ISSUE № 025 FRIDAY, AUGUST 28, 2026 7 MIN READ

The Daily Signal

BUILD WITH AI № 25 · DEV TOOLS

AI that matters, from the architect's desk. Curated and engineered by Saaket Varma, PhD — no hype, just signal.

LIVE DNA HELIX · DRAG TO ORBIT · CLICK TO PULSE
TODAY'S BRIEFING · 79S
Coding Agents Get Dashboards, Queues, And Cost Controls
▶ LISTEN — 79 SECONDS  ·  WATCH VIDEO ↗
LIVE TRANSCRIPT — words light up as they're spoken · click any word to jump

Today's stories expose four agent control surfaces: repo creation, browser consent, per-call OAuth scopes, and pre-execution task scope.

SEC.01 / THE LEAD

Cursor Cloud Agents Now Start Without a Repo

AGENT BEFORE REPO SHIPPED

HOW TO READ THIS Follow the top row left to right: a prompt with no repo starts the agent, which previews through browser port forwarding; the lower row shows the Origin repo made behind it, the save that keeps the scaffold, and the Vercel step needed to publish.

DRAG TO ORBIT · ARROWS TO ROTATE
Cursor Cloud Agents start from a prompt with no connected source control, work inside an Origin repo, preview through browser port forwarding, and need Vercel to publish.PROMPTNO REPO CONNECTEDCLOUD AGENTSTARTS AT ONCEBROWSER PREVIEWPORT FORWARDINGORIGIN REPOMADE IN BACKGROUNDSAVE THE REPOKEEPS THE SCAFFOLDPUBLISH LIVEVERCEL REQUIREDPREVIEW STAYS IN BROWSER · LIVE URL ONLY VIA VERCEL
LEGENDprompt with no repo connectedagent → origin repo → browser previewrepo created in background, saved to keep workpreview in browser; vercel required to publish
WHY IT MATTERS Save the scaffolded repo; Vercel is required to publish

Cursor, published by Anysphere, added a changelog entry on August 27 titled Start from scratch, without a repo. Cloud Agents no longer require a connected GitHub or other third-party source-control provider to get started: a user picks Start from scratch in the repo picker, prompts the agent, and Cursor creates an Origin repo in the background. It leads this edition because it removes the first setup step that separates a cloud agent from a prompt box, and because it is a shipped vendor release with a live changelog rather than a preview.

Once the build is to the user's liking, clicking Create repo saves the work into a Cursor Origin repo, with a custom or suggested name and private or internal visibility, and the result appears as a fully scaffolded repo under the Codebase tab. Cursor also port-forwards the agent's live environment straight to the browser, so the running result can be previewed there, including with tools like design mode. Connecting a Vercel account and hitting publish yields a live URL; a Vercel account is required for that step.

For anyone who has bounced off a cloud agent at the connect-GitHub prompt, this is the difference between trying an idea and provisioning for one. What differs from the earlier Cloud Agents flow, per the changelog, is the entry point: the repo, the preview and the publish step are now sequenced after the work rather than before it. The potential advantage is that Cursor keeps the whole loop from prompt to live URL inside its own hosting and repo layer, which could make Origin the default home for throwaway projects that later become real. The evidence is a single vendor changelog entry; there are no independent reports yet on how Origin repos fit an existing GitHub workflow, or what limits apply to the port-forwarded preview.

Origin repo created in background
SOURCE · CURSOR CHANGELOG
SEC.02 / WORTH YOUR TIME

Worth your time

01

Hermes Agent v0.20.6

CONSENT BEFORE BROWSING SHIPPED

HOW TO READ THIS The agent's browse request must pass the consent shield — approval opens real-profile browsing, denial ends it — while a separate opt-in lane routes secrets into the OS keychain for encryption.

DRAG TO ORBIT · ARROWS TO ROTATE
Hermes Agent must receive explicit approval before browsing with a real profile, and secrets can optionally be encrypted in the OS keychain.NOUS RESEARCH · HERMES AGENTSHIPPEDHERMES AGENTWANTS TO BROWSEREQUESTCONSENTGATEEXPLICIT APPROVALAPPROVEDREAL-PROFILEBROWSINGDENIEDNO BROWSER ACCESSSECRETSOPT-INOS KEYCHAINOPTIONALENCRYPTED
LEGENDhermes agent browse requestconsent gate, explicit approvalapproved vs denied branchreal-profile browsing; keychain-encrypted secrets
WHY IT MATTERS Consent for browsing; optional secret encryption

Nous Research tagged Hermes Agent version 0.20.6 as v2026.8.27 on August 27, a patch release that rolls up roughly 525 pull requests merged since 0.20.5 into a stable tag for Docker images, hosted deployments and fresh installs. Since 0.20.5, tagged on August 21, the window landed roughly 1,313 commits across roughly 1,557 files. It is here because the two additions that matter most for a self-hosted agent touching real accounts, consent-gated browsing and keychain-encrypted secrets, arrived in the same release.

Consent-gated real-profile browsing lets the agent use your default Chromium profile for local browsing, with a Windows close-with-approval flow, and the desktop Browser gets its own OS window. Stored secrets can now be encrypted through the OS keychain on an opt-in basis, which the notes say removes the per-launch macOS Keychain prompts. The remote MCP catalog grows by 50-plus live-verified vendor-hosted servers, Cloudflare, Grafana Cloud, Better Stack and Railway among them, alongside a managed SSH remote-update engine, a fleet profile rail, TTL caching for web_search and web_extract, and updaters that pause gateways over the control socket instead of tree-killing them.

An agent that browses as you, holds your tokens and updates itself is exactly the software that needs explicit gates, and this release adds the two that were missing. What differs from 0.20.5 is a list of shipped controls, not a measured security result; the maintainers say the full curated notes for the window ship with 0.21.0. The potential edge is breadth plus cadence, five releases since August 16 and a catalog that reaches many of the infrastructure vendors a developer already pays, if the live-verification claim holds over time. All of this is the project's own release notes; no external review of the consent gate or the keychain path exists yet, and the roughly 237 thousand stars shown at capture are a popularity signal, not a quality one.

02

GitHub MCP Server v1.11.0

OAUTH SCOPE CHECKED ON EVERY CALL SHIPPED

HOW TO READ THIS Read left to right: each agent call passes its own runtime scope check and reaches GitHub with only the single permission that call asked for.

DRAG TO ORBIT · ARROWS TO ROTATE
GitHub checks OAuth scope on each tool call at runtime, so every invocation receives only the permission it requests.GITHUB · OAUTH SCOPE PER TOOL CALLSHIPPEDAGENTCALL 1READ ISSUECALL 2CREATE ISSUECALL 3PUSH COMMITRUNTIME SCOPE CHECKONLY ISSUES: READONLY ISSUES: WRITEONLY REPO: PUSHGITHUB APIGRANTED: ISSUE READGRANTED: ISSUE WRITEGRANTED: PUSHUNREQUESTED SCOPES NEVER ISSUED · ACCESS BOUNDED PER CALL
LEGENDagent tool callsper-call request pathruntime scope checkonly the requested permission granted
WHY IT MATTERS Runtime checks limit each tool call's access

GitHub released version 1.11.0 of its MCP server on August 25 from the github/github-mcp-server repository, with per-call OAuth scope checks that request only the permissions each tool invocation needs, plus runtime checks where required. It follows 1.10.0 on August 19, which added confirmed repository deletion through form elicitation with protected multi-round-trip state, enforced HTTPS for GitHub Enterprise hosts, restricted bearer credentials to configured GitHub authorities and made invalid static --tools configuration fail closed. It is included because the most common agent-to-repo bridge is tightening its own authorization model, and the pattern is worth copying.

Rather than one broad grant at connect time, the server evaluates what a specific tool call needs and requests that, adding a runtime check when the scope alone cannot settle it. Browser clients gain CORS across the OAuth discovery routes and a configurable authorization-server URL through a new --authorization-server flag. The release also creates parent and sub-issues atomically, adds ETag conditional requests to the REST transport, described as better HTTP caching for STDIO, and moves the runtime to Go 1.27; a 1.10.1 patch on August 20 fixed an add_issue_comment schema regression in between.

For anyone wiring an agent to a repo that holds production secrets, per-call scoping narrows what a compromised agent session can reach. What is new relative to 1.10 is the granularity of the request, not a new authorization scheme; the complementary choice is that repository deletion now needs an explicit confirmation round trip. GitHub's potential advantage is that it owns both the OAuth authority and the most common agent target, so its defaults can become the reference other MCP servers are measured against. The release notes are the only source here; there is no independent audit of how the runtime checks behave against a misbehaving client, and the roughly 32.6 thousand stars at capture say nothing about which versions are actually deployed.

03

Kiro CLI 2.20.0

SPEC TASKS RUN FULL-SCREEN SHIPPED

HOW TO READ THIS Read left to right: the V3 spec's task list passes a scope choice (all tasks or one) before execution, then runs inside a full-screen view that reports each task's live progress, with scrollback optionally kept below.

DRAG TO ORBIT · ARROWS TO ROTATE
Kiro CLI runs a V3 spec's tasks in a full-screen view after a scope choice, showing real-time progress with optional scrollback preservation.KIRO CLI · SPEC TASK EXECUTIONSHIPPEDSPEC V3TASK ATASK BTASK CTASK DTASK LISTSCOPE CHOICEALL TASKSONE TASKBEFORE EXECUTIONRUNFULL-SCREEN TASK VIEWREAL-TIME PROGRESSTASK A · DONETASK B · RUNNINGTASK C · QUEUEDTASK D · QUEUEDUPDATES WHILE TASKS RUNSCROLLBACK PRESERVED · OPTIONAL
LEGENDv3 spec task listscope choice before executionfull-screen task viewlive progress, optional scrollback
WHY IT MATTERS Visible progress with optional scrollback preservation

Kiro shipped CLI 2.20.0 on August 26, giving V3 spec runs a dedicated full-screen task execution view with real-time progress and task scope selection, opened by running a spec with the /spec run command. It follows 2.19.0 on August 19, which added a stream idle watchdog and automatic retries, with patches 2.19.1 and 2.19.2 on August 21 and 25. It is here because the two releases together turn Kiro's spec-driven workflow into a supervised, self-recovering execution loop rather than a chat transcript.

In the full-screen view you follow progress as tasks run and choose the task scope before execution begins; a Preserve scrollback toggle keeps terminal history available through overflow and resize redraws. The 2.19.0 watchdog warns after 60 seconds of silence and cancels at 300, throttling, 5xx errors and connection drops are retried automatically with backoff, and streaming responses get a 60-minute timeout by default so long outputs are no longer cut off, all tunable through api.streamIdleSoftTimeout, api.streamIdleHardTimeout and api.timeout. Spec review gained mouse support, scroll to navigate and click to position the cursor with the m key toggling it, building on the 2.18.0 review screen that opens with Ctrl+X at a phase checkpoint.

Long agent runs die quietly on dropped streams far more often than on bad reasoning, so a watchdog with backoff is a reliability feature, not polish. What differs from prior Kiro releases is that scope selection now happens before anything executes, which puts the human decision at the front of the run instead of in a review afterwards. The potential edge is that a spec-first tool can bound what an agent touches by construction, an advantage worth watching against Cursor and Claude Code if teams actually keep their specs current. The evidence is Kiro's own changelog; nothing here measures how often the retries succeed or how the full-screen view holds up on a multi-hour run.

SEC.03 / REPO RADAR

Trending, not yet covered

✦ wshobson/agents ★ 0
GitHub Trending snapshot: Aug 27, 2026, 6:00 PM EDT

A plugin marketplace that packages agents and skills once and installs them across Claude Code, Codex, Cursor, OpenCode, GitHub Copilot and Antigravity, so a team's workflow does not have to be rebuilt per harness.

GitHub Trending snapshot: Aug 27, 2026, 6:00 PM EDT

Routes Claude Code, Codex, Pi, OpenCode and similar CLIs through free token pools from terminal, IDE or phone; the repo calls itself ToS-friendly, which is worth checking against each provider's terms before adopting.

GitHub Trending snapshot: Aug 13, 2026, 11:58 AM EDT

A DeepSeek-native terminal coding agent engineered around prefix-cache stability, aimed at long-running sessions where cache misses, not model quality, drive the bill.

GitHub Trending snapshot: Aug 1, 2026, 12:42 AM EDT

Builds a document index for reasoning-based retrieval without vector embeddings, an option when chunk-and-embed RAG loses the structure of long technical documents.

✦ KeygraphHQ/shannon ★ 0
GitHub Trending snapshot: Aug 18, 2026, 12:23 AM EDT

An AI pentester that reads your source, derives attack vectors and executes real exploits against web apps and APIs to prove a vulnerability before it ships; run it only against systems you own.

SEC.04 / CROSS-SIGNAL

From the other desks

Ben's Bites Who let the agents in? It's you, and it's getting easier — a fitting frame for a week in which the setup steps keep disappearing.

Latent Space AINews recaps Hot Chips — OpenAI's Jalapeño, Cerebras CS-5, Groq 3 LPX and Apple M6 — the silicon roadmap behind next year's token prices.

The Sequence Opinion #921 adds finance as a sixth layer to Jensen Huang's five-layer cake, arguing capital decides how quickly, and by whom, intelligence scales.