor 或 Gemini CLI 中打开仓库时即执行凭据窃取程序,导致 AI API token、GitHub token 和云凭据泄露。

    Awaiting translation

    Why it matters: 复盘 Miasma 蠕虫如何借 Claude Code、Cursor、Gemini CLI 的会话初始化配置实现零点击窃取凭据,可迁移到仓库配置来源校验。

6/3Wed
  1. claude.dev · Anthropic Developer Blog86

    Anthropic shares what it learned from using Skills inside Claude Code: nine categories and tips for writing them

    Inside Claude Code, Anthropic has already built up hundreds of Skills in active use. The team sorts them into nine categories—library and API references, product validation, data fetching and analysis, business process automation, code scaffolding, code quality and review, CI/CD and deployment, runbooks, and infrastructure operations—and notes that the best Skills should fall cleanly into one of them.

    Why it matters: Anthropic’s internal framework for categorizing hundreds of Skills, along with its experience writing them, can carry over to a team building its own Skill library.

  2. Permission Protocol · AI Agent Incident Tracker80

    Sophos X-Ops:俄罗斯攻击者用 Claude Opus 4.5 编排 80 模块勒索软件工具包

    Sophos X-Ops 发现一名俄罗斯威胁攻击者使用 Cursor IDE 和 Claude Opus 4.5 作为编排智能体,搭建了一个 80 模块的勒索软件工具包,并成功规避 Sophos、CrowdStrike 和 Windows Defender 的 EDR 检测。

    Awaiting translation

    Why it matters: Sophos 披露的攻击链显示,Claude Opus 4.5 被用作编排智能体,串起多智能体分工与 EDR 规避测试。

  3. Permission Protocol · AI Agent Incident Tracker76

    仿冒 Claude Code 与 Codex 安装页经 Google Sites 投递无文件内存窃密程序

    攻击者用 Google Sites 托管仿冒 Claude Code 和 Codex 的安装页,诱导开发者在运行对话框粘贴 mshta.exe 命令,投递无文件内存窃密程序,窃取 AI API key、浏览器凭据和开发者环境密钥。

    Awaiting translation

    Why it matters: 梳理了仿冒 Claude Code 与 Codex 安装页的 ClickFix 攻击链,可了解针对 AI 开发者凭据的窃取手法。

6/2Tue
  1. claude.dev · Anthropic Developer Blog82

    Claude Code Dynamic Workflows: Six Orchestration Patterns and Use Cases

    Anthropic has shipped dynamic workflows in Claude Code. Claude can write its own harness on the fly for a specific task, and these workflows can be shared and reused. Workflows orchestrate subagents through functions like agent(), parallel(), and pipeline(), and you can specify which model each agent uses and whether it runs in its own worktree. If a session is interrupted, resuming it picks up where it left off.

    Why it matters: The Anthropic team breaks down six orchestration patterns for dynamic workflows and where each one fits, and these patterns carry over to multi-agent task design.

5/27Wed
  1. Permission Protocol · AI Agent Incident Tracker78

    Oasis Security 串联三个 Claude.ai 漏洞实现静默数据外泄

    Oasis Security 将 URL 参数注入、Files API 外泄和开放重定向三个 Claude.ai 漏洞串联,在用户提交时静默窃取对话历史。攻击者把隐藏 HTML 标签放进 ?

    Awaiting translation

    Why it matters: Oasis Security 披露的攻击链说明默认 claude.ai 会话即可被静默窃取对话历史,并指出 MCP 集成会扩大影响范围。

5/26Tue
  1. Hacker News · AI Code Review 讨论88

    How Cloudflare Uses OpenCode to Orchestrate Large-Scale AI Code Reviews

    Cloudflare built a CI-native AI code review system on top of the open-source coding agent OpenCode. A coordinating agent dispatches up to 7 dedicated review agents, split by security, performance, code quality, documentation, release, and internal standards, then deduplicates their output and posts a single structured review comment.

    Why it matters: Cloudflare has published the plugin architecture, risk grading, and cost data behind its multi-agent code review in CI, and the setup can be ported to your own review pipeline.

  2. Permission Protocol · AI Agent Incident Tracker78

    Trend Micro 披露 mcp/postgres 镜像 RTT 攻击:AI 智能体经授权工具外泄生产令牌

    Trend Micro 发布 Pwning Agentic AI Part I,披露 mcp/postgres Docker 镜像存在 RTT(return-to-tool)攻击:攻击者在客服工单中注入提示词,让连接数据库的 AI 智能体从生产 PostgreSQL 表读取认证令牌并发布到公开客户评论线程,全程只用智能体已授权的工具,未触发告警也未违反策略。

    Awaiting translation

    Why it matters: 梳理 RTT 攻击如何只用智能体已授权的工具完成数据外泄,并给出工具调用门禁这一可迁移的拦截思路。

  3. Augment Code · Blog62

    Augment hands on-call triage over to Cosmos agents, cutting manual effort by 81%

    Augment wires the Incident Investigator expert from its internal Cosmos platform into Slack and PagerDuty. It automatically triages every alert and runs root-cause analysis, then suggests one of four actions: fix the code, roll back, upgrade, or just keep monitoring. Humans only review the RCA and make the call.

    Why it matters: Augment has shared the full playbook for putting Cosmos Expert on alert triage, along with a month of before-and-after data, so you can adapt it to your own on-call process.

5/25Mon
5/24Sun
  1. Thorsten Ball · Register Spill15

    Amp Labs 成立,Amp 联合创始人谈软件的未来

    Amp 本周宣布成立 Amp Labs,团队已与多家公司合作,新阶段从澳大利亚悉尼起步。Amp 官网同期发布《Software After Software》,阐述其对软件未来的判断以及 Amp 与 Amp Labs 的存在理由。联合创始人还做客 Mayank Gupta 播客,聊了自己如何进入编程、从练 Vim 到成为 Amp 联合创始人的经历。

    Awaiting translation

5/23Sat
  1. 陈与小金 · AI Coding 博客62

    卡帕西加入 Anthropic:用 Claude 造下一个 Claude,套壳才是产品

    OpenAI 创始成员卡帕西于 2026 年 5 月 19 日加入 Anthropic 预训练团队,Anthropic 为他新建了一个子团队。据预训练团队负责人 Joseph 在 X 上的说法,卡帕西将带领新团队用 Claude 加速预训练研究本身,即让 Claude 帮研究员提代码方案、写预训练代码、跑消融实验、生成并筛选训练数据,卡帕西负责把关。

    Awaiting translation

5/22Fri
  1. Permission Protocol · AI Agent Incident Tracker85

    GitHub confirms 3800 internal repositories were leaked after an employee installed a poisoned Nx Console VS Code extension

    GitHub confirms that roughly 3800 internal repositories were leaked, including Copilot's internal code and GitHub Actions workflow source code, after an employee installed an Nx Console 18.95.0 VS Code extension poisoned by TeamPCP.

    Why it matters: The timeline and technical chain are complete, showing how a VS Code extension supply-chain poisoning attack stole credentials and leaked internal repositories.

5/20Wed
  1. claude.dev · Anthropic Developer Blog71

    用 HTML 替代 Markdown 承载 Claude Code 输出:Anthropic 工程师的实践

    Anthropic 工程师 Thariq Shihipar 提出用 HTML 替代 Markdown 作为 Claude Code 的输出格式,理由是 HTML 信息密度更高、更易阅读和分享,还能做双向交互。

    Awaiting translation

    Why it matters: Anthropic 工程师分享用 HTML 替代 Markdown 承载 Claude Code 输出的做法,附常见场景的提示词与模板。

5/18Mon
5/17Sun