MaxKB's v2.10.5-lts fix for a CVSS 10.0 agent flaw repairs shell quoting but leaves the execute tool off the approval list. According to one developer's trace of the release tag, a prompt planted in ingested documents can still trigger shell commands with no human sign-off.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives30
- Confidence40
Anduril marketing chief Jeff Miller gave AI agents access to his bank details and email, then used them to clear six months of expense reports. The approval he keeps for himself covers what an agent sends or buys, so a team policy modelled on it still has to decide what the agent may read.
Reality
- Evidence35
- Adoption20
- Hype gap+35
- Incentives60
- Confidence40
A dev.to post says the 2026-07-28 specification dropped the initialize flow and Mcp-Session-Id, so MCP requests can land on any instance. The refund agent it walks through still breaks on the second pod.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives25
- Confidence40
Across 34 runs on three agent frameworks, a recorder proxy shows that what the dedup key names decides whether a retried publish executes once or twice, and that surviving a SIGKILL is a separate question about where state is kept.
Reality
- Evidence46
- Adoption
- Insufficient
- Hype gap+18
- Incentives36
- Confidence52
Part 4 of a dev.to enterprise AI series puts a person in front of the write and send connectors and leaves read paths alone, with the refusal enforced by the tool layer instead of a sentence in the prompt.
Reality
- Evidence38
- Adoption15
- Hype gap−8
- Incentives25
- Confidence50
An R0-R5 tiering in the open-source KeelBase server lets the declared level decide whether an agent's call executes, waits for a person, or is refused, and a tool that declares nothing has its writes held at confirmation.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+18
- Incentives70
- Confidence52
Part 14 of a dev.to series describes what its author calls "a support agent that can work out whether you're owed a refund, and cannot give you one", with the eligibility rules pinned to the JDK by a test.
Reality
- Evidence50
- Adoption4
- Hype gap−10
- Incentives28
- Confidence45
A dev.to walkthrough swaps the agent spinner for a typed state machine covering planning, approval, retry and blocked, and its reducer reads only the newest event, so the server has to name each state first.
Reality
- Evidence63
- Adoption
- Insufficient
- Hype gap+18
- Incentives22
- Confidence68
capbroker hands the agent a signed, expiring ticket and evaluates every call in deterministic code. In the second run the injected instruction stayed inside the granted scope, and a human at the terminal was what stopped it.
Reality
- Evidence45
- Adoption10
- Hype gap−12
- Incentives60
- Confidence45
His case rests on a refund workflow where anything over $100 needs human confirmation, a rule that stays an instruction while it lives in the prompt and becomes enforceable only when something inspects the tool call first.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence58
Anthropic's 37-skill beta reads only what a user's Salesforce permissions allow and writes back only after that seller approves each change. The approval is a default setting. Revenue teams now have to govern it.
Reality
- Evidence52
- Adoption34
- Hype gap+14
- Incentives78
- Confidence55
The journal chains each record's hash into the next, so a one-line edit to a refusal surfaced as a numbered record; anyone able to rerun the writer can still recompute the chain and pass the check.
Reality
- Evidence48
- Adoption15
- Hype gap+28
- Incentives80
- Confidence42
The Run SDK swaps eval's ambient authority for a worker-thread sandbox with narrow host functions and resumable interrupts. The replay semantics are the part to read twice.
Reality
- Evidence45
- Adoption22
- Hype gap+18
- Incentives78
- Confidence50
In MCP's Sampling flow the server composes the prompt and the client runs the completion on its own model. The includeContext default is "none", and the two wider values only work if the client declares a capability.
Reality
- Evidence50
- Adoption30
- Hype gap+8
- Incentives15
- Confidence55
A quality engineer writing on dev.to argues that ISO 13485, EU MDR and FDA guidance all assume an accountable human without listing the approvals an AI may not make, so each site has to write that list itself.
Reality
- Evidence28
- Adoption18
- Hype gap+12
- Incentives45
- Confidence40
Tenable's account of the control layer around Hexa AI lists what broke during development, including an agent that did not know who was asking, a model that denied tags it could not find, and queries that died past 5,000 assets.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+18
- Incentives82
- Confidence52
The write-up names three ways attacker-controlled text can reshape what an approval prompt shows, and cites one Checkmarx demonstration against Claude Code. It carries no measure of how often a doctored dialog actually fools a human.
Publishers:owasp.org
Reality
- Evidence52
- Adoption20
- Hype gap+15
- Incentives38
- Confidence60
Hossein Hezami's ladder runs observe to destroy and gives sensitive reads a class of their own. The interesting part is the TypeScript, where risk arrives as a field on the request and someone other than the model has to set it.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+16
- Incentives22
- Confidence44
Max Brin's authorization layer runs alongside AI agents for several hundred personal users and at least four organizations. The pattern worth noting is enforcement at the outbound action rather than inside the model.
Reality
- Evidence22
- Adoption16
- Hype gap+38
- Incentives76
- Confidence52
A dev.to design note inserts code gates and a human approval between the model and the tool, which is the right shape, though a policy layer that reads a severity field the model itself wrote has not moved the authority anywhere.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+22
- Incentives20
- Confidence45
Earlier coverage
- Let the agent propose, not commit: the envelope that has to arrive before a write
Build · August 24, 2026 · 1 publisher
- Prompt injection has no parameterized query, so stop shopping for a sterner system prompt
Build · August 23, 2026 · 1 publisher
- One state machine or two: the transaction fork hiding inside your MCP server
Build · August 23, 2026 · 1 publisher
- A self-healing scraper that must prove its repair against twelve records that cannot move
Build · August 22, 2026 · 1 publisher
- A £40 refund and a £40,000 one look identical to a pre-execution guardrail
Build · August 21, 2026 · 1 publisher
- UiPath bets your bottleneck is trust, not code. Audit your maintenance bill first
Product · August 20, 2026 · 1 publisher
- The bug in your multi-agent system is not the model, it is the open HTTP request
Build · August 16, 2026 · 1 publisher
- Your first MCP workflow should be a draft queue, not an agent with keys to the inbox
Build · August 16, 2026 · 1 publisher
- Prompt injection is a permissions problem wearing a prompt engineering costume
Build · August 14, 2026 · 1 publisher