$ cat ai-agents/month/2026-09-01.log
the month in review · September 2026
OpenCode npm installs and Claude Desktop file bug
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
Two exploitable holes this month: one on OpenCode servers installed via npm, one on macOS Claude Desktop opening files from Cowork folders.
Cross-site OpenCode server upgrade request can install arbitrary packages for npm-based installations anomalyco/opencode
A cross-site request against an OpenCode server can make it install arbitrary packages, but only for npm-based installations. If you run OpenCode that way, treat the server as exposed until you upgrade. The advisory lists this as a breaking entry.
Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host anthropics/claude-code
On macOS, opening a malicious file from a Cowork folder can execute commands on the host. Claude Desktop users should upgrade before opening shared or downloaded files. The advisory lists this as a breaking entry.
langchain==1.4.0 langchain-ai/langchain
by github-actions[bot]
The 1.4.0 line adds a `langchain.mcp` namespace and an `MCPAdapter`, with runnable examples in the docs, plus an agent tool-routing fix that now includes the model destination. Anthropic middleware traces are also trimmed. Anthropic 1.7.1 ships the Claude Fable 5.1 support and the same trace change; 1.7.2 preserves invalid tool use blocks instead of dropping them; 1.4.1 preserves open MCP objec...
v2.1.277 anthropics/claude-code
In a project with no CLAUDE.md, Claude Code now reads AGENTS.md instead, switchable under "Project instructions" in `/config`, though the release notes say it is not yet on Bedrock, Vertex or Foundry. Gateway operators also get `CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1` for deployments where the Claude apps gateway is your only egress boundary.
langchain==1.4.1 langchain-ai/langchain
by github-actions[bot]
Agent Plugins are discovered and run by the shared Hub: packages under `~/.agents/plugins` are validated from their `plugin.json`, valid Agent Skills become available to the agent, and stdio, Streamable HTTP and SSE MCP servers start automatically. Settings then lists them under Customize.
Desktop v0.0.28 cline/cline
by github-actions[bot]
Desktop no longer sticks on "Desktop backend unavailable" when the hub is slow to start, because the shell no longer gives up after roughly 15 seconds while waiting for the backend address. v0.0.27 fixed the other half of that experience: an expired sign-in now produces one actionable error instead of two competing failure messages.
v1.20.0 OpenHands/OpenHands
by openhands-release-bot[bot]
Agent profiles land properly in 1.20.0 with per-profile secret selection and Docker context forwarding, after 1.17.0 surfaced manifest-declared value statements on dashboard cards and 1.18.0 added attachment image preview and creator-only controls. Practically, profiles are now how you scope what an agent can reach.
CLI v3.0.64 cline/cline
by github-actions[bot]
A model turn that burns its whole output allowance before making a tool call no longer ends the run: the turn is retried up to three times with a reminder to be concise. Reasoning-heavy prompts that previously died on an output-token-limit error now recover.
$ ls ai-agents/month/ # the briefings behind this review
Keep up with Agentic Coding in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.