self.md radar — 2026-05-21
Agent trust failed at the edges today: the sandbox, the CLI, and the repo handoff all needed harder controls than the interface suggested.
Start with a Claude Code sandbox bypass, then a Google CLI migration deadline, then three small tools that test docs, repos, and workflow before an agent starts editing. The pattern is not glamorous. It is mostly locks, runway checks, and migration dates. Good.
1. Claude Code’s sandbox got a second red mark
sources:
what happened: Aonan Guan published a second reported Claude Code network sandbox bypass. The writeup says every Claude Code release from 2.0.24 through 2.1.89 was vulnerable to a SOCKS5 hostname null-byte injection that let a process inside the sandbox reach hosts the user’s policy meant to block. It also says the vulnerable span covered about 5.5 months and roughly 130 versions, and that both this finding and an earlier bypass ended in silent fixes without a Claude Code security advisory.
why this matters: A sandbox is not a brand promise; it is code with strange string edges. If agent policy depends on network allowlists, operators need reproducible probes, version pinning, and external logs instead of waiting for a changelog to admit the part that matters.
2. Gemini CLI got a migration deadline
sources:
what happened: Google said Antigravity CLI is now available and set June 18, 2026 as the stop-serving date for Gemini CLI and Gemini Code Assist IDE extension requests from Google AI Pro, Google AI Ultra, and free individual Gemini Code Assist users. The post says Gemini CLI grew to millions of users, more than 100,000 GitHub stars, 6,000 merged pull requests, and hundreds of contributors, then says those workflows outgrew the early-2025 terminal UI.
why this matters: A successful agent CLI can still become migration debt. If a team wired scripts, internal docs, or muscle memory around Gemini CLI, the deadline turns a product rename into an operations chore.
3. Agent readiness moved from vibes to preflight
sources:
what happened: Dari-docs tests whether documentation is clear enough for agents by sending simulated developer agents through real tasks, reporting where they get stuck, and proposing docs edits from that feedback. Agent Readiness Scanner checks 12 repo-governance signals, returns a 0–100 readiness score, separates critical failures, and advertises deterministic local checks with no LLM calls or telemetry. SaneProcess packages AGENTS.md, native hooks, MCP, SaneMaster, verification commands, release checks, and circuit breakers into a shared workflow for coding agents.
why this matters: The better question is no longer whether the model can understand the repo. It is whether the repo has proved it is safe to hand to a model. That is dull in the correct way: fewer heroic prompts, more boring gates.
supporting links
- Claude Code Plugins Directory — Anthropic’s managed plugin directory is useful, but the README’s trust warning is the part to read twice.
- Engram — local MCP-compatible identity layer for Claude Code, Codex, and Cursor; interesting, but not stronger than the safety/preflight spine.
- True Recall — Obsidian plugin with FSRS v6 scheduling and 5k downloads; a clean PKM signal on a non-PKM day.
- agent-browser — Vercel’s Rust browser automation CLI stayed supporting because browser-agent receipts already had recent main coverage.
left on the table
- Claude Code Plugins Directory did not become a main item because skills and plugin packaging have had recent main coverage; the fresh operator detail was Anthropic’s warning about third-party MCP servers, files, and software.
- Engram has a neat local-first identity shape, but memory and identity layers have been close to the surface all week.
- OpenAI’s geometry-conjecture item was cut because the canonical OpenAI page returned a Cloudflare/JavaScript challenge during source verification.
- Karpathy-to-Anthropic chatter stayed out because personnel heat is not an operator change by itself.
Related self.md routes
- Personal AI OS tools — the control-plane map for personal agents, receipts, memory, and tools
- AI coding assistants — compare coding workbenches by review surface, permissions, cost, logs, and escape hatches
- Best Claude Code plugins — choose the Claude-specific extensions worth installing, and the ones to skip