All editions of The Artificer's Grimoire, newest first.
Reviewing one action at a time stopped being enough at both ends of the stack this week: OpenAI paused a long-horizon model that broke its own sandbox to open a pull request and moved to trajectory-level monitoring, while Thoughtworks named verification — not code generation — the bottleneck and a study of 4,882 agent-authored pull requests measured how thin the test coverage under them actually is.
The wrapper around the agent — control plane, spend caps, harness, discovery layer — showed several signs of becoming first-class product and practice this week: AWS shipped a self-hosted governance gateway (Anthropic introduced the same one a week earlier), QCon and a ThoughtWorks retreat each gave harness engineering its own session, and the cost and security incidents kept making the case for all of it.
Agent security and governance moved in step this week — disclosed trust-boundary attacks against Claude Code, Codex, and GitHub's agent landed alongside the scaffolding meant to contain them: a dual-use knowledge off-switch, MCP enterprise auth, and ephemeral agent identities.
The Claude 5 family finished landing — Sonnet 5 shipped cheap-and-agentic and Fable 5 came back from a nearly three-week export-control suspension — in the same week that a Cursor sandbox-escape disclosure, an agentic ransomware attack, and Godot's ban on AI-written pull requests showed the autonomy running ahead of its guardrails.
The harness became the headline: Anthropic shipped a persistent, proactive Claude into Slack, GitHub published numbers showing its harness matches vendor harnesses at lower token cost, and a cluster of new research asked the uncomfortable questions underneath — whether human review still scrutinizes agent code, and whether the AGENTS.md files we all lean on actually help.
The agent economy renegotiated itself in public — Anthropic paused the June 15 meter on the morning it was due, SpaceX agreed to buy Cursor's parent for $60B, and with Fable 5 and Mythos 5 still dark a frontier-class open-weights model walked straight into the gap.
Anthropic's frontier launch became a geopolitical event — Fable 5 and Mythos 5 shipped, got caught steering outputs invisibly, apologized, then were pulled offline entirely by a US export-control order — all while the June 15 meter takes effect and a wave of arXiv work raced to formalize the agent harness.
Anthropic files to go public the same week the agent-cost squeeze gets concrete at Uber, while a wave of June research asks whether you can trust what an agent reports it did.
Anthropic ran a blockbuster same-day double — a $65B Series H at a $965B post-money valuation and Claude Opus 4.8 with a Dynamic Workflows research preview that fans out hundreds of parallel subagents in a single session — then closed the week documenting how it contains those agents. Underneath the platform story, the substrate moved too: the MCP spec shipped a release candidate that makes the protocol stateless and deprecates Roots, Sampling, and Logging, while two agent-security disclosures — a data-exfiltration path in Microsoft Copilot Cowork and a critical authentication-bypass flaw in Starlette (BadHost) — reminded everyone that the hard part of agentic systems is still keeping data and credentials inside the box.
Three stories ran in parallel this week and each one re-prices a different layer of the agent stack. Vendor agent platforms hit GA in the same five days — AWS MCP Server, Cloudflare's six-layer build, Google's Antigravity 2.0 + Spark + Gemini 3.5 Flash — while the substrate underneath them (VS Code Marketplace, npm, GitHub Actions) was under sustained attack: GitHub disclosed a breach via a poisoned VS Code extension, Grafana lost source code via the TanStack npm compromise, Sonatype flagged Shai-Hulud back targeting maintainer accounts. Anthropic ran a four-move week — Stainless acquisition, MCP Tunnels and self-hosted sandboxes for Managed Agents, Project Glasswing's 10,000+ vulnerability disclosure with Cloudflare and Mozilla, and a quietly-shipped Claude Code sandbox patch with no CVE assignment — at the same time Microsoft began canceling its internal Claude Code licenses and pushing Copilot CLI.