Skip to content
Guidance/Daily Briefing
digesteveryonedigestevidenceradarmodelagent7 min read · Aug 8, 2026

Radar brief — 2026-08-08

Plugins, plan-mode locks, and self-hosted runners dominate: Codex and Claude Code push portable agent surfaces, while Cline, Goose, and Windsurf tighten security defaults.

What the evidence shows

Versioned GitHub releases carry the weight this window. Themes cluster on agent/plugin portability, MCP/skills surfaces, CLI approval & sandbox controls, and security hardening (plan-mode write blocks, cyber-model auto-review, symlink write refusal, credential HTTPS).

Claude Codev2.1.224
Key Signal & Impact
Self-hosted runner for web/mobile/desktop sessions (Team/Enterprise); archive plugin install over HTTPS with optional SHA-256 pin; Bedrock region-prefix env; paste-cancel confirm
OpenAI Codex CLIrust-v0.147.0
Key Signal & Impact
Portable Agent Plugins + multi-catalog search; persistent ordered conversation sections; --approve-for-me auto-reviewed approvals; import Cursor skills / sync Claude·Cursor threads
OpenAI Codex CLIrust-v0.146.0
Key Signal & Impact
/new·/clear session naming, pin/switch side conversations; plugin manifests + Bedrock/Claude Code marketplaces; thread fork (incl. temporary); app-server ↔ remote Code Mode over WebSocket
OpenAI Codex CLIrust-v0.146.1
Key Signal & Impact
Safer automatic-review defaults for cyber-capable models; permission changes explained in TUI
Clinev4.1.4
Key Signal & Impact
Skills next to workflows in slash menu; remove model-initiated plan→act; hard-block file-editing shell in plan mode (not prompt-only)
Clinedesktop-v0.0.8
Key Signal & Impact
Edit any earlier message → fork + checkpoint rewind; transactional workspace-atomic restores; reliable checkpoints after restart/compaction/resume
Clinesdk/v0.0.67
Key Signal & Impact
Reasoning effort/budget normalized from models.dev catalog; explicit Anthropic thinking modes; OpenRouter default → anthropic/claude-sonnet-5
Goosev1.44.0
Key Signal & Impact
Security advisory GHSA-r5pp-p5r8-466r: arbitrary command exec via goose review / git core.fsmonitor; latest Gemini models; Stop hook gets working_dir
Google Antigravity1.1.10
Key Signal & Impact
Business sign-in for Gemini Enterprise (Cloud project, license seat, regional inference, org admin controls)
OpenCodev1.18.5
Key Signal & Impact
Claude adaptive-thinking shapes; Mistral reasoning history + cache stability; correct prompt-cache keys per SDK; server terminal/review transport fixes
Gemini CLIv0.54.0
Key Signal & Impact
Enforce HTTPS on GoogleCredentialsAuthProvider (cleartext leak fix); rotate session ID on model fallback; caretaker triage hardening
Zed AIv1.15.0-pre
Key Signal & Impact
git.diff_base (HEAD vs default-branch merge base); Project Panel drag-out; JSX/TSX linked editing + Emmet in arrow/return bodies (prerelease)
Windsurfv3.6.27
Key Signal & Impact
Devin Desktop Windows loads OS cert store (TLS-inspecting proxy fix); Local edit/write/apply_patch/notebook_edit refuse symlink targets
xAI Grok CLIed6d543
Key Signal & Impact
ACP session resume/close; cap live workflow subagents at 16; extract MCP images before truncation; sandbox no longer refuses large deny-glob workspaces

Gemini CLI nightlies/previews (v0.56.0-nightly…, v0.54.0-preview.0) mostly surface internal caretaker/triage plumbing—signal is real but noisy versus tagged stables.

For developers

  • Codex CLI: Try Agent Plugins and --approve-for-me on a throwaway repo; import Cursor skills once and confirm no duplicate threads. Skim permission copy after rust-v0.146.1 if you use cyber-capable models.
  • Claude Code: If on Team/Enterprise, prototype claude self-hosted-runner before relying on cloud sessions; pin plugin zips with SHA-256 via the new archive source.
  • Cline: Upgrade to v4.1.4 before long plan-mode sessions—you drive plan→act now, and mutating shell/file ops are hard-blocked. On desktop-v0.0.8, practice edit-earlier-message forks; restores are workspace-atomic.
  • Goose: Treat v1.44.0 as a security patch first—read GHSA-r5pp-p5r8-466r and drop any core.fsmonitor workaround that invoked goose review.
  • OpenCode / Gemini CLI: Pull v1.18.5 and v0.54.0 for thinking/cache and credential-HTTPS fixes; avoid building on caretaker nightly APIs.
  • Windsurf: v3.6.27 matters behind corporate TLS inspection and anywhere Devin Local might follow symlinks.
  • Grok CLI: Commit ed6d543 fixes sandbox startup on large deny-glob trees and caps subagents at 16—useful if workflows were stalling or fan-out heavy.

For teams

  • Enterprise auth & residency: Antigravity 1.1.10 Business sign-in maps Gemini Enterprise seats, region, and admin controls—evaluate before broad Gemini CLI/Antigravity rollout.
  • Self-hosted agent compute: Claude Code’s self-hosted runner is the clearest “run our sessions on our machines” signal this window; pair with plugin SHA-256 pinning for supply-chain policy.
  • Approval policy: Codex --approve-for-me plus safer cyber-model defaults (0.146.1) and Cline’s hard plan-mode write block are concrete levers—document which tier may auto-approve vs. must stay plan-locked.
  • Plugin governance: Codex plugin catalogs (local/personal/workspace/remote) and Claude archive HTTPS installs need an allowlist + hash pin process; Bedrock/Claude marketplace entries in 0.146.0 expand the blast radius.
  • Incident response: Goose GHSA and Windsurf symlink-write refusal are patch-now items for shared runner images and developer laptops.
  • Open proposals (8) sit mostly at P5 team improvements (Codex 0.145/0.144.6, Cline 4.0.7, Goose 1.44.0, OpenCode 1.18.5, Zed 1.13.0-pre breaking review)—triage after the security pins above.

What to ignore

  • Gemini CLI nightlies/previews caretaker Firestore/Pub/Sub/Cloud Run choreography unless you operate that internal agent path.
  • Zed v1.15.0-pre git/UI niceties until a stable tag; marked prerelease.
  • Marketing-adjacent version bumps without behavior change; this brief already filters to actionable release notes.
  • HTML-only changelog noise where GitHub tags exist for the same assistant—Windsurf’s cert/symlink fixes are the exception worth keeping.
  • Internal score / evidence-weight fields—not decision inputs.

Watch next

  • Codex Plugin manifest + marketplace auth hardening after the 0.146–0.147 drop.
  • Claude Code self-hosted runner networking, isolation, and billing edges on Team/Enterprise.
  • Cline ecosystem consistency: desktop checkpoint forks vs. v4.1.4 plan-mode blocks vs. SDK reasoning catalog.
  • Goose post-advisory follow-ups (any further fsmonitor/hook path CVEs).
  • Whether Zed’s git.diff_base and drag-out land unchanged in stable.
  • Grok CLI whether monorepo syncs graduate to tagged releases (currently commit-level).
  • Closure of the eight open improvement proposals, especially Goose 1.44.0 and Codex backports.

How to use DevAgentRadar

  • Read What the evidence shows first—every row is a cited versioned signal, not a vendor claim.
  • Developers: adopt patches and flags in personal tooling the same day; verify on a scratch branch.
  • Teams: translate security and approval rows into policy (auto-approve tiers, plugin pin requirements, self-hosted eligibility) before wide rollout.
  • Ignore unlisted assistants/versions—if it is not in the table, it is not in this brief’s evidence window.
  • Re-check Watch next and open proposals on the next pass; prefer GitHub/changelog primary sources over secondary HTML.

Evidence appendix

  • Evidence window: top curated signals (versioned releases preferred)
  • Assistants tracked: 22
  • Signals in this brief: 16
  • Trusted source mix (GitHub/changelog vs HTML): 55%
  • Open improvement proposals: 8
  • Sources reporting errors: 0

High-signal releases used

  • Claude Code v2.1.224: Added self-hosted environments: claude self-hosted-runner turns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can — source

  • OpenAI Codex CLI rust-v0.147.0: Install portable Agent Plugins and search across local, personal, workspace, and remote plugin catalogs. (#36544, #36409, #36919, #36796) · Organize conversatio — source

  • OpenAI Codex CLI rust-v0.146.0: Name new sessions with /new or /clear, pin important threads, and switch between side conversations without closing them. (#34605, #34840, #35011) · Support — source

  • Zed AI v1.15.0-pre: This week's release includes a new git.diff_base setting for choosing whether editor gutters, file-status colors, and git: diff show uncommitted changes aga — source

  • Google Antigravity 1.1.10: Added Business sign-in for Gemini Enterprise accounts, so you can authenticate with a Google Cloud project under Google Cloud terms, use a license seat allocate — source

  • Cline desktop-v0.0.8: Edit any earlier message in a conversation — the app forks the session at that point, rewinds the workspace to that run's checkpoint, and re-runs from your edit — source

  • Goose v1.44.0: Arbitrary command execution in goose CLI via goose review (via git core.fsmonitor config) - [GHSA-r5pp-p5r8-466r](https://github.com/aaif-goose/goose/security — source

  • Cline v4.1.4: Recognize Chutes as a provider. · Show skills alongside workflows in the slash command menu, and disambiguate commands that share a name instead of letting one — source

  • Cline sdk/sdk/v0.0.67 — Reasoning controls (effort, budget, on/off) are now driven by the models.dev catalog and normalized once before provider encoding, so requests match what each p — source

  • OpenAI Codex CLI rust-v0.146.1: Apply safer automatic-review defaults for cyber-capable models and explain permission changes in the terminal interface. (#37057) · #37057 [0.146] Backport safe — source

  • Gemini CLI v0.56.0-nightly.20260808.gcf22ac7e8: Reclassifying Capacity Exhaustion as Terminal Error · feat(caretaker): update Firestore schema with error, and pr_number fields · feat(caretaker-triage): prompt — source

  • Gemini CLI v0.54.0: Changelog for v0.53.0-preview.0 · Changelog for v0.52.0 · chore(release): bump version to 0.54.0-nightly.20260722.gf743ab579 · fix(caretaker): sanitize and wrap — source

  • OpenCode v1.18.5: Improve Claude adaptive thinking handling across more response shapes. · Avoid OpenAI Responses phase handling that could break some conversations. · Preserve g — source

  • Gemini CLI v0.54.0-preview.0: Changelog for v0.53.0-preview.0 · Changelog for v0.52.0 · chore(release): bump version to 0.54.0-nightly.20260722.gf743ab579 · fix(caretaker): sanitize and wrap — source

Open proposals

Was this guidance useful?

Anonymous · one vote per visitor · re-click to clear. Helps improve digests—not a product ranking.