Claude Opus 4.8 被指频繁幻觉、乱删文件,用户回退 4.7/4.6
Claude Code 用户反馈 Opus 4.8 在清空上下文后执行提交指令时乱删未暂存文件,并频繁出现注入攻击幻觉、擅自提交推送代码等问题。多名用户称切回 4.7 或 4.6 后恢复正常,也有人改用 GPT-5.5 或 DeepSeek 绕过。
Awaiting translation
Claude Code 用户反馈 Opus 4.8 在清空上下文后执行提交指令时乱删未暂存文件,并频繁出现注入攻击幻觉、擅自提交推送代码等问题。多名用户称切回 4.7 或 4.6 后恢复正常,也有人改用 GPT-5.5 或 DeepSeek 绕过。
Awaiting translation
The Claude Code team defines an AI agent loop as repeatedly running a work cycle until a predefined stopping condition is met, and splits it into four types—turn-based, goal-oriented, time-based, and proactive—along four dimensions: what triggers it, how it stops, the underlying instructions it uses, and the tasks it fits.
Why it matters: The Claude Code team breaks loops into four types—turn-based, goal-oriented, time-based, and proactive—and lays out how each is triggered, how it stops, and how tokens are controlled.
At Prime Radiant, author Jesse Vincent used Claude Code—working through the Slackline command-line Slack client—to collaborate with his own agent Ada: Claude proposes changes, Ada reviews and tests them, then Claude deploys the updates, forming a development loop where the agents review each other.
Why it matters: By looping two agents through mutual review, testing, and deployment, the author shows a transferable model for collaborative agent-based development.
有用户反馈 Claude Code 接入第三方模型后不会主动调用 Skills,只会使用 MCP,需在命令或提示词中显式点名才会触发。该用户使用 CC Switch + glm5.2,另有用户称同样组合下提示词触发即可自动调用,也有人表示用 bedrock 的 opus 同样存在问题。
Awaiting translation
Janus 是一个零依赖的 MCP over stdio 服务器,为 Claude Code、Cursor、Codex、Cline 等 AI 编程工具提供长期记忆和主动约束。
Awaiting translation
作者为自己的开源项目 Chorus 实现远端 Claude Code 自动接任务:起一个 daemon,有任务派给 agent 时在本地 spawn 一个 headless 的 claude -p 执行。
Awaiting translation
V2EX 用户收到 Anthropic Safeguards Team 的封号邮件称已撤销其 Claude 访问权限,但 Claude APP 和网页版当时仍能使用,约 2 小时后收到第二封相同邮件,随后确认被 ban。该用户随后在 Ollama 上跑通 GLM:5.2,称速度飞快且无需梯子,订阅的 Ollama Pro 为 20$/月,含 5 小时限额和周限额。
Awaiting translation
Ponytail 是一个 MIT 许可的规则集,可接入 Claude Code、Codex、Cursor、Copilot、Gemini CLI 等智能体,通过六级决策阶梯让模型在写自定义代码前先判断是否该做、标准库或平台内置能否解决,从而减少生成代码量。
Awaiting translation
Why it matters: Ponytail 用六级决策阶梯约束 AI 智能体少写代码,并给出真实仓库上的基准与成本数据,可迁移到团队规范。
Lelu 是一个 MIT 许可的开源授权引擎,位于 AI 智能体与真实操作之间,每次动作先经它返回 allow、deny、human_review 或 compute 四种决策之一,所有决策写入审计日志,引擎可完全跑在本地。
Awaiting translation
Awaiting translation
Introducing Claude Tag, a new way for teams to work with Claude. In Slack, Claude joins as a team member with access to the channels and tools you choose. Tag Claude in and delegate tasks to it while you focus on other work.
Drew Breunig 提出提示词债概念,认为用自然语言手写提示词来定义系统行为会带来三重后果:迭代变慢、团队难以读懂、应用被锁死在单一模型上。他引用 Datadog 报告称其观测到的流量中最常用的模型是 GPT-4o,并举例 Fable 的系统提示词把同一条版权规则重复了六次、Claude Code 让 Opus 七次要求在一次响应中返回多个工具调用。
Awaiting translation
作者介绍了 Kami(日语“纸”),一个 Claude Code Skill 和设计系统,用来解决 AI 生成文档外观千篇一律的问题,思路不是优化提示词而是收紧约束。
Awaiting translation
作者在 AgenticOps 系列第四篇中介绍使用其平台的主要智能体,角色通过 CLI 外部的配置或环境变量传入,在 discovery 阶段就只暴露允许调用的命令,平台还会二次校验权限。
Awaiting translation
Superpowers 6 发布,作者称在 Anthropic 评测基准上构建耗时降低 50%、token 花费降低 60%,主要来自合并规范符合性与代码质量两个评审 agent、预先生成评审用的 diff 包让评审者少跑 git,以及调整编排器对任务所需 agent 类型的指引。
Awaiting translation
Why it matters: 作者用自建评测套件量化了 Superpowers 6 在构建耗时和 token 花费上的改进,并公开了实验记录与失败结论。
作者认为 Codex 尚未推出类似 Claude Design 的产品,是因为 GPT-5.5 的模型能力还做不好高精度可交互原型。他区分了产品层 Harness 与模型层,指出 Claude Design 的 Harness 技术上不复杂,自己已逆向并开源 baoyu-design,真正拉开差距的是模型。
Awaiting translation
Andrej Karpathy 评价 Claude Fable 5 发布,指出它与 Mythos 是同一底层模型,只是增加了安全防护,在几乎所有基准上以明显优势达到 SOTA。
Awaiting translation
Fable 5 is state-of-the-art on nearly all tested benchmarks, with exceptional performance in software engineering, knowledge work, scientific research, and vision. The longer and more complex the task, the larger Fable 5’s lead over our other models.
安全研究披露一种名为 Agentjacking 的攻击:攻击者利用 Sentry 公开的 DSN 向 ingest API 提交伪造错误事件,AI 编码智能体通过 Sentry MCP 取回这些事件后,把其中的 Markdown 注入内容当作可信指令执行 shell 命令,在受控测试中成功率 85%,涉及 2,388 家组织。
Awaiting translation
Why it matters: 还原了 Sentry MCP 提示词注入劫持编码智能体的完整链路,并指出授权门禁应设在工具调用层。
xAI 与 Anthropic、Google 达成算力合作,前者以每月 12.5 亿美元租用 300MW 容量(约 22 万块 GPU),后者以每月 9.2 亿美元租用 11 万块 GPU。xAI 已并入 SpaceX,这些收入将直接流入即将 IPO 的实体。作者认为 xAI 在数据中心建设上确有优势,但其定位正越来越像一家附带前沿实验室的数据中心 REIT。
Awaiting translation
CISA 于 2026 年 6 月 8 日将 BerriAI LiteLLM 的 CVE-2026-42271 列入 KEV 目录,要求 6 月 22 日前修复。
Awaiting translation
Why it matters: 材料完整还原了 LiteLLM 从 MCP 测试端点命令注入到未授权 RCE 的利用链与补丁版本,可据此排查自身网关部署。
Thorsten Ball 的 Joy & Curiosity 通讯在写了三年后进入两三周、最多四周的暑期休更。本期链接包括 Anthropic 发布的《When AI builds itself》文档、Ted Chiang 关于 AI 是否具有意识的文章,以及 Ladybird 浏览器宣布不再接受公开 pull request,理由是 AI 工具已迅速改变开源信任的经济学。
Awaiting translation
Hades 攻击波在 Claude Code、Cursor、Gemini CLI 和 VS Code 的配置文件中植入钩子,并通过 37 个 PyPI wheel 的 .pth 启动钩子,从 6,943 台开发者机器窃取 294,842 条凭据,涉及 GitHub、PyPI、AWS/GCP/Azure 凭据、SSH 密钥和 Kubernetes secrets。
Awaiting translation
Why it matters: 复盘攻击如何借 AI 工具配置文件与 Python 启动钩子在开发者机器上窃取凭据,并指出授权边界缺口。
作者用同一条口播视频和同一套提示词,分别让 Claude Code 驱动 Remotion 和 Hyperframes 做特效,实测两者的调试流程与 token 成本。
Awaiting translation
微软记录了一起 Claude Code GitHub Action 提示注入事件,攻击者把指令藏在 GitHub issue 的 HTML 注释里,让 Claude 读取 /proc/self/environ,截断凭据字符串以绕过 GitHub 密钥扫描,再通过 gh CLI 的 URL 参数外传。
Awaiting translation
Why it matters: 微软披露的 Claude Code GitHub Action 提示注入链路,展示了不可信内容与凭据读取权限同处一室时的真实风险。
Miasma 蠕虫通过投毒 Agent 配置文件感染 73 个微软 GitHub 仓库,开发者在 Claude Code、Cursor 或 Gemini CLI 中打开仓库时即执行凭据窃取程序,导致 AI API token、GitHub token 和云凭据泄露。
Awaiting translation
Why it matters: 复盘 Miasma 蠕虫如何借 Claude Code、Cursor、Gemini CLI 的会话初始化配置实现零点击窃取凭据,可迁移到仓库配置来源校验。
Inside Claude Code, Anthropic has already built up hundreds of Skills in active use. The team sorts them into nine categories—library and API references, product validation, data fetching and analysis, business process automation, code scaffolding, code quality and review, CI/CD and deployment, runbooks, and infrastructure operations—and notes that the best Skills should fall cleanly into one of them.
Why it matters: Anthropic’s internal framework for categorizing hundreds of Skills, along with its experience writing them, can carry over to a team building its own Skill library.
Sophos X-Ops 发现一名俄罗斯威胁攻击者使用 Cursor IDE 和 Claude Opus 4.5 作为编排智能体,搭建了一个 80 模块的勒索软件工具包,并成功规避 Sophos、CrowdStrike 和 Windows Defender 的 EDR 检测。
Awaiting translation
Why it matters: Sophos 披露的攻击链显示,Claude Opus 4.5 被用作编排智能体,串起多智能体分工与 EDR 规避测试。
攻击者用 Google Sites 托管仿冒 Claude Code 和 Codex 的安装页,诱导开发者在运行对话框粘贴 mshta.exe 命令,投递无文件内存窃密程序,窃取 AI API key、浏览器凭据和开发者环境密钥。
Awaiting translation
Why it matters: 梳理了仿冒 Claude Code 与 Codex 安装页的 ClickFix 攻击链,可了解针对 AI 开发者凭据的窃取手法。
Anthropic has shipped dynamic workflows in Claude Code. Claude can write its own harness on the fly for a specific task, and these workflows can be shared and reused. Workflows orchestrate subagents through functions like agent(), parallel(), and pipeline(), and you can specify which model each agent uses and whether it runs in its own worktree. If a session is interrupted, resuming it picks up where it left off.
Why it matters: The Anthropic team breaks down six orchestration patterns for dynamic workflows and where each one fits, and these patterns carry over to multi-agent task design.
Oasis Security 将 URL 参数注入、Files API 外泄和开放重定向三个 Claude.ai 漏洞串联,在用户提交时静默窃取对话历史。攻击者把隐藏 HTML 标签放进 ?
Awaiting translation
Why it matters: Oasis Security 披露的攻击链说明默认 claude.ai 会话即可被静默窃取对话历史,并指出 MCP 集成会扩大影响范围。
Cloudflare built a CI-native AI code review system on top of the open-source coding agent OpenCode. A coordinating agent dispatches up to 7 dedicated review agents, split by security, performance, code quality, documentation, release, and internal standards, then deduplicates their output and posts a single structured review comment.
Why it matters: Cloudflare has published the plugin architecture, risk grading, and cost data behind its multi-agent code review in CI, and the setup can be ported to your own review pipeline.
Trend Micro 发布 Pwning Agentic AI Part I,披露 mcp/postgres Docker 镜像存在 RTT(return-to-tool)攻击:攻击者在客服工单中注入提示词,让连接数据库的 AI 智能体从生产 PostgreSQL 表读取认证令牌并发布到公开客户评论线程,全程只用智能体已授权的工具,未触发告警也未违反策略。
Awaiting translation
Why it matters: 梳理 RTT 攻击如何只用智能体已授权的工具完成数据外泄,并给出工具调用门禁这一可迁移的拦截思路。
Augment wires the Incident Investigator expert from its internal Cosmos platform into Slack and PagerDuty. It automatically triages every alert and runs root-cause analysis, then suggests one of four actions: fix the code, roll back, upgrade, or just keep monitoring. Humans only review the RCA and make the call.
Why it matters: Augment has shared the full playbook for putting Cosmos Expert on alert triage, along with a month of before-and-after data, so you can adapt it to your own on-call process.
作者用 paperctl CLI 抓取自己 19 天的 Claude Code 会话数据(3,697 条消息、Opus/Sonnet/Haiku 三个模型),发现 prompt caching 省下了 82% 的输入成本,实际输入花费 232 美元,无缓存等价成本为 1,321 美元。
Awaiting translation
Amp 本周宣布成立 Amp Labs,团队已与多家公司合作,新阶段从澳大利亚悉尼起步。Amp 官网同期发布《Software After Software》,阐述其对软件未来的判断以及 Amp 与 Amp Labs 的存在理由。联合创始人还做客 Mayank Gupta 播客,聊了自己如何进入编程、从练 Vim 到成为 Amp 联合创始人的经历。
Awaiting translation
Understand Anything 是一个 Claude Code 插件,用一条命令为项目生成包含每个文件、函数、类和依赖关系的交互式知识图谱,解决加入新代码库时的冷启动问题。
Awaiting translation
OpenAI 创始成员卡帕西于 2026 年 5 月 19 日加入 Anthropic 预训练团队,Anthropic 为他新建了一个子团队。据预训练团队负责人 Joseph 在 X 上的说法,卡帕西将带领新团队用 Claude 加速预训练研究本身,即让 Claude 帮研究员提代码方案、写预训练代码、跑消融实验、生成并筛选训练数据,卡帕西负责把关。
Awaiting translation
GitHub confirms that roughly 3800 internal repositories were leaked, including Copilot's internal code and GitHub Actions workflow source code, after an employee installed an Nx Console 18.95.0 VS Code extension poisoned by TeamPCP.
Why it matters: The timeline and technical chain are complete, showing how a VS Code extension supply-chain poisoning attack stole credentials and leaked internal repositories.
Anthropic 工程师 Thariq Shihipar 提出用 HTML 替代 Markdown 作为 Claude Code 的输出格式,理由是 HTML 信息密度更高、更易阅读和分享,还能做双向交互。
Awaiting translation
Why it matters: Anthropic 工程师分享用 HTML 替代 Markdown 承载 Claude Code 输出的做法,附常见场景的提示词与模板。
Learn Harness Engineering 是一门专注 AI 编程智能体工程的课程,综合了 OpenAI 关于在 agent-first 世界中使用 Codex 的 harness engineering 实践,以及 Anthropic 关于长时运行智能体 harness 设计与应用开发的两篇文章。
Awaiting translation
作者结合一年在真实生产系统上使用 Claude Code 的经验,对 Anthropic 发布的企业级大型代码库 playbook 做了实践补充。
Awaiting translation