Skip to content
Guidance/Daily Briefing
digesteveryonedigestevidenceradaragentmodel10 min read · Oct 6, 2026

Radar brief — 2026-10-06

Must-know today: Mistral Vibe v2.26.0 locks the ~/.vibe/.env API-key fallback to owner-only 0600, and Google Antigravity 1.3.0 silently drops default conversation Verbosity from high to medium (including people who left it at the old default). Also new in the last 36 hours: GitH…

What the evidence shows

Seventeen versioned releases from eight tools landed in the last 36 hours. GitHub tags dominate the high-signal items; Kiro’s notes come from HTML changelogs (weaker than GitHub tags). Several Copilot and Codex tags are prereleases with thin notes. One source in the window is reporting errors; treat HTML changelogs as noisier than GitHub releases. Bodies with omitted lines are cited only for what was published.

Mistral Vibev2.26.0
Key Signal & Impact
Must-know. API-key fallback file is now 0600. Vibe Code warns when the model cannot see images; sessions expose background processes with Stop. Rust CLI adds onboarding, /teleport, /voice, /loop, and package-manager-aware vibe update. Plugin discovery can use embedding-app roots. 88 further changes omitted.
Google Antigravity1.3.0
Key Signal & Impact
Must-know. Default Verbosity is now medium for anyone who never overrode it (including prior default-high). Restore full traces in /config. j/k in /diff move the line cursor; scrolling and special-character paths (#, %, spaces, Windows drives) are fixed.

| GitHub Copilot CLI | v1.0.92 | copilot config CRUD; Ctrl+E local vs cloud picker. Entra MCP tokens renew silently; HTTP+SSE MCP no longer hangs forever. Sandboxed shells withhold ambient GITHUB_TOKEN unless configured. Compaction keeps the latest prompt; large Anthropic requests retry after shrinking attachments; live shell stdout/stderr; large-file writes no longer freeze the session. 26 further changes omitted. | | Qwen Code | v0.25.0 | “No known breaking changes.” Local workspace-agent collaboration, A2A sharing, Mem0 bundled in the CLI, Broker worker contract, G0 public workspace file turns, private Hosted MCP (H1), hosted tool approvals, durable remote shell results and permission actions, workspace cold restore. 70 further changes omitted. | | Qwen Code | sdk-typescript-v0.1.18 | TypeScript SDK now bundles CLI 0.25.0 (and a stack of older CLIs in the same tag). Bundled 0.23.0 notes: memory.enableManagedAutoMemory and size-triggered microcompaction. 90 further changes omitted. | | Claude Code | v2.1.290 | Plugin hooks: serverToolUses on turn.step, agentId and org ceiling on tool.check. claude plugin validate lists gating hooks; Deny on gateway sign-in; claude attach/logs by name; managed-agents onboard commands; warnings when managed settings are outside the folder or ignore sandbox allow-reads. 77 further changes omitted. | | Claude Code | v2.1.291 | Fixes 2.1.290 dropping cloud permission-prompt answers, and 2.1.288 losing last messages on quit. | | GitHub Copilot CLI | v1.0.92-5 | Prerelease: pick Entra account after sign-in; /logout those OAuth sessions; same Entra MCP silent renew as v1.0.92. | | GitHub Copilot CLI | v1.0.93-0 | Prerelease: warmed LSPs keep running when sandboxing is off; truncated compact shell commands expand on click. | | OpenAI Codex CLI | rust-v0.160.1 | Remote stdio MCP on Unix keeps Windows executor SYSTEMROOT/TEMP/TMP when remote env is set (backported to 0.160). | | Kiro | v2.27.1 | HTML changelog. CLI Workflows: choose whether main chat delegates to sub-agents or only via Workflows. Steering gets live #[[file:…]] / #[[folder:…]]. Saved prompts become slash commands. Tightens access to local Kiro state. 22 further changes omitted. |

| Kiro | v1.2.37 | HTML changelog. IDE Workflows (off by default). Untrusted workspaces: ask before Kiro config/Hook/Power/workflow-recipe writes and before each command; recipes do not load until the workspace is trusted. Enterprise sign-in and region traffic controls. 1 further change omitted. | | Augment Code | v1.2.0-prerelease.20261005* | Three prerelease tags. Install-script + Node SEA binaries; macOS SEA unsigned; Linux publishes SHA256SUMS-sea. No product-behavior changelog in the evidence. | | OpenAI Codex CLI | rust-v0.162.0-alpha.15 / .16 | Alpha tags with no published change list. | | Kilo Code | jetbrains/v7.1.7 | Still relevant this week (not in the 36-hour set): JetBrains Marketplace for agents/MCP/skills, Kilo Swarm board, worktree cleanup, CLI background/cron/PR linking. 25 further changes omitted. |

For developers

  • Antigravity 1.3.0: If traces look collapsed, set Verbosity back to high in /config. Re-learn /diff: j/k are line motion; left/right switch files. Paths with spaces or #/% should now @-mention and open correctly.

  • Copilot CLI v1.0.92: Use copilot config instead of hand-editing settings. Expect sandboxed shells not to inherit GITHUB_TOKEN until you grant it. Prefer v1.0.92 over the -5 prerelease unless you need the Entra account picker; skip v1.0.93-0 unless you want the LSP/expand fixes.

  • Claude Code: If you are on 2.1.290, upgrade to 2.1.291 before relying on cloud permission prompts or quit. Hook authors can use agentId, ceiling, and serverToolUses; claude attach/logs accept a name fragment.

  • Mistral Vibe v2.26.0: First-run wizard stores the key in the OS keyring; if it falls back to ~/.vibe/.env, that file should now be unreadable by other accounts. Try /teleport, /voice, /loop, and vibe update. Expect a warning when the selected model cannot view images.

  • Qwen Code v0.25.0: Opt into local workspace-agent collaboration, A2A sharing, and bundled Mem0 only if you want those surfaces; SDK users should take sdk-typescript-v0.1.18 so the bundled CLI matches 0.25.0.

  • Codex rust-v0.160.1: Install if you launch remote stdio MCP from Unix against a Windows executor. Ignore empty 0.162 alphas.

  • Kiro: CLI 2.27.x: Workflows sub-agent tool is on by default when Workflows are enabled—turn it off under /settings features if main chat should only delegate through Workflows. IDE 1.2.37: enable Workflows explicitly (kiroAgent.workflows.enabled). Untrusted folders will prompt on config writes and every command.

  • Open radar proposal for individuals: name a cheaper Mistral Vibe utility_models entry for session titles and smart-approve.

For teams

  • Copilot CLI: Treat v1.0.92 as a sandbox policy change. Workflows that assumed a sandboxed agent had GITHUB_TOKEN will fail until the token is granted explicitly. Radar proposal: upgrade and document that grant. Entra-protected MCP should renew access-token-only creds without a re-login; still verify HTTP+SSE servers honor their own ack timeout.

  • Claude Code: Roll 2.1.291, not 2.1.290. Use the new managed-settings warnings (symlink outside the managed folder; sandbox allowRead / allowed domains ignored). Gateway sign-in now has Deny so a waiting terminal unblocks. Org hook authors can enforce a ceiling on tool.check.

  • Qwen Code v0.25.0: Hosted MCP, hosted tool approvals, durable remote shell, and workspace cold restore are the team surface. Enable workspace-agent collaboration / Mem0 only with a policy for A2A sharing. Radar proposal exists to turn those on deliberately.

  • Mistral Vibe: The 0600 .env fallback is the security fix to require; embedding apps can now ship plugin roots next to the package. Confirm enable_system_trust_store matches how you want update checks to verify TLS.

  • Kiro IDE 1.2.37: Untrusted workspaces no longer load workflow recipes until trusted, and Kiro asks before agent/Hook/Power/.kiro/workflows/ writes even if broader file perms allow it. Pair with enterprise sign-in / region controls. HTML changelog—verify in product before mandating.

  • Kilo Code JetBrains 7.1.7: Marketplace can install agents, MCP servers, and skills from npm or git:…@tag#subdir; add a review path before Swarm boards and worktree cleanup hit shared machines.

  • Augment Code prereleases: macOS SEA assets are unsigned in the notes—do not treat them as a signed enterprise drop.

What to ignore

  • Codex rust-v0.162.0-alpha.15/16: tag-only, no changelog.
  • Augment v1.2.0-prerelease.* install-script spam (three near-identical tags).
  • Copilot v1.0.92-5 if you already have v1.0.92, except for the Entra account picker / /logout.
  • Qwen sdk-typescript-v0.1.18 as a feature dump—it is a bundler of CLIs, not a second product launch.
  • Kiro HTML pages for precise “Oct 2 / Oct 5” sequencing versus GitHub-dated tags; 54% of this brief’s mix is GitHub/changelog-class, the rest is HTML.
  • Internal judge scores, omitted “+N more changes,” and empty Copilot CLI title fields.

Watch next

  • Whether Copilot v1.0.93 ships the LSP-when-unsandboxed and expand-command fixes without staying prerelease.
  • Claude post-2.1.291 for any leftover cloud-permission or quit-flush issues.
  • Qwen Hosted MCP (H1) and workspace-agent A2A in real tenant use—large omitted tail on v0.25.0.
  • Codex 0.162 alphas growing a real changelog after the 0.160.1 Windows MCP env backport.
  • Signed Augment SEA builds (macOS currently unsigned).
  • Open proposals still on the board: Copilot sandbox token grant, Qwen hosted/Mem0 enablement, Mistral cheaper utility model, plus older Zed/Goose/Windsurf/xAI items not evidenced in this window.

How to use DevAgentRadar

This brief is judgment from published release evidence, not vendor marketing. New (isNew) tags are the last 36 hours; mustKnow items are ranked first because they change daily use. We prefer versioned GitHub releases over blogs/HTML, never invent omitted changelog lines, and split actions for people who type versus people who set policy. Use the tables as the source of truth, the For developers / For teams lists as checklists, and Watch next as the follow-up queue—not as rumored launches.


Evidence appendix

  • New in the last 36 hours: 17 release(s) from 8 tool(s)
  • Evidence window: new releases first, then top curated signals (versioned releases preferred)
  • Assistants tracked: 29
  • Signals in this brief: 40
  • Trusted source mix (GitHub/changelog vs HTML): 54%
  • Open improvement proposals: 8
  • Sources reporting errors: 1

High-signal releases used

  • GitHub Copilot CLI v1.0.92: 2026-10-05 · Add copilot config subcommands to list, read, set, and remove settings. · Add a pre-conversation Ctrl+E environment picker to switch between loca — source

  • Qwen Code v0.25.0: See the complete change list below. · No known breaking changes. · feat(agents): add local workspace-agent collaboration ([#11206](https://github.com/QwenLM/q — source

  • Qwen Code sdk-typescript-v0.1.18: This SDK release bundles CLI version: 0.25.0 · Source: CLI built from source (same branch/ref as SDK) · --- · This SDK release bundles CLI version: 0.24.7 · Sou — source

  • Mistral Vibe v2.26.0: The app-server can discover built-in plugins from roots an embedding application ships, alongside the ones inside the package. · Vibe Code warns when the select — source

  • Claude Code v2.1.290: Added serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end — source

  • Claude Code v2.1.291: Fixed a regression in 2.1.290 where cloud sessions could drop answers to permission prompts · Fixed a regression in 2.1.288 where the last messages of a session — source

  • Google Antigravity 1.3.0: Changed the default Verbosity setting from high to medium, so the conversation view now groups related tool calls and thoughts into concise summaries whil — source

  • GitHub Copilot CLI v1.0.93-0: Fixed · Warmed language servers stay running across LSP requests when sandboxing is disabled · Clicking a truncated compact shell command expands it — source

  • OpenAI Codex CLI rust-v0.160.1: Preserve SYSTEMROOT, TEMP, and TMP when launching remote stdio MCP servers with explicitly configured remote environment variables, allowing Unix hosts to — source

  • GitHub Copilot CLI v1.0.92-5: Improved · Select which account to use after Microsoft Entra sign-in, and let /logout sign out those OAuth sessions. · Fixed · Entra-protected MCP serve — source

  • Augment Code v1.2.0-prerelease.202610051518 — auggie-v2 v1.2.0-prerelease.202610051518: Install the latest release (macOS/Linux): · curl -fsSL https://github.com/augmentcode/auggie/releases/latest/download/install.sh | bash · Install a specific ver — source

  • Augment Code v1.2.0-prerelease.202610051436 — auggie-v2 v1.2.0-prerelease.202610051436: Install the latest release (macOS/Linux): · curl -fsSL https://github.com/augmentcode/auggie/releases/latest/download/install.sh | bash · Install a specific ver — source

  • Augment Code v1.2.0-prerelease.202610050923 — auggie-v2 v1.2.0-prerelease.202610050923: Install the latest release (macOS/Linux): · curl -fsSL https://github.com/augmentcode/auggie/releases/latest/download/install.sh | bash · Install a specific ver — source

  • Kiro v2.27.1: 2.27.1 Oct 2, 2026 Workflow Delegation, Live Steering Context, and Saved Prompt Commands Choose how V3 delegates with Workflows, include live file and folder co — source

Open proposals

Was this guidance useful?

Anonymous · one vote per visitor · re-click to clear. Helps improve digests—not a product ranking.