Skip to content
Guidance/Daily Briefing
digesteveryonedigestevidenceradaragentmodel11 min read · Oct 7, 2026

Radar brief — 2026-10-07

A busy 36 hours: 22 releases from 11 tools. Three changes land first because they hit nearly every daily user of that assistant.

What the evidence shows

Must-know first, then the rest of today’s versioned GitHub-style signals. Rows with omitted changelog tails are marked; those extra items are not inferred.

Kilo Codev7.8.7 (pre-release)
Key Signal & Impact
Multi-project Agent Manager is default; current workspace is first; experimental toggle and old single-project view are gone. Tabs, background sessions, and branch defaults stay with their project. Shortcut hints in the prompt; Integrated Browser can open in an editor tab per session. +43 changes omitted.
Mistral Vibev2.26.0
Key Signal & Impact
Warns when the selected model cannot view attached images. Sessions list background processes with live status and Stop. ~/.vibe/.env key fallback is 0600. Rust CLI: first-run onboarding (keyring + browser sign-in), /teleport, /voice, /loop, undo/redo, vibe update. App-server can discover built-in plugins from embedding-app roots. +88 changes omitted.
Google Antigravity1.3.0
Key Signal & Impact
Default Verbosity is now medium (grouped tool/thought summaries). Applies to unset users and anyone who selected high while it was the default — set /config back to high for full traces. j/k in /diff now move the line cursor; arrows switch files. Fixes trackpad jump-scroll and paths with spaces/#/%.

| GitHub Copilot CLI | v1.0.92 | copilot config list/read/set/remove. Pre-conversation Ctrl+E picker for local vs cloud. Entra MCP can silently renew access-token-only credentials. Legacy HTTP+SSE MCP POSTs no longer hang past the server timeout. Sandboxed shells withhold ambient GITHUB_TOKEN unless explicitly configured. Large-file writes no longer stall the session. +26 changes omitted. | | Cline | cli-v3.0.69 | Windows npx/uvx MCP servers often exceeded a 3s start limit and were dropped; default is now 10s. Custom Anthropic base URLs (Azure AI Foundry, gateways) no longer 400. Reasoning level snaps to what the model accepts (Kimi K3). cline config --json prints JSON again. -y/--yolo is documented as sandbox-only. | | Claude Code | v2.1.292 | claude plugin install --marketplace <source> (same policy as marketplace add). Agent tool gains effort for sub-agents. CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS for 529 backoff. Security: sandboxed commands could read /ultrareview staged copies under ~/.claude/seed-admin; mid-session sandbox deny paths failed to drop grants; notebook/PDF reads on macOS/Windows could follow a swapped link outside the approved file. +79 changes omitted. | | Claude Code | v2.1.290 | Plugin/mod hooks: serverToolUses on turn.step, agentId and org ceiling on tool.check. claude attach/logs by partial session name. Warnings when managed settings are a symlink outside the managed folder, or ignore user sandbox allowRead/domains. +77 changes omitted. | | Claude Code | v2.1.291 | Fixes 2.1.290 dropping answers to permission prompts in cloud sessions, and 2.1.288 losing last messages on quit. | | Google Antigravity | 1.3.1 | /diff file view: arrows open next/prev file at first change; n/N continue across files; header shows change A/B and file X/Y. /rewind no longer lists compacted turns as (empty message) or errors when picked — they are dimmed and unselectable. +10 changes omitted. | | GitHub Copilot CLI | v1.0.93-2 (pre-release) | Enterprise permissions.limitTo for managed domain boundaries. Model picker recommends GPT-6.1 Sol, GPT-6 Astra/Luna, Claude 5.5. Breaking: user settings are read only from ~/.copilot/settings.json; user-setting keys in ~/.copilot/config.json are ignored. | | GitHub Copilot CLI | v1.0.93-4 (pre-release) | Command sandboxing for all users via /sandbox and --sandbox. Local-network allowlists include localhost/loopback. Safe /user commands run during active turns; unsafe remote commands are rejected without dialogs. | | Cline | sdk/v0.0.91 | Unknown/missing finish reasons are no longer treated as stop; one hidden continue, then fail. Stdio MCP initialize budget 10s (was 3s). Anthropic server-side fallbacks sent only to api.anthropic.com. +9 changes omitted. | | OpenAI Codex CLI | rust-v0.160.1 | Remote stdio MCP with explicit env still preserves SYSTEMROOT, TEMP, and TMP so Unix hosts keep the Windows executor’s startup environment (backport of #51121). |

| Kiro | v2.27.1 | HTML changelog (not a GitHub tag): Workflows sub-agent tool on by default when Workflows are enabled; live #[[file:...]] / #[[folder:...]] in Steering; saved prompts as slash commands. +22 changes omitted. Prefer GitHub-style notes when they appear. |

Source mix: 54% GitHub/changelog vs HTML. Kiro is the HTML changelog in this set. Stats report 1 source with errors — treat that feed as noisy until the next clean tag. Augment Code and Codex alpha notes are in What to ignore.

For developers

  • Antigravity 1.3.0/1.3.1: If you still want every tool call and thought, set Verbosity back to high in /config. Relearn /diff: j/k move lines, ←/→ switch files, n/N walk changes across files. Do not try to rewind compacted turns.
  • Copilot CLI v1.0.92: Use copilot config instead of hand-editing. Ctrl+E before a chat to pick local vs cloud. If you live on the 1.0.93 pre-release line, move user keys into ~/.copilot/settings.json now — config.json user keys are ignored in v1.0.93-2. Try /sandbox / --sandbox only after you know v1.0.93-4’s localhost allowlist.
  • Mistral Vibe v2.26.0: Run the Rust CLI wizard (--setup or first run) so the key lands in the OS keyring, not a world-readable file. Expect a warning when the model cannot see images. Use the session side panel to Stop background processes; /teleport, /voice, and /loop are in this tag.
  • Cline CLI v3.0.69: Windows MCP users should upgrade — tools that never appeared were dying at 3s. Do not use -y/--yolo outside a sandbox. SDK consumers: unknown finish reasons now continue once, then fail the run.
  • Claude Code: Do not stay on v2.1.290. Take v2.1.292 (v2.1.291 is the permission-prompt / quit-message hotfix). New knobs: Agent effort, claude plugin install --marketplace, CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS. Partial session names work with claude attach / claude logs.
  • Kilo Code v7.8.7 (pre-release): Expect Agent Manager, not the old single-project UI. Shortcut hints follow your keybindings; turn them off in Display settings if they get in the way. Each session can own a browser tab.
  • Kiro v2.27.1: If you use Workflows, the new sub-agent tool setting is on by default — turn it off under /settings features to force delegation through Workflows only. Saved prompts become slash commands.

For teams

  • Copilot CLI v1.0.92 (do this): After upgrade, explicitly grant GITHUB_TOKEN in the sandbox if agents must talk to GitHub. Ambient injection is gone. Pair with the open team proposal to upgrade and grant that token. Entra-protected MCP can renew access-token-only credentials without a human loop — confirm that matches your token policy. v1.0.93-2 adds enterprise permissions.limitTo for managed domain boundaries; keep it off the default path until the pre-release line settles.
  • Claude Code v2.1.292: Treat as a security patch, not a feature drop. Sandbox deny paths, /ultrareview staged copies, and notebook/PDF link-swap reads were wrong. v2.1.291 is required if anyone ran 2.1.290 in cloud sessions (permission answers could be dropped). Watch managed-settings symlink and sandbox allowRead warnings in /status and doctor.
  • Mistral Vibe v2.26.0: The ~/.vibe/.env 0600 fix matters on shared machines and jumphosts. Confirm embedding apps that ship plugin roots are paths you intend the app-server to load. There is an open everyone/P5 proposal to name a cheaper model under utility_models for session titles and smart approve — that is config, not a missing release.
  • Cline: Fleet Windows laptops with npx/uvx MCP were silently tool-less; 10s initialize is the new default (explicit timeout still wins). Custom Anthropic endpoints should stop 400ing; official fallbacks stay on api.anthropic.com only.
  • Kilo Code: Multi-project is no longer opt-in in this pre-release. Plan for Agent Manager as the shared surface (tabs, background sessions, PR review shortcuts) before you roll v7.8.7 past early adopters.
  • Antigravity: The verbosity default rewrite will change what reviewers see in conversation logs. If audit needs full command/thought traces, set high in /config as policy, not preference.
  • Codex CLI rust-v0.160.1: Only material if you launch remote stdio MCP from Unix toward a Windows executor with a locked-down env.

What to ignore

  • Augment Code v1.2.0-prerelease.202610061520, …1216, and …0923: three near-duplicate install notes (curl installer, Node SEA binaries, macOS -sea unsigned, Linux SHA256SUMS). No product behavior in the evidence.
  • OpenAI Codex CLI rust-v0.162.0-alpha.18: body is only “Release 0.162.0-alpha.18”. No signal.
  • Any “+N more changes” tails (bodyOmitted on Copilot 1.0.92, Kilo, Mistral, Claude 2.1.290/292, Antigravity 1.3.1, Cline SDK, Kiro). Those lines are unpublished here — do not plan from them.
  • Copilot v1.0.93-* model-picker names and sandbox-for-everyone until that line is a non-pre-release tag.
  • Kiro’s HTML changelog as a peer of GitHub tags; 54% of this window is GitHub/changelog, and one source is reporting errors.

Watch next

  • Whether Kilo v7.8.7 leaves pre-release with the same default Agent Manager (43 omitted lines could still move the story).
  • Copilot CLI 1.0.93 stabilizing: settings.json vs config.json, permissions.limitTo, and /sandbox for all users.
  • Claude Code hook/mod surface (prompt.autocomplete, effort, marketplace install) vs another permission-prompt regression.
  • Mistral Vibe omitted bulk (88 lines) and the cheaper utility_models proposal.
  • Codex 0.162 alphas actually growing a changelog.
  • Open proposals not evidenced as shipping in this JSON: Qwen Code hosted MCP, Zed spawn_agent / GPT-6.1 Sol BYOK, Goose v1.53.0, Windsurf/Devin Fusion, xAI Grok CLI harness. Track those as radar work, not as releases.

How to use DevAgentRadar

This brief is a public cut of the radar: judgment from tagged releases, not vendor marketing. New (isNew) items are the last 36 hours; mustKnow is a ranking hint that the change hits almost every daily user of that tool — always cite the version itself.

Use it as an upgrade checklist, not a feature catalog. Developers take the per-tool actions; teams take token, sandbox, MCP, and default-UX policy. Ignore omitted changelog tails, empty alphas, and unsigned prerelease installers. If you maintain a fleet, start from the open proposals that match today’s tags (Copilot sandbox GITHUB_TOKEN, Mistral utility_models) and wait for a non-pre-release tag before you change defaults for everyone.


Evidence appendix

  • New in the last 36 hours: 22 release(s) from 11 tool(s)
  • Evidence window: new releases first, then top curated signals (versioned releases preferred)
  • Assistants tracked: 29
  • Signals in this brief: 40
  • Trusted source mix (GitHub/changelog vs HTML): 54%
  • Open improvement proposals: 8
  • Sources reporting errors: 1

High-signal releases used

  • GitHub Copilot CLI v1.0.92: 2026-10-05 · Add copilot config subcommands to list, read, set, and remove settings. · Add a pre-conversation Ctrl+E environment picker to switch between loca — source

  • Kilo Code v7.8.7 — (pre-release): #14797 ecb450b - Ma — source

  • Mistral Vibe v2.26.0: The app-server can discover built-in plugins from roots an embedding application ships, alongside the ones inside the package. · Vibe Code warns when the select — source

  • Cline cli-v3.0.69: MCP servers launched with npx or uvx on Windows now load. · They often took longer than the 3-second startup limit and were silently dropped, so their tools — source

  • Claude Code v2.1.292: Added --marketplace <source> to claude plugin install: adds the marketplace if needed, under the same policy checks as claude plugin marketplace add, then — source

  • Claude Code v2.1.290: Added serverToolUses to the result of a mod's turn.step hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end — source

  • Google Antigravity 1.3.1: Improved navigation in the /diff file view: ←/→ now open the next or previous file at its first change with the hunk header and leading context in view, e — source

  • GitHub Copilot CLI v1.0.93-2: Added · Add enterprise permissions.limitTo to enforce managed domain boundaries for network requests · Improved · Model picker updates the recommended l — source

  • GitHub Copilot CLI v1.0.93-4: Improved · Command sandboxing is available to all users via /sandbox and --sandbox. · Fixed · Run safe /user commands immediately during active turns, r — source

  • Cline sdk/sdk/v0.0.91: Responses that end with a missing or unrecognized finish reason are no longer treated as successful completions. AgentModelFinishReason gains unknown (the A — source

  • Claude Code v2.1.291: Fixed a regression in 2.1.290 where cloud sessions could drop answers to permission prompts · Fixed a regression in 2.1.288 where the last messages of a session — source

  • Google Antigravity 1.3.0: Changed the default Verbosity setting from high to medium, so the conversation view now groups related tool calls and thoughts into concise summaries whil — source

  • OpenAI Codex CLI rust-v0.160.1: Preserve SYSTEMROOT, TEMP, and TMP when launching remote stdio MCP servers with explicitly configured remote environment variables, allowing Unix hosts to — source

  • Augment Code v1.2.0-prerelease.202610061520 — auggie-v2 v1.2.0-prerelease.202610061520: Install the latest release (macOS/Linux): · curl -fsSL https://github.com/augmentcode/auggie/releases/latest/download/install.sh | bash · Install a specific ver — source

Open proposals

Was this guidance useful?

Anonymous · one vote per visitor · re-click to clear. Helps improve digests—not a product ranking.