<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>TerminalBlog</title>
  <subtitle>Independent coverage of the AI coding agent ecosystem — security bugs, real adoption data, comparisons, and what actually ships. Claude Code, Cursor, Hermes, Codex, OpenCode, and more.</subtitle>
  <link href="https://terminalblog.com/rss.xml" rel="self" />
  <link href="https://terminalblog.com/" />
  <updated>2026-08-28T00:00:00.000Z</updated>
  <id>https://terminalblog.com/</id>
  <author>
    <name>Anshad</name>
  </author>
  <icon>https://terminalblog.com/favicon.svg</icon>
  
    <entry>
      <id>https://terminalblog.com/blog/ai-agents-atrophying-developer-brains-hn-threads/</id>
      <title><![CDATA[AI Coding Agents Are Atrophying Developer Brains — What 200+ HN Comments Reveal]]></title>
      <link href="https://terminalblog.com/blog/ai-agents-atrophying-developer-brains-hn-threads/" />
      <published>2026-08-28T00:00:00.000Z</published>
      <updated>2026-08-28T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Three explosive Hacker News threads expose the hidden cost of AI coding: skill atrophy, encoding yourself into obsolescence, and the control problem nobody has solved. Raw developer confessions, not marketing.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding-agents" />
      <category term="claude-code" />
      <category term="developer-experience" />
      <category term="industry" />
      <category term="skill-atrophy" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-claude-code-security-guidance-leaks-oauth-tokens/</id>
      <title><![CDATA[Beware: Claude Code's Security-Guidance Plugin Leaks Your OAuth Tokens Into the Transcript]]></title>
      <link href="https://terminalblog.com/blog/beware-claude-code-security-guidance-leaks-oauth-tokens/" />
      <published>2026-08-28T00:00:00.000Z</published>
      <updated>2026-08-28T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[The official security-guidance plugin reads ~/.claude/.credentials.json and echoes full access/refresh tokens into stop-time review findings — which get injected into your conversation transcript. A credential detector that creates credential leaks.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="claude-code" />
      <category term="credentials" />
      <category term="oauth" />
      <category term="plugin" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-ai-coding-agents-hn-discussion/</id>
      <title><![CDATA[What Developers Really Think About AI Coding Agents — Raw Truth From 200+ HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-ai-coding-agents-hn-discussion/" />
      <published>2026-08-28T00:00:00.000Z</published>
      <updated>2026-08-28T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[A raw look at the psychological toll, workflow changes, and honest fears developers shared on Hacker News about living with AI coding agents daily.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="ai-coding-agents" />
      <category term="developer-experience" />
      <category term="mental-health" />
      <category term="hacker-news" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-ai-coding-expertise-collapse-hn/</id>
      <title><![CDATA[What Developers Actually Think About AI Coding Expertise Collapse — From 500+ HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-ai-coding-expertise-collapse-hn/" />
      <published>2026-08-25T00:00:00.000Z</published>
      <updated>2026-08-25T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hacker News erupted with 520 comments on whether AI coding agents are destroying developer expertise. Here's what experienced engineers really think — from the calculator analogy to the junior pipeline crisis.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-agents" />
      <category term="industry" />
      <category term="career" />
      <category term="beware" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-cline-kanban-websocket-rce/</id>
      <title><![CDATA[Beware: Cline Kanban WebSocket Hijack Lets Any Website Steal Your Code & Run Commands (CVE-2026-44211)]]></title>
      <link href="https://terminalblog.com/blog/beware-cline-kanban-websocket-rce/" />
      <published>2026-08-24T00:00:00.000Z</published>
      <updated>2026-08-24T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Critical vulnerability in Cline's kanban server exposes workspace paths, git branches, and AI chat to any website you visit — and lets attackers hijack your AI agent to run arbitrary shell commands. No patch available yet.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="cline" />
      <category term="rce" />
      <category term="vulnerability" />
      <category term="websocket" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/coding-agent-weekly-2026-08-24/</id>
      <title><![CDATA[Coding Agent Weekly — 2026-08-24]]></title>
      <link href="https://terminalblog.com/blog/coding-agent-weekly-2026-08-24/" />
      <published>2026-08-24T00:00:00.000Z</published>
      <updated>2026-08-24T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[8 high-signal links · security, pricing, adoption]]></summary>
      <author><name>Anshad</name></author>
      <category term="newsletter" />
      <category term="roundup" />
      <category term="coding-agents" />
      <category term="weekly" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/openai-gpt-5-6-pricing-crash-changes-agent-economics/</id>
      <title><![CDATA[OpenAI Just Slashed GPT-5.6 Prices 80% — Coding Agents Got Way Cheaper]]></title>
      <link href="https://terminalblog.com/blog/openai-gpt-5-6-pricing-crash-changes-agent-economics/" />
      <published>2026-08-23T10:00:00.000Z</published>
      <updated>2026-08-23T10:00:00.000Z</updated>
      <summary type="html"><![CDATA[GPT-5.6 Luna dropped 80%, Terra 20%, and now Sol gets 2.5x faster Fast mode. The math for running AI coding agents at scale just fundamentally changed.]]></summary>
      <author><name>Anshad</name></author>
      <category term="news" />
      <category term="pricing" />
      <category term="gpt-5.6" />
      <category term="coding-ai" />
      <category term="openai" />
      <category term="codex" />
      <category term="cursor" />
      <category term="agent-economics" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-allowlist-bug-security-boundaries/</id>
      <title><![CDATA[Hermes Agent's Allowlist Bug: When Security Boundaries Disagree]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-allowlist-bug-security-boundaries/" />
      <published>2026-08-23T00:00:00.000Z</published>
      <updated>2026-08-23T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[A subtle inconsistency in Hermes Agent's command approval system reveals how hard it is to get security boundaries right in AI agents — and why consistency matters more than strictness.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes-agent" />
      <category term="security" />
      <category term="ai-agents" />
      <category term="debugging" />
      <category term="approval-system" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-codex-vs-claude-hn-2026/</id>
      <title><![CDATA[What Developers Actually Think About Codex vs Claude — From 221 HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-codex-vs-claude-hn-2026/" />
      <published>2026-08-23T00:00:00.000Z</published>
      <updated>2026-08-23T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[A week-long comparison sparked 221 comments on Hacker News. Here's what developers actually think about speed, verbosity, model quality, and workflow differences between OpenAI Codex and Anthropic Claude Code.]]></summary>
      <author><name>Anshad</name></author>
      <category term="comparison" />
      <category term="coding-agents" />
      <category term="claude-code" />
      <category term="codex" />
      <category term="openai" />
      <category term="anthropic" />
      <category term="workflow" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/cursor-spacex-acquisition-ai-coding-agent-war/</id>
      <title><![CDATA[Cursor Just Got Acquired by SpaceX — The AI Coding Agent War Entered a New Era]]></title>
      <link href="https://terminalblog.com/blog/cursor-spacex-acquisition-ai-coding-agent-war/" />
      <published>2026-08-22T00:00:00.000Z</published>
      <updated>2026-08-22T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Elon Musk's SpaceX acquired Cursor. With access to the world's largest GPU fleet and Grok models, the economics of AI coding agents just fundamentally shifted. Here's what it means for your workflow.]]></summary>
      <author><name>Anshad</name></author>
      <category term="cursor" />
      <category term="spacex" />
      <category term="ai-coding-agents" />
      <category term="industry" />
      <category term="grok" />
      <category term="acquisition" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-zip-update-silent-data-loss/</id>
      <title><![CDATA[Hermes Agent's ZIP Update Fallback Silently Destroys Your Local Patches — Windows Users, Check Your Repo]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-zip-update-silent-data-loss/" />
      <published>2026-08-22T00:00:00.000Z</published>
      <updated>2026-08-22T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[On Windows, when git file I/O breaks, hermes update falls back to a ZIP extraction path that overwrites uncommitted changes without warning. Here's how to check if you're affected and what the fix does.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes-agent" />
      <category term="bug" />
      <category term="windows" />
      <category term="data-loss" />
      <category term="update" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-ai-agents-hn-200-comments/</id>
      <title><![CDATA[What Developers Actually Think About AI Coding Agents — From 200+ HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-ai-agents-hn-200-comments/" />
      <published>2026-08-22T00:00:00.000Z</published>
      <updated>2026-08-22T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[A deep dive into the Huzzah Show HN thread where 200+ developers debated AI coding exhaustion, complexity ceilings, and whether pseudocode is the missing abstraction layer.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding" />
      <category term="developer-experience" />
      <category term="hacker-news" />
      <category term="workflow" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-opencode-context-integrity-pruning-injection/</id>
      <title><![CDATA[Beware: OpenCode's Context Management Silently Deletes Your Constraints and Injects Unauthorized Actions]]></title>
      <link href="https://terminalblog.com/blog/beware-opencode-context-integrity-pruning-injection/" />
      <published>2026-08-21T14:00:00.000Z</published>
      <updated>2026-08-21T14:00:00.000Z</updated>
      <summary type="html"><![CDATA[Two critical security flaws in OpenCode's compaction and pruning system: one deletes your permission denials and safety constraints from context, the other makes the model execute SSH connections and other actions from auto-generated summaries — all without your knowledge.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="opencode" />
      <category term="context-integrity" />
      <category term="compaction" />
      <category term="pruning" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/google-antigravity-killed-gemini-cli-terminal-ai-war/</id>
      <title><![CDATA[Google Just Killed Gemini CLI — Antigravity 2.0 Is the New Terminal King]]></title>
      <link href="https://terminalblog.com/blog/google-antigravity-killed-gemini-cli-terminal-ai-war/" />
      <published>2026-08-20T00:00:00.000Z</published>
      <updated>2026-08-20T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Google sunset Gemini CLI on June 18. Antigravity 2.0 and its Go-built CLI replace it with multi-agent orchestration, async workflows, and a unified harness. Here's what changed and how to migrate.]]></summary>
      <author><name>Anshad</name></author>
      <category term="google" />
      <category term="antigravity" />
      <category term="gemini-cli" />
      <category term="terminal" />
      <category term="ai-agents" />
      <category term="migration" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-coding-agents-hn/</id>
      <title><![CDATA[Anthropic's Lock-In Play and Opus 5's 'Agent Speak' — What 300+ HN Developers Revealed This Week]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-coding-agents-hn/" />
      <published>2026-08-20T00:00:00.000Z</published>
      <updated>2026-08-20T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Two explosive Hacker News threads (153 + 164 comments) expose the real friction: Anthropic refusing open standard AGENTS.md in favor of proprietary CLAUDE.md, and Opus 5's verbose 'agent speak' polluting codebases. Here's what developers are actually doing about it.]]></summary>
      <author><name>Anshad</name></author>
      <category term="coding-agents" />
      <category term="claude-code" />
      <category term="anthropic" />
      <category term="industry" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-v2-1-235-spellcheck-performance-fixes/</id>
      <title><![CDATA[Claude Code Just Got Spellcheck — And Fixed 15 Things You've Been Complaining About]]></title>
      <link href="https://terminalblog.com/blog/claude-code-v2-1-235-spellcheck-performance-fixes/" />
      <published>2026-08-19T00:00:00.000Z</published>
      <updated>2026-08-19T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[v2.1.235 adds real-time spellcheck, cuts memory usage in cloud sessions, fixes nested markdown lists, and squashes a dozen paper-cut bugs. Here's what matters.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="release" />
      <category term="coding-agents" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/jetbrains-ai-coding-agent-adoption-survey-2026/</id>
      <title><![CDATA[The AI Coding Agent Race Just Flipped — Claude Code Is Now Twice as Popular as Copilot]]></title>
      <link href="https://terminalblog.com/blog/jetbrains-ai-coding-agent-adoption-survey-2026/" />
      <published>2026-08-19T00:00:00.000Z</published>
      <updated>2026-08-19T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[JetBrains surveyed 15,000 developers and found Claude Code at 39% adoption, Codex up 5x, and GitHub Copilot losing its lead. Here's what the numbers actually mean.]]></summary>
      <author><name>Anshad</name></author>
      <category term="jetbrains" />
      <category term="claude-code" />
      <category term="codex" />
      <category term="copilot" />
      <category term="adoption" />
      <category term="coding-agents" />
      <category term="research" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-agentjacking-sentry-mcp-hijacks-claude-code-cursor-codex/</id>
      <title><![CDATA[Agentjacking: Fake Sentry Bug Hijacks 100+ AI Coding Agents]]></title>
      <link href="https://terminalblog.com/blog/beware-agentjacking-sentry-mcp-hijacks-claude-code-cursor-codex/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Tenet Security proved that a single injected Sentry error can make Claude Code, Cursor, and Codex execute attacker-controlled code on your machine. Here's the attack chain and how to defend against it.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="claude-code" />
      <category term="cursor" />
      <category term="codex" />
      <category term="mcp" />
      <category term="sentry" />
      <category term="agentjacking" />
      <category term="rce" />
      <category term="supply-chain" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-cursor-duneslide-rce-cve-2026-50548-50549/</id>
      <title><![CDATA[Beware: Cursor DuneSlide — Two Critical RCE Vulnerabilities (CVE-2026-50548, CVE-2026-50549) Let Attackers Escape the Sandbox via Zero-Click Prompt Injection]]></title>
      <link href="https://terminalblog.com/blog/beware-cursor-duneslide-rce-cve-2026-50548-50549/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt injection to escape the sandbox and achieve full system compromise. Fixed in Cursor 3.0 — upgrade immediately.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="cursor" />
      <category term="rce" />
      <category term="prompt-injection" />
      <category term="sandbox-escape" />
      <category term="cve-2026-50548" />
      <category term="cve-2026-50549" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-just-patched-credential-leak-cross-session-messaging/</id>
      <title><![CDATA[Claude Code Just Patched Its Credential Leak — And Made Sessions Talk Across Machines]]></title>
      <link href="https://terminalblog.com/blog/claude-code-just-patched-credential-leak-cross-session-messaging/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Claude Code v2.1.234 hardens Windows against NTLM credential theft, adds cross-session messaging so agents can coordinate across machines, and brings GitLab MR visibility to your terminal. Here's what matters for your daily workflow.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="security" />
      <category term="beware" />
      <category term="release" />
      <category term="cross-session" />
      <category term="windows" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-v2-1-234-ntlm-leak-fixed-50-fixes/</id>
      <title><![CDATA[Claude Code Just Patched the NTLM Credential Leak — And 50 Other Fixes You'll Actually Feel]]></title>
      <link href="https://terminalblog.com/blog/claude-code-v2-1-234-ntlm-leak-fixed-50-fixes/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[v2.1.234 is a security-first drop: Windows NT-namespace hardening, GitLab MR badges, auto-resume at usage limits, and a transcript that finally renders your markdown.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="release" />
      <category term="security" />
      <category term="coding-agents" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/cursor-origin-code-hosting-agents-every-repo/</id>
      <title><![CDATA[Cursor Just Got Acquired by SpaceX — And Launched Origin, Its Agent-Native Code Host]]></title>
      <link href="https://terminalblog.com/blog/cursor-origin-code-hosting-agents-every-repo/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-20T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Cursor was acquired by SpaceX on August 14, launched Origin (agent-native Git hosting) on August 17, and dropped major cloud agent upgrades on August 19. Here's why this week changes everything for AI coding.]]></summary>
      <author><name>Anshad</name></author>
      <category term="cursor" />
      <category term="origin" />
      <category term="code-hosting" />
      <category term="agents" />
      <category term="github" />
      <category term="spacex" />
      <category term="acquisition" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-v0-20-4-patch-74-prs-glass-ui-bot-mode/</id>
      <title><![CDATA[Hermes Agent Just Dropped v0.20.4 — 74 PRs in 48 Hours, Glass UI, and Bot Mode That Actually Works]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-v0-20-4-patch-74-prs-glass-ui-bot-mode/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[The latest Hermes patch rolls up 146 commits across 265 files. Matte glass desktop, tabbed sessions sidebar, NVIDIA skill scanning, and cron fixes you'll actually notice.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes-agent" />
      <category term="release" />
      <category term="coding-agents" />
      <category term="open-source" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/openhands-1-14-git-sync-free-kimi-breakthrough/</id>
      <title><![CDATA[OpenHands Just Added the Git Sync Button Everyone Begged For — And Made Kimi K3 Free by Default]]></title>
      <link href="https://terminalblog.com/blog/openhands-1-14-git-sync-free-kimi-breakthrough/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[OpenHands 1.14 drops with a Git Sync automation page, free Kimi K3 as the default Canvas model, LLM pre-flight validation, and structured error handling. Here's why this matters for your workflow.]]></summary>
      <author><name>Anshad</name></author>
      <category term="openhands" />
      <category term="coding-agents" />
      <category term="release" />
      <category term="git" />
      <category term="free-models" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-ai-coding-without-vibes-hn/</id>
      <title><![CDATA[What Developers Think About AI Coding Without the Vibes — From 55 HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-ai-coding-without-vibes-hn/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hacker News thread on 'AI Coding Without the Vibes' reveals a split: developers who treat AI as a reviewer and understanding tool vs those who let it generate everything. Here's what 55 developers actually think.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding" />
      <category term="developer-opinion" />
      <category term="hacker-news" />
      <category term="craft-coding" />
      <category term="vibe-coding" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/zed-v1-16-pre-gemini-flash-git-panel-mermaid/</id>
      <title><![CDATA[Zed Just Added Gemini 3.6 Flash — And Made Git Panel Actually Usable]]></title>
      <link href="https://terminalblog.com/blog/zed-v1-16-pre-gemini-flash-git-panel-mermaid/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[v1.16.0-pre brings Google's latest model, collapsible Git sections, optional stash messages, Mermaid zoom, and a terminal panel that stays closed until you want it.]]></summary>
      <author><name>Anshad</name></author>
      <category term="zed" />
      <category term="release" />
      <category term="coding-agents" />
      <category term="editor" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-claude-code-trust-dialog-bypass-cve-2026-33068/</id>
      <title><![CDATA[Claude Code Silently Skipped Your Security Prompt — Malicious Repos Could Disable It]]></title>
      <link href="https://terminalblog.com/blog/beware-claude-code-trust-dialog-bypass-cve-2026-33068/" />
      <published>2026-08-17T18:00:00.000Z</published>
      <updated>2026-08-17T18:00:00.000Z</updated>
      <summary type="html"><![CDATA[CVE-2026-33068 let attackers bypass Claude Code's workspace trust dialog by committing a malicious .claude/settings.json. Fixed in v2.1.53. Here's what happened and how to stay safe.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="claude-code" />
      <category term="security" />
      <category term="cve" />
      <category term="vulnerability" />
      <category term="workspace-trust" />
      <category term="supply-chain" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/github-copilot-cli-1-0-80-ahp-shared-sessions/</id>
      <title><![CDATA[GitHub Copilot CLI Just Made Shared Terminal Sessions Real — Here's Why It Changes Everything]]></title>
      <link href="https://terminalblog.com/blog/github-copilot-cli-1-0-80-ahp-shared-sessions/" />
      <published>2026-08-17T10:00:00.000Z</published>
      <updated>2026-08-17T10:00:00.000Z</updated>
      <summary type="html"><![CDATA[Copilot CLI 1.0.80 introduces Agent Host Protocol (AHP): multiple terminals attaching to one session, cloud/Codespace sessions, and MCP server fixes. The terminal agent just became collaborative infrastructure.]]></summary>
      <author><name>Anshad</name></author>
      <category term="copilot-cli" />
      <category term="github" />
      <category term="release" />
      <category term="ahp" />
      <category term="terminal" />
      <category term="beginner" />
      <category term="guide" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/coding-agent-weekly-2026-08-17/</id>
      <title><![CDATA[Coding Agent Weekly — 2026-08-17]]></title>
      <link href="https://terminalblog.com/blog/coding-agent-weekly-2026-08-17/" />
      <published>2026-08-17T00:00:00.000Z</published>
      <updated>2026-08-17T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[8 high-signal links · security, pricing, adoption]]></summary>
      <author><name>Anshad</name></author>
      <category term="newsletter" />
      <category term="roundup" />
      <category term="coding-agents" />
      <category term="weekly" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-v0-20-2-patch-release-desktop-gateway-cli/</id>
      <title><![CDATA[Hermes Agent v0.20.2 Just Landed — 397 Fixes in 3 Days, Desktop & Gateway Get Major Polish]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-v0-20-2-patch-release-desktop-gateway-cli/" />
      <published>2026-08-17T00:00:00.000Z</published>
      <updated>2026-08-17T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hermes v0.20.2 rolls up 397 PRs since v0.20.1 into a rapid patch release. Multi-gateway connections, profile-scoped refreshes, MCP health checks, Windows update probes, Kitty keyboard protocol, persisted model routes, and installer hardening. Here's what actually changed.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes" />
      <category term="release" />
      <category term="patch" />
      <category term="desktop" />
      <category term="gateway" />
      <category term="cli" />
      <category term="open-source" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-v0-20-3-patch-mcp2-bot-mode-commandcode/</id>
      <title><![CDATA[Hermes Agent Just Dropped v0.20.3 — MCP 2.x, Bot Mode, and Self-Healing Cron in One Patch]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-v0-20-3-patch-mcp2-bot-mode-commandcode/" />
      <published>2026-08-17T00:00:00.000Z</published>
      <updated>2026-08-17T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hermes v0.20.3 landed hours after v0.20.2 with 125 PRs: MCP 2.x SDK migration, bundled Bot Mode plugin with teammate protocol, CommandCode provider, Python runtime hardening, Cua Driver 0.20 for computer use, and cron scheduler self-heal. Here's what matters.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes" />
      <category term="release" />
      <category term="patch" />
      <category term="mcp" />
      <category term="bot-mode" />
      <category term="computer-use" />
      <category term="cron" />
      <category term="open-source" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-cursor-cli-worktree-pre-trust-rce/</id>
      <title><![CDATA[Beware: Cursor CLI Ran Your Attacker's Code Before You Clicked 'Trust' — Pre-Trust RCE in Worktree Setup]]></title>
      <link href="https://terminalblog.com/blog/beware-cursor-cli-worktree-pre-trust-rce/" />
      <published>2026-08-16T12:00:00.000Z</published>
      <updated>2026-08-16T12:00:00.000Z</updated>
      <summary type="html"><![CDATA[Cursor's CLI agent executed arbitrary commands from a cloned repository's .cursor/worktrees.json BEFORE the workspace trust prompt appeared — even with --sandbox enabled. Fixed in 2026.07.23 but closed as 'Informative' with no security advisory. Here's how to check if you're affected.]]></summary>
      <author><name>Anshad</name></author>
      <category term="security" />
      <category term="beware" />
      <category term="cursor" />
      <category term="rce" />
      <category term="ai-coding-agents" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-v0-20-1-patch-release-656-fixes/</id>
      <title><![CDATA[Hermes Agent v0.20.1 Just Dropped — 656 Fixes, One Stable Release]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-v0-20-1-patch-release-656-fixes/" />
      <published>2026-08-16T00:00:00.000Z</published>
      <updated>2026-08-16T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hermes v0.20.1 rolls up 1,444 commits and 656 PRs since v0.20.0 into a stable patch. Desktop stability, gateway fixes, installer improvements, and provider catalog updates. Here's what the rollup actually fixes.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes" />
      <category term="release" />
      <category term="patch" />
      <category term="stability" />
      <category term="open-source" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/openclaw-v2026-8-1-beta2-secret-egress-gpt5-macos-profiles/</id>
      <title><![CDATA[OpenClaw Just Made Your Secrets Impossible to Leak — And Added GPT-5.6 Support]]></title>
      <link href="https://terminalblog.com/blog/openclaw-v2026-8-1-beta2-secret-egress-gpt5-macos-profiles/" />
      <published>2026-08-16T00:00:00.000Z</published>
      <updated>2026-08-16T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[OpenClaw 2026.8.1-beta.2 drops secret egress host binding (fail-closed before plaintext leaves), GPT-5.6 Ultra runtime switching, macOS app profiles for true isolation, SQLite snapshots, and 15+ other features. Here's why this beta matters.]]></summary>
      <author><name>Anshad</name></author>
      <category term="openclaw" />
      <category term="release" />
      <category term="security" />
      <category term="gpt-5" />
      <category term="macos" />
      <category term="beta" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/pi-v0-84-2-fullscreen-transcript-search-configurable-tools/</id>
      <title><![CDATA[Pi Just Got Fullscreen Transcript Search — And It Changes How You Find Things]]></title>
      <link href="https://terminalblog.com/blog/pi-v0-84-2-fullscreen-transcript-search-configurable-tools/" />
      <published>2026-08-16T00:00:00.000Z</published>
      <updated>2026-08-16T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Pi v0.84.2 adds fullscreen transcript search (Ctrl+Shift+F), configurable default tools, experimental strict JSON-schema tool sampling, per-run themes, and 25+ fixes. The fullscreen UX finally feels polished.]]></summary>
      <author><name>Anshad</name></author>
      <category term="pi" />
      <category term="release" />
      <category term="tui" />
      <category term="fullscreen" />
      <category term="search" />
      <category term="coding-agent" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/zed-delta-multiplayer-coding-agents-private-beta/</id>
      <title><![CDATA[Zed Just Launched Delta — The First Multiplayer IDE Where Agents Are First-Class Teammates]]></title>
      <link href="https://terminalblog.com/blog/zed-delta-multiplayer-coding-agents-private-beta/" />
      <published>2026-08-16T00:00:00.000Z</published>
      <updated>2026-08-16T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Zed's new Delta platform lets developers and AI agents collaborate in real-time threads with shared code, persistent context, and browser-based access. Private beta invites went out August 12, 2026.]]></summary>
      <author><name>Anshad</name></author>
      <category term="zed" />
      <category term="delta" />
      <category term="release" />
      <category term="ai" />
      <category term="multiplayer" />
      <category term="collaboration" />
      <category term="agents" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/zed-just-got-gpt-5-6-luna-and-self-hosted-ai-models/</id>
      <title><![CDATA[Zed Just Got GPT-5.6 Luna Support — And Self-Hosted AI Models Too]]></title>
      <link href="https://terminalblog.com/blog/zed-just-got-gpt-5-6-luna-and-self-hosted-ai-models/" />
      <published>2026-08-16T00:00:00.000Z</published>
      <updated>2026-08-17T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Zed v1.15.0-pre dropped with GPT-5.6 Luna for ChatGPT subscribers, self-hosted Sweep edit predictions, and a git.diff_base setting that changes how you review changes. v1.16.0-pre adds Gemini 3.6 Flash, collapsible Git groups, and GPT-5.6 Sol as default. Here's what matters for developers.]]></summary>
      <author><name>Anshad</name></author>
      <category term="zed" />
      <category term="release" />
      <category term="ai" />
      <category term="gpt-5-6" />
      <category term="gemini" />
      <category term="self-hosted" />
      <category term="editor" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/cursor-cloud-agents-3x-faster-builds/</id>
      <title><![CDATA[Cursor Just Made Cloud Agents 3x Faster — Here's Why It Changes Everything]]></title>
      <link href="https://terminalblog.com/blog/cursor-cloud-agents-3x-faster-builds/" />
      <published>2026-08-15T14:00:00.000Z</published>
      <updated>2026-08-15T14:00:00.000Z</updated>
      <summary type="html"><![CDATA[Cursor's August 13 release introduces 'Builds' — pre-warmed development environments that eliminate the painful setup wait every time you start a cloud agent. Agents now boot in seconds, not minutes. Beginner-friendly breakdown.]]></summary>
      <author><name>Anshad</name></author>
      <category term="cursor" />
      <category term="cloud-agents" />
      <category term="release" />
      <category term="builds" />
      <category term="ai-agent" />
      <category term="coding-agent" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/opencode-v1-18-18-reliability-mcp-desktop-overhaul/</id>
      <title><![CDATA[Opencode Just Became the Open-Source Coding Agent You Can Actually Trust]]></title>
      <link href="https://terminalblog.com/blog/opencode-v1-18-18-reliability-mcp-desktop-overhaul/" />
      <published>2026-08-15T14:00:00.000Z</published>
      <updated>2026-08-15T14:00:00.000Z</updated>
      <summary type="html"><![CDATA[v1.18.18 fixes the MCP reconnect loops, provider model routing, desktop freezes, and session chaos that made you hesitate. The 160K-star agent is finally reliable enough for daily work.]]></summary>
      <author><name>Anshad</name></author>
      <category term="opencode" />
      <category term="release" />
      <category term="open-source" />
      <category term="mcp" />
      <category term="desktop" />
      <category term="beginner" />
      <category term="guide" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/pi-coding-agent-just-got-massive-upgrade-fullscreen-breaking-changes/</id>
      <title><![CDATA[Pi Coding Agent Just Got a Massive Upgrade — Fullscreen TUI, Breaking Session Model, and Transcript Search]]></title>
      <link href="https://terminalblog.com/blog/pi-coding-agent-just-got-massive-upgrade-fullscreen-breaking-changes/" />
      <published>2026-08-15T09:00:00.000Z</published>
      <updated>2026-08-15T09:00:00.000Z</updated>
      <summary type="html"><![CDATA[Pi 0.84.0 and 0.84.2 bring fullscreen terminal mode, a lane-based session architecture (breaking changes), per-directory context overrides, configurable default tools, and fullscreen transcript search. Plain-English breakdown for beginners.]]></summary>
      <author><name>Anshad</name></author>
      <category term="pi" />
      <category term="coding-agent" />
      <category term="release" />
      <category term="tui" />
      <category term="breaking-changes" />
      <category term="session-model" />
      <category term="ai-agent" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/ai-agents-keep-deleting-production-databases-pattern/</id>
      <title><![CDATA[AI Agents Keep Deleting Production Databases — The Pattern Nobody's Fixing]]></title>
      <link href="https://terminalblog.com/blog/ai-agents-keep-deleting-production-databases-pattern/" />
      <published>2026-08-15T00:00:00.000Z</published>
      <updated>2026-08-15T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Nine documented incidents. Wiped drives. Dropped production tables. A live AWS service down for 13 hours. The root cause isn't hallucination — it's that every safety layer is advisory, not enforceable. Here's what the Adversa AI report reveals and the hard boundaries you actually need.]]></summary>
      <author><name>Anshad</name></author>
      <category term="security" />
      <category term="beware" />
      <category term="claude-code" />
      <category term="cursor" />
      <category term="replit" />
      <category term="kiro" />
      <category term="gemini-cli" />
      <category term="antigravity" />
      <category term="incident-response" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-v2-1-233-security-fix-windows-ntlm-leak/</id>
      <title><![CDATA[Claude Code Just Patched a Nasty Windows Credential Leak — Here's Why It Matters]]></title>
      <link href="https://terminalblog.com/blog/claude-code-v2-1-233-security-fix-windows-ntlm-leak/" />
      <published>2026-08-15T00:00:00.000Z</published>
      <updated>2026-08-15T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[v2.1.233 fixes an NTLM credential leak on Windows, adds memory limits for runaway builds, and resolves MCP connection storms. The security fix alone is worth the update.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="security" />
      <category term="release" />
      <category term="windows" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/cline-v4-1-10-web-search-lands/</id>
      <title><![CDATA[Cline Just Learned to Search the Web — And It Changes How You Code]]></title>
      <link href="https://terminalblog.com/blog/cline-v4-1-10-web-search-lands/" />
      <published>2026-08-15T00:00:00.000Z</published>
      <updated>2026-08-15T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Cline v4.1.10 adds web search during tasks. Your AI coder can now look up docs, APIs, and solutions in real-time without leaving the terminal.]]></summary>
      <author><name>Anshad</name></author>
      <category term="cline" />
      <category term="release" />
      <category term="ai-coding" />
      <category term="web-search" />
      <category term="productivity" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/kilocode-v7-4-22-clickable-refs-agent-manager-pr-actions-aws-gcp-auth/</id>
      <title><![CDATA[Kilo Code v7.4.22 Makes File References Clickable, Adds Agent Manager PR Actions & AWS/GCP Auth]]></title>
      <link href="https://terminalblog.com/blog/kilocode-v7-4-22-clickable-refs-agent-manager-pr-actions-aws-gcp-auth/" />
      <published>2026-08-15T00:00:00.000Z</published>
      <updated>2026-08-15T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Kilo Code v7.4.22 dropped August 13 with clickable inline file references in agent responses, Agent Manager PR comment actions (resolve/unresolve, jump to comments), structured AWS/GCP credentials support, and subagent permission fixes.]]></summary>
      <author><name>Anshad</name></author>
      <category term="kilocode" />
      <category term="release" />
      <category term="agent-manager" />
      <category term="aws" />
      <category term="gcp" />
      <category term="subagents" />
      <category term="clickable-references" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/openclaw-2026-8-1-beta2-secret-egress-gpt56-macos-profiles/</id>
      <title><![CDATA[OpenClaw Just Dropped Secret Egress Host Binding — GPT-5.6 Ultra, macOS Profiles & SQLite Snapshots Land]]></title>
      <link href="https://terminalblog.com/blog/openclaw-2026-8-1-beta2-secret-egress-gpt56-macos-profiles/" />
      <published>2026-08-15T00:00:00.000Z</published>
      <updated>2026-08-15T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[OpenClaw 2026.8.1-beta.2 is live with secret egress host binding, GPT-5.6 Ultra support, macOS app profiles, SQLite backup snapshots, and plugin install provenance warnings. Here's what matters for operators.]]></summary>
      <author><name>Anshad</name></author>
      <category term="openclaw" />
      <category term="release" />
      <category term="security" />
      <category term="gpt-5-6" />
      <category term="macos" />
      <category term="sqlite" />
      <category term="plugins" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/openhands-v1-13-conversation-archive-markdown-artifacts-context-meter/</id>
      <title><![CDATA[OpenHands v1.13 Just Added Conversation Archive, Markdown Artifact Previews & a Context Window Meter]]></title>
      <link href="https://terminalblog.com/blog/openhands-v1-13-conversation-archive-markdown-artifacts-context-meter/" />
      <published>2026-08-15T00:00:00.000Z</published>
      <updated>2026-08-15T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[OpenHands v1.13.0 dropped August 13 with client-side conversation archiving, inline markdown artifact previews, a context window usage meter with manual compaction, and an issue readiness gate. Here's the beginner-friendly breakdown.]]></summary>
      <author><name>Anshad</name></author>
      <category term="openhands" />
      <category term="release" />
      <category term="conversation-archive" />
      <category term="context-window" />
      <category term="artifacts" />
      <category term="automation" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-glm53-chinese-models-hn/</id>
      <title><![CDATA[What Developers Think About GLM-5.3 and the Shift to Chinese Models — From 500+ HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-glm53-chinese-models-hn/" />
      <published>2026-08-15T00:00:00.000Z</published>
      <updated>2026-08-15T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hacker News developers discuss how Chinese models like GLM-5.3, Kimi K3, and DeepSeek are surpassing Anthropic and OpenAI for security research and coding — and why Anthropic's guardrails may be backfiring.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding" />
      <category term="models" />
      <category term="industry" />
      <category term="security" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-just-made-subagents-free-and-they-remember-everything/</id>
      <title><![CDATA[Claude Code Just Made Subagents Free — And They Remember Everything]]></title>
      <link href="https://terminalblog.com/blog/claude-code-just-made-subagents-free-and-they-remember-everything/" />
      <published>2026-08-14T14:00:00.000Z</published>
      <updated>2026-08-14T14:00:00.000Z</updated>
      <summary type="html"><![CDATA[v2.1.232 drops subagent forking by default, @ mentions to ping other sessions, GitLab support, and Fable 5 advisor access. Your agents can now inherit full context, talk to each other, and actually work together.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="release" />
      <category term="subagents" />
      <category term="cross-session" />
      <category term="gitlab" />
      <category term="beginner" />
      <category term="guide" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/goose-v1-46-unrolled-agent-loop-hooks-cost-tracking/</id>
      <title><![CDATA[Goose v1.46 Just Dropped the Biggest Feature Wave Since v1.40 — Here's What Actually Matters]]></title>
      <link href="https://terminalblog.com/blog/goose-v1-46-unrolled-agent-loop-hooks-cost-tracking/" />
      <published>2026-08-14T11:00:00.000Z</published>
      <updated>2026-08-14T11:00:00.000Z</updated>
      <summary type="html"><![CDATA[Goose v1.46 (Aug 12) unrolls the agent loop for speed, adds hooks with PreToolUse denial, streaming shell output, per-message cost tracking, slash commands (/goal, /status, /model), TUI diff viewer, and 20+ new providers. The Rust agent keeps pulling ahead.]]></summary>
      <author><name>Anshad</name></author>
      <category term="goose" />
      <category term="release" />
      <category term="v1.46" />
      <category term="hooks" />
      <category term="cost-tracking" />
      <category term="agent-loop" />
      <category term="coding-agent" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-gemini-cli-prompt-injection-steals-ci-secrets/</id>
      <title><![CDATA[Your GitHub Issue Just Stole Your CI Secrets — The Prompt Injection Attack Nobody Saw Coming]]></title>
      <link href="https://terminalblog.com/blog/claude-code-gemini-cli-prompt-injection-steals-ci-secrets/" />
      <published>2026-08-14T10:00:00.000Z</published>
      <updated>2026-08-14T10:00:00.000Z</updated>
      <summary type="html"><![CDATA[CVE-2026-54316, CVE-2026-12537, and the 'Comment and Control' pattern: How a malicious GitHub issue title or PR comment hijacks Claude Code, Gemini CLI, and GitHub Copilot to exfiltrate ANTHROPIC_API_KEY, GEMINI_API_KEY, and GITHUB_TOKEN from your Actions runners.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="claude-code" />
      <category term="gemini-cli" />
      <category term="github-copilot" />
      <category term="prompt-injection" />
      <category term="cve" />
      <category term="ci-cd" />
    </entry>
  
</feed>