AI that matters, from the architect's desk. Curated and engineered by Saaket Varma, PhD — no hype, just signal.
Today's stories expose four agent control surfaces: repo creation, browser consent, per-call OAuth scopes, and pre-execution task scope.
HOW TO READ THIS Follow the top row left to right: a prompt with no repo starts the agent, which previews through browser port forwarding; the lower row shows the Origin repo made behind it, the save that keeps the scaffold, and the Vercel step needed to publish.
Cursor, published by Anysphere, added a changelog entry on August 27 titled Start from scratch, without a repo. Cloud Agents no longer require a connected GitHub or other third-party source-control provider to get started: a user picks Start from scratch in the repo picker, prompts the agent, and Cursor creates an Origin repo in the background. It leads this edition because it removes the first setup step that separates a cloud agent from a prompt box, and because it is a shipped vendor release with a live changelog rather than a preview.
Once the build is to the user's liking, clicking Create repo saves the work into a Cursor Origin repo, with a custom or suggested name and private or internal visibility, and the result appears as a fully scaffolded repo under the Codebase tab. Cursor also port-forwards the agent's live environment straight to the browser, so the running result can be previewed there, including with tools like design mode. Connecting a Vercel account and hitting publish yields a live URL; a Vercel account is required for that step.
For anyone who has bounced off a cloud agent at the connect-GitHub prompt, this is the difference between trying an idea and provisioning for one. What differs from the earlier Cloud Agents flow, per the changelog, is the entry point: the repo, the preview and the publish step are now sequenced after the work rather than before it. The potential advantage is that Cursor keeps the whole loop from prompt to live URL inside its own hosting and repo layer, which could make Origin the default home for throwaway projects that later become real. The evidence is a single vendor changelog entry; there are no independent reports yet on how Origin repos fit an existing GitHub workflow, or what limits apply to the port-forwarded preview.
HOW TO READ THIS The agent's browse request must pass the consent shield — approval opens real-profile browsing, denial ends it — while a separate opt-in lane routes secrets into the OS keychain for encryption.
Nous Research tagged Hermes Agent version 0.20.6 as v2026.8.27 on August 27, a patch release that rolls up roughly 525 pull requests merged since 0.20.5 into a stable tag for Docker images, hosted deployments and fresh installs. Since 0.20.5, tagged on August 21, the window landed roughly 1,313 commits across roughly 1,557 files. It is here because the two additions that matter most for a self-hosted agent touching real accounts, consent-gated browsing and keychain-encrypted secrets, arrived in the same release.
Consent-gated real-profile browsing lets the agent use your default Chromium profile for local browsing, with a Windows close-with-approval flow, and the desktop Browser gets its own OS window. Stored secrets can now be encrypted through the OS keychain on an opt-in basis, which the notes say removes the per-launch macOS Keychain prompts. The remote MCP catalog grows by 50-plus live-verified vendor-hosted servers, Cloudflare, Grafana Cloud, Better Stack and Railway among them, alongside a managed SSH remote-update engine, a fleet profile rail, TTL caching for web_search and web_extract, and updaters that pause gateways over the control socket instead of tree-killing them.
An agent that browses as you, holds your tokens and updates itself is exactly the software that needs explicit gates, and this release adds the two that were missing. What differs from 0.20.5 is a list of shipped controls, not a measured security result; the maintainers say the full curated notes for the window ship with 0.21.0. The potential edge is breadth plus cadence, five releases since August 16 and a catalog that reaches many of the infrastructure vendors a developer already pays, if the live-verification claim holds over time. All of this is the project's own release notes; no external review of the consent gate or the keychain path exists yet, and the roughly 237 thousand stars shown at capture are a popularity signal, not a quality one.
HOW TO READ THIS Read left to right: each agent call passes its own runtime scope check and reaches GitHub with only the single permission that call asked for.
GitHub released version 1.11.0 of its MCP server on August 25 from the github/github-mcp-server repository, with per-call OAuth scope checks that request only the permissions each tool invocation needs, plus runtime checks where required. It follows 1.10.0 on August 19, which added confirmed repository deletion through form elicitation with protected multi-round-trip state, enforced HTTPS for GitHub Enterprise hosts, restricted bearer credentials to configured GitHub authorities and made invalid static --tools configuration fail closed. It is included because the most common agent-to-repo bridge is tightening its own authorization model, and the pattern is worth copying.
Rather than one broad grant at connect time, the server evaluates what a specific tool call needs and requests that, adding a runtime check when the scope alone cannot settle it. Browser clients gain CORS across the OAuth discovery routes and a configurable authorization-server URL through a new --authorization-server flag. The release also creates parent and sub-issues atomically, adds ETag conditional requests to the REST transport, described as better HTTP caching for STDIO, and moves the runtime to Go 1.27; a 1.10.1 patch on August 20 fixed an add_issue_comment schema regression in between.
For anyone wiring an agent to a repo that holds production secrets, per-call scoping narrows what a compromised agent session can reach. What is new relative to 1.10 is the granularity of the request, not a new authorization scheme; the complementary choice is that repository deletion now needs an explicit confirmation round trip. GitHub's potential advantage is that it owns both the OAuth authority and the most common agent target, so its defaults can become the reference other MCP servers are measured against. The release notes are the only source here; there is no independent audit of how the runtime checks behave against a misbehaving client, and the roughly 32.6 thousand stars at capture say nothing about which versions are actually deployed.
HOW TO READ THIS Read left to right: the V3 spec's task list passes a scope choice (all tasks or one) before execution, then runs inside a full-screen view that reports each task's live progress, with scrollback optionally kept below.
Kiro shipped CLI 2.20.0 on August 26, giving V3 spec runs a dedicated full-screen task execution view with real-time progress and task scope selection, opened by running a spec with the /spec run command. It follows 2.19.0 on August 19, which added a stream idle watchdog and automatic retries, with patches 2.19.1 and 2.19.2 on August 21 and 25. It is here because the two releases together turn Kiro's spec-driven workflow into a supervised, self-recovering execution loop rather than a chat transcript.
In the full-screen view you follow progress as tasks run and choose the task scope before execution begins; a Preserve scrollback toggle keeps terminal history available through overflow and resize redraws. The 2.19.0 watchdog warns after 60 seconds of silence and cancels at 300, throttling, 5xx errors and connection drops are retried automatically with backoff, and streaming responses get a 60-minute timeout by default so long outputs are no longer cut off, all tunable through api.streamIdleSoftTimeout, api.streamIdleHardTimeout and api.timeout. Spec review gained mouse support, scroll to navigate and click to position the cursor with the m key toggling it, building on the 2.18.0 review screen that opens with Ctrl+X at a phase checkpoint.
Long agent runs die quietly on dropped streams far more often than on bad reasoning, so a watchdog with backoff is a reliability feature, not polish. What differs from prior Kiro releases is that scope selection now happens before anything executes, which puts the human decision at the front of the run instead of in a review afterwards. The potential edge is that a spec-first tool can bound what an agent touches by construction, an advantage worth watching against Cursor and Claude Code if teams actually keep their specs current. The evidence is Kiro's own changelog; nothing here measures how often the retries succeed or how the full-screen view holds up on a multi-hour run.
A plugin marketplace that packages agents and skills once and installs them across Claude Code, Codex, Cursor, OpenCode, GitHub Copilot and Antigravity, so a team's workflow does not have to be rebuilt per harness.
Routes Claude Code, Codex, Pi, OpenCode and similar CLIs through free token pools from terminal, IDE or phone; the repo calls itself ToS-friendly, which is worth checking against each provider's terms before adopting.
A DeepSeek-native terminal coding agent engineered around prefix-cache stability, aimed at long-running sessions where cache misses, not model quality, drive the bill.
Builds a document index for reasoning-based retrieval without vector embeddings, an option when chunk-and-embed RAG loses the structure of long technical documents.
An AI pentester that reads your source, derives attack vectors and executes real exploits against web apps and APIs to prove a vulnerability before it ships; run it only against systems you own.