The Cline team built a code review agent with the Cline SDK, splitting review into two agent loops—review and judge—then using a driver script to batch-submit the surviving issues as a single COMMENT event to the GitHub PR.
Why it matters: A full breakdown of the plugin, Hooks, and two-stage loop behind a code review agent, transferable to other automated review scenarios.
Lovable shared a retrospective on how it connected its platform app to third-party services: first it supported MCP as a stopgap for pulling context into chats, then it built app connectors of its own, using a Connector Gateway to proxy requests between published apps and third-party APIs. The gateway holds credentials and refresh logic, so deployed apps never touch the keys.
Why it matters: Lovable’s retrospective on turning connectors into reusable infrastructure is worth a look for teams doing third-party integrations and credential management.
OpenAI engineers use Codex with the open-source notebook app Runme to automate repetitive work such as running model evaluations. The approach: write a goal cell in the Runme notebook, have Codex read the goal, produce a plan, and wait for human approval before executing, logging commands, outputs, and conclusions along the way—including the dead ends.
Why it matters: The author uses the Runme notebook plus WebMCP to hand the evaluation process over to Codex; readers can borrow the way it handles goals, approvals, and context capture.
OpenAI has open-sourced the harness that drives the Codex app, CLI, and IDE extensions, and through the Codex app-server client protocol it exposes capabilities like creating threads, starting turns, receiving events, and handling approval requests.
Why it matters: With the Codex harness and app-server protocol now public, developers can see how to embed the agent in their own products and where the boundaries are.
8/18Tue
Tuesday
Permission Protocol · AI Agent Incident TrackerSelectedAI score7878
Context7 MCP's custom AI instruction feature returns unsanitized attacker content alongside normal document queries, carrying injected instructions into the coding agent's trusted context and tricking it into reading keys, exfiltrating data, or deleting files.
Why it matters: The material breaks down how Context7 MCP injects prompts through custom instructions, and offers a mitigation approach: adding an authorization gate at the tool invocation boundary.
8/14Fri
Friday
InfoQ · AI Coding PresentationsSelectedAI score8080
Vercel ships v0 API, giving programmatic, headless access to the v0 app-generation agent: send a prompt, v0 generates an app, spins up a dev server in the Vercel Sandbox, and returns a preview URL you can embed in your own UI. The API is now generally available.
At Prime Radiant, author Jesse Vincent used Claude Code—working through the Slackline command-line Slack client—to collaborate with his own agent Ada: Claude proposes changes, Ada reviews and tests them, then Claude deploys the updates, forming a development loop where the agents review each other.
Why it matters: By looping two agents through mutual review, testing, and deployment, the author shows a transferable model for collaborative agent-based development.
6/8Mon
Monday
Permission Protocol · AI Agent Incident TrackerSelectedAI score8888
X41 D-Sec found CVE-2026-48710 (BadHost): injecting a single character into the HTTP Host header of requests sent to an MCP server or AI agent harness built on Starlette makes the authentication middleware evaluate the wrong path from request.url.path, letting unauthorized access through.
Why it matters: This post breaks down how the BadHost vulnerability works, its blast radius, and the fixed versions, and explains what an authorization gate does and does not cover.
Codex team member jason (@jxnlco) shares how to get the most out of Codex, the key being to combine persistent conversation threads, voice input, task intervention and queuing, MCP servers and connectors, conversation thread automation, goal setting, and the sidebar.
Why it matters: A member of the official Codex team breaks down how to use persistent conversation threads, task intervention, automation, and goal setting—approaches you can carry over into everyday agent workflows.
5/14Thu
Thursday
Permission Protocol · AI Agent Incident TrackerSelectedAI score7878
Simon Willison explains how to put the LLM CLI tool in a script's shebang line so that plain-text files—in English or any other language—can be run directly. The key trick is #!