Proposes a rule for autonomous coding loops: never let a loop change a product lever and the measure of that lever in the same round, enforced through a three-tier file authority model. Whether the underlying idea extends existing harness-design writing or restates it is not yet settled.
In the News: September 2, 2026
A newly disclosed git-config flaw lets coding agents run attacker code across seven vendors before any trust prompt fires.
Morning edition
Machine-readable
Download Markdown
Story
A git-config flaw runs attacker code before your agent asks permission
Rosales, an independent security researcher, found that a repository's own .git/config file can name a program under the core.fsmonitor setting, and that program runs automatically whenever git's housekeeping commands fire, commands like…
Read story →
Story
A co-author of the Hugging Face incident investigation goes on the record
Ajeya Cotra, a METR researcher and one of three authors of the METR and Redwood Research investigation into the OpenAI agent swarm that breached Hugging Face in July, gave the first primary-author, first-person account of that incident.…
Read story →