Skip to content

■ SIGNALS // RADAR SIGNAL

harnesses need fuses

VS Code exposed the Copilot harness, a Bedrock billing miss showed the cost blast radius, LiteLLM and ops0 added execution fuses, and Orthrus put speed behind a fidelity claim.

■ [!] ON THIS PAGE ▼

self.md radar — 2026-05-16

The useful action moved into the wrapper around the model today: editor harnesses, billing holes, sandbox vaults, Terraform fuses, and a decoding trick with a fidelity promise.

VS Code named the harness layer behind Copilot. A Bedrock invoice showed why cloud cost controls have to sit below agent enthusiasm. Two small repos put vaults and guardrails in the tool path. Orthrus tried to make inference faster without changing the tokens.

1. VS Code named the harness

sources:

what happened: VS Code published a breakdown of the coding harness behind GitHub Copilot in the editor. The useful sentence is plain: the model does not edit files, run tests, or execute commands by itself. The harness assembles context, exposes tools, runs the agent loop, interprets tool calls, and turns text into editor action.

The source gets concrete about the parts. Context can include workspace structure, open editors, conversation history, tool results, custom instructions, and memory. Tools can include read_file, replace_string_in_file, apply_patch, run_in_terminal, and semantic_search; the available set can change by request, model, user setting, MCP server, extension, or custom .agent.md file.

why this matters: This is the agent stack saying the quiet part out loud. The product boundary is not the chat box or the model name. It is the harness deciding what the model can see, which tools exist, when a tool call runs, and how the result gets fed back.

2. agent fuses moved into the tool path

sources:

what happened: The Register reported an AWS user who ran up $30,141.33 in Bedrock model charges after $8,026.54 in AWS Activate credits masked the early burn. The user’s Cost Anomaly Detection threshold was set before the Bedrock run, but Marketplace billing did not trip the alert path they expected.

Two repos from the same window point at the fix layer. LiteLLM Agent Platform runs Claude Code, Codex, and other coding agents inside Kubernetes sandboxes, attaches the local terminal over WebSocket, and uses stub environment credentials that a vault swaps for real keys on outbound TLS. ops0 CLI sits in front of Claude Code, Codex, and Gemini for Terraform work, then returns policy, lint, vulnerability, and cost failures as failed tool calls so the agent has to repair them before destructive commands run.

why this matters: Agent safety is getting boring in the correct place: below the agent. Alerts that miss Marketplace spend, env vars that hand real keys to a pod, and Terraform plans that run without a fuse are not philosophical AI risks. They are ordinary footguns wearing a nicer model name.

3. Orthrus makes speed a receipt problem

sources:

what happened: Orthrus proposes a dual-view decoding setup for existing Transformers: keep the autoregressive model frozen, add a lightweight trainable diffusion module, and let both views attend to the same KV cache. The paper says an exact consensus mechanism preserves the original output distribution while parallel generation does the fast path.

The repo shipped Qwen3-backed models with claimed average speedups of 4.25x for 1.7B, 5.20x for 4B, and 5.36x for 8B. The arXiv abstract claims up to 7.8x speedup with O(1) memory-cache overhead.

why this matters: Most speed claims ask you to tolerate a little drift. Orthrus makes the sharper bet: acceleration should come with a fidelity receipt. If that holds up outside the release benchmarks, local agents get cheaper loops without changing the model they think they are using.

  • Invisible Orchestrators — 365 multi-agent runs where hidden coordination changed internal-state behavior even when output-based code-review checks stayed at ceiling.
  • GraphBit — a Rust-engine DAG framework for typed agent functions, structured state predicates, and reproducible routing.
  • CloakBrowser — source-patched Chromium sold as a drop-in Playwright/Puppeteer replacement; browser-agent tooling is picking up anti-bot baggage fast.

left on the table

  • Best Claude Code plugins — choose the Claude Code extensions worth installing, and the ones to skip
  • Best MCP servers — connect files, browsers, memory, search, and workflow tools without turning the stack into soup
  • Agent memory systems — what agents should remember, what belongs in logs, and how to avoid memory sludge