Skip to content
Guidance/Daily Briefing
digesteveryonedigestevidenceradarmodelcli12 min read · Oct 10, 2026

Radar brief — 2026-10-10

A busy 36 hours: 22 releases from 11 tools. The signal that should change how you work today is control surfaces, not a new model card. Google Antigravity 1.3.2–1.3.3 ships an official /plugin marketplace (skills, MCP, subagents, rules, hooks) and tightens two safety defaults: -…

What the evidence shows

GitHub/changelog tags are 54% of the mix. Prefer the versioned GitHub rows below; HTML notes (Factory Droid, Kiro) are thinner. Several bodies are truncated (bodyOmitted) — only the listed changes are in evidence. Two sources in the window reported errors; this brief does not have enough to name an incident.

Mistral Vibev2.26.1
Key Signal & Impact
App-server reports which process holds a stored session and notifies on release, so another client can show it read-only. Rust CLI: /proxy-setup, narrator/speaking row, /plugins + /reload-plugins, session-only s vs config-saving Enter in /model and /thinking, nix run .#rustCli, /whoami, enable_background_processes = false, enable_subagents = false. +75 changes omitted.

| OpenAI Codex CLI | rust-v0.162.0 | Tools to create/list managed Git worktrees (feature-flagged, trusted local projects). Pin Command Center tasks with p. /copy, Ctrl+Insert, tui.mouse_scroll_speed. Clickable URLs in prompts/warnings. Live web + remote compaction for custom Responses-compatible providers. apply_patch keeps CRLF. Linux/Windows sandbox hardening (denied files, writable construction executables, ripgrep deny-globs, Win10 drive letters). +132 omitted. | | OpenAI Codex CLI | rust-v0.162.1 | Fixes a TUI crash on multi-line async questions; startup no longer fails when a background server’s feature settings differ from CLI defaults (checks only on explicit CLI overrides). | | OpenAI Codex CLI | rust-v0.163.0-alpha.5 | Tag only: “Release 0.163.0-alpha.5”. No changelog body. | | Claude Code | v2.1.295 | Hooks: onFailure: "block" so a command/HTTP hook that cannot start, times out, or exits unexpectedly blocks the action. OSC 7501 program status. /copy strips > on quotes. Warning when plugin/marketplace writes hit a settings file that does not load. Gateway: timeouts.upstream_ttfb_ms, per-upstream models list, forceLoginMethod: "gateway". +80 omitted. | | Claude Code | v2.1.296 | Managed gateway managed.policies[] gains a code key (same settings as cli, also Claude Desktop Code tab; with desktop enables gateway mode). Subagent autoCompactWindow; CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL; CLAUDE_CODE_OVERLOADED_RETRY_MAX_DELAY_MS; Read tool allow_large. Fixes for managed PreToolUse/PostToolUse hooks, headless .mcp.json / plugin MCP after cd/reload, and gateway allowedProviders locking laptops out. +86 omitted. | | Google Antigravity | 1.3.2 | /plugin marketplace: browse/install official plugins (agy plugin install <name>@antigravity-plugins-official), local folder install, settings form, enable/disable/list. Author layout: .antigravity-plugin/ or .gemini-plugin/, PLUGIN_DATA, bin/. --dangerously-skip-permissions no longer auto-approves the /plan implementation — it only skips tool prompts. +6 omitted. | | Google Antigravity | 1.3.3 | Pinned prompt header while scrolling. MCP tools can set _meta: {"antigravity/alwaysLoad": true}. Plugins may ship root agents.json. macOS sandbox blocks ~/Library/Application Support by default (credentials/session tokens). Clearer HTML/quota errors. +17 omitted. | | Goose | v1.54.0 | First-run prompt for goose mode. HTML session export with interactive viewer. Adaptive thinking for Claude Sonnet and Haiku 5.5. Client extension selection is the exact session set. Hyphenated GPT 6.1 Sol effort aliases. Copilot token refresh, Bedrock cache-token totals, Databricks GLM pricing aliases. +12 omitted. | | GitHub Copilot CLI | v1.0.94 | Claude Haiku 5.5 in model picker and --model. MCP add recovers after interrupted init; enable/disable before discovery. Assisted permissions send visible shell code to the judge. Warning when managed settings suppress startup bypass-permission flags. Managed policy can disable Assisted Permissions (Manual Approval). | | GitHub Copilot CLI | v1.0.95 | Native Microsoft Entra broker auth on macOS (browser fallback). copilot config sandbox credential injectHosts + shell completion. --context applies to new and resumed ACP sessions. Managed plugin setup retries hourly / after policy change, not on every message failure. | | GitHub Copilot CLI | v1.0.96-2 | Prerelease: /model and /config model IDs are case-insensitive; canonical IDs are saved. | | Crush | v0.98.0 | OSC 7501 program status (via Bubbletea). Grok OAuth login. MCP sessions stay alive when a server lacks ping. UI fixes for sub-agent branches and multi-line answers. +34 omitted. | | Crush | v0.98.1 | Routes newer Copilot GPT-6 models through the Responses API. | | Factory Droid | v0.236.0 (Desktop v0.193.0 in the same note) | OSC-style terminal activity status. Runtime-built script calls now prompt for permission. Skills in delegated tasks. Org-managed custom model settings may carry non-credential request headers. Resume by session link. HTML changelog, not a GitHub tag. +10 omitted. | | Kiro | CLI 2.29.0 | Memory for local V3 sessions: learn repo commands/conventions, recall later. /memories → read & write / read only / off; untrusted workspaces can read but not write. HTML changelog. +8 omitted. | | Kiro | IDE 1.2.56 | Stub: “Workflow Feedback, Power Search, and Flexible Hook Matching.” No further body. | | Augment Code | v1.2.0-prerelease.202610091519 | Install-script / Node SEA packaging notes. macOS -sea assets unsigned. Not a product changelog. |

For developers

  • Antigravity: Run /plugin (or agy plugin install …@antigravity-plugins-official) only for plugins you intend to keep; fill settings before enable. If you used --dangerously-skip-permissions to skip plans, that path is gone — review /plan yourself. On macOS, expect sandbox denials under ~/Library/Application Support unless you add an explicit allow. MCP authors can mark hot tools with _meta.antigravity/alwaysLoad.

  • Codex CLI: Upgrade through 0.162.1 (not only 0.162.0) if you hit multi-line question crashes or background-server startup mismatches. Turn on worktrees only for trusted local projects. Use /copy / Ctrl+Insert; set tui.mouse_scroll_speed if the wheel feels wrong. CRLF repos should patch more cleanly without an opt-in.

  • Claude Code: Put autoCompactWindow on long-running subagents; use CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL when workflow agents should share one model. Set onFailure: "block" on command/HTTP hooks you treat as policy. allow_large on Read is for files you truly need in one shot. Watch /plugin when two plugins share a hook name.

  • Mistral Vibe: Prefer the Rust CLI (nix run .#rustCli if that is your install). Use s in /model//thinking for this session only; Enter still writes config. /proxy-setup for corp TLS; /whoami to confirm key scope. enable_subagents = false / enable_background_processes = false if you want a single-agent box. Expect a session open in another process to be read-only.

  • Copilot CLI: Select Claude Haiku 5.5 explicitly. Pass --context on resume, not just new ACP sessions. On macOS, Entra broker should appear before browser login. If model IDs flake on casing, the v1.0.96-2 prerelease is the narrow fix.

  • Goose: Complete first-run mode prompt. Export HTML when you need a shareable viewer. Set GOOSE_CLI_SHOW_THINKING if you want traces. Treat the GPT 6.1 Sol hyphenated aliases and Haiku 5.5 adaptive thinking as routing changes, not new local models.

  • Crush: Use v0.98.1 if Copilot GPT-6 models failed; v0.98.0 is the Grok OAuth / OSC 7501 drop.

  • Kiro CLI 2.29.0: In local V3, /memories → config. Start read only until you want automatic writes. Untrusted workspaces will not persist new memories.

  • Factory Droid: Expect new permission prompts on dynamically built script calls; terminals with OSC 7501 can show working / waiting / done.

  • Terminals: OSC 7501 is now in Claude Code, Crush, and Factory Droid. If your emulator supports it, agent status can live in the tab, not only the TUI.

For teams

  • Re-pin permissions, do not assume old bypass flags. Antigravity’s --dangerously-skip-permissions no longer rubber-stamps plans. Copilot CLI shows a warning when managed settings suppress startup bypass flags, and org policy can force Manual Approval by disabling Assisted Permissions. Treat those as compliance events, not UX nits.
  • Sandbox and credential paths. Antigravity’s macOS sandbox now denies ~/Library/Application Support by default — desktop tokens live there. Codex 0.162.0 hardens Linux deny-globs, rejects writable sandbox-construction executables, and restores Win10 drive-letter access. If you ship custom sandbox rules, re-test after these two upgrades.
  • Managed Claude gateway. v2.1.296’s code key applies CLI-like policy to Desktop’s Code tab; combining with desktop turns on gateway mode. v2.1.295 adds upstream TTFB timeouts, per-upstream models (with *), and forceLoginMethod: "gateway". Re-check allowedProviders so naming the gateway in user settings does not lock laptops out. Hook denials with "continue": false were fixed so they refuse the call without killing the turn.
  • Plugin supply chain. Antigravity’s marketplace installs skills, MCP, subagents, hooks, and bin/ tools. Claude Code now warns if plugin enable writes a settings file that does not load, and notes when one plugin’s hooks win on name collision. Inventory official vs local-directory plugins; do not roll marketplace installs as silently as editor extensions.
  • Mistral Vibe session locking is a collaboration default: a held session is read-only elsewhere. Decide whether the Rust CLI is the supported binary (/proxy-setup, /whoami) and whether enable_subagents / background processes stay on.
  • Factory Droid org custom-model settings may attach non-credential headers only; runtime script permission prompts will surface more in shared sandboxes.
  • Kiro Memory is per local V3 session with trust gating. If you do not want repo conventions written to disk, set read only or off before a team-wide CLI bump.
  • Open radar proposals still waiting on owners: re-pin Vibe thinking / Rust CLI; Cline provider pins; Qwen Code hosted MCP; Devin Desktop / Fusion model pin; Grok CLI harness; OpenCode verification videos. None of those are releases in this evidence pack.

What to ignore

  • Codex rust-v0.163.0-alpha.5 — empty alpha tag, not a reason to leave 0.162.1.
  • Augment Code prerelease — installer/SEA packaging, unsigned macOS -sea builds, no product notes.
  • Crush v0.98.1 checksum/cosign boilerplate — verification how-to, not a feature.
  • Copilot v1.0.96-2 unless you are hitting case-sensitive model IDs; it is a prerelease.
  • Kiro IDE 1.2.56 until a real changelog body exists (title-only).
  • Any “+N more changes” — omitted on purpose; do not infer breaking or pricing from the count.
  • Marketing tone in Crush release notes; internal scores/tags; HTML stubs weighted like GitHub releases.
  • Do not treat Goose “GPT 6.1 Sol” aliases, Crush “GPT-6 via Copilot”, or Copilot Haiku 5.5 as the same model launch — they are routing/catalog changes in three different CLIs.

Watch next

  • Codex 0.163 once it grows a body; 0.162.0 already wired live web access and remote compaction for custom Responses providers.
  • Whether Antigravity alwaysLoad MCP meta and plugin agents.json become the pattern other CLIs copy.
  • OSC 7501 uptake beyond Claude Code, Crush, and Factory Droid (Crush notes TUIOS/Rex already speak it).
  • Copilot Assisted Permissions vs managed Manual Approval — the policy warning in v1.0.94 is the tell that org overrides are live.
  • Two error-reporting sources in this window: wait for a versioned GitHub fix, not a status tweet.
  • The six open proposals, especially Mistral Vibe thinking/Rust CLI pinning if you standardize on v2.26.1.

How to use DevAgentRadar

This brief is a 36-hour public radar, not a vendor roundup. Rank from the evidence JSON: isNew leads, GitHub tags beat HTML posts, omitted bodies are not secrets to guess. Use For developers as personal upgrade actions and For teams as policy/sandbox/plugin defaults. Follow sourceUrl before you change a flag. Ignore scores, theme counts, and anything not in the cited version. If a day has no isNew signals, the radar will say so and recap the week — today was not that day.


Evidence appendix

  • New in the last 36 hours: 22 release(s) from 11 tool(s)
  • Evidence window: new releases first, then top curated signals (versioned releases preferred)
  • Assistants tracked: 29
  • Signals in this brief: 40
  • Trusted source mix (GitHub/changelog vs HTML): 54%
  • Open improvement proposals: 6
  • Sources reporting errors: 2

High-signal releases used

  • Mistral Vibe v2.26.1: The app-server reports which process holds a stored session, and pushes a change when that process lets go of it, so a client can show a session open elsewhere — source

  • OpenAI Codex CLI rust-v0.162.0: Add tools for creating and listing managed Git worktrees from trusted local projects when the worktrees feature is enabled. (#50148) · Pin tasks in the agent Co — source

  • Claude Code v2.1.296: Added a code key to the Claude apps gateway's managed.policies[]: the same settings as cli, also applied in Claude Desktop's Code tab; beside desktop, i — source

  • Google Antigravity 1.3.2: Added /plugin, an interactive manager for the official Antigravity plugin marketplace: browse and install plugins that bundle skills, MCP servers, subagents, — source

  • Claude Code v2.1.295: Added onFailure: "block" for command and HTTP hooks: a hook that can't start, times out, or exits with an unexpected code blocks the action instead of letting — source

  • Goose v1.54.0: Prompt for goose mode during first-time configure #12629 · HTML session export with an interactive viewer [#11 — source

  • GitHub Copilot CLI v1.0.94: 2026-10-08 · Add Claude Haiku 5.5 to model selection and --model completions · copilot mcp add recovers cleanly after interrupted MCP config initialization · MC — source

  • Google Antigravity 1.3.3: Added a pinned prompt header in no flickering mode while you scroll back through a long conversation: the prompt that produced the response you're reading stays — source

  • Crush v0.98.0: Hey! There’s some good quality of life stuff in this release. · Let’s take a look! · Following an update on [Bubbletea](https://github.com/charmbracelet/bubblet — source

  • GitHub Copilot CLI v1.0.95: 2026-10-09 · Use native Microsoft Entra broker authentication on macOS when available, with browser fallback. · copilot config supports sandbox credential injec — source

  • Crush v0.98.1: This fixes new GPT-6 models via Copilot! · Enjoy, · Charm XX 💫 · 8584922dc75b0911bf5dea2cbaec64af557f7a45: fix: route newer Copilot models through the Response — source

  • GitHub Copilot CLI v1.0.96-2: Fixed · Make model IDs in /model and /config model case-insensitive and save canonical IDs — source

  • OpenAI Codex CLI rust-v0.162.1: Fixed a TUI crash when asynchronous questions contain multiple lines, preserving line breaks and complete hyperlink destinations. (#51866) · Fixed startup failu — source

  • Augment Code v1.2.0-prerelease.202610091519 — auggie-v2 v1.2.0-prerelease.202610091519: Install the latest release (macOS/Linux): · curl -fsSL https://github.com/augmentcode/auggie/releases/latest/download/install.sh | bash · Install a specific ver — source

Open proposals

Was this guidance useful?

Anonymous · one vote per visitor · re-click to clear. Helps improve digests—not a product ranking.