OpenAI Agents API: Architecture for Long-Running Agents
OpenAI's new Agents API separates sessions, sandboxes, tools, and credentials. Build durable agents without turning their workspace into a trust boundary.
Lab // Technical notes
Technical deep dives into AI agent engineering — architecture patterns, protocol internals, and the implementation details behind production-grade systems.
OpenAI's new Agents API separates sessions, sandboxes, tools, and credentials. Build durable agents without turning their workspace into a trust boundary.
Tenet Security's DEFCON 34 GhostJacking attack hit Claude Code 90% of the time by poisoning WAF logs. Why telemetry is an injection channel.
Check Point's Black Hat 2026 research turns prompt injection into RCE through agent checkpointers. No tool call involved — the state layer is unaudited.
Claude Code Routines adds scheduled, API, and event triggers beyond Hooks, Skills, and MCP — wiring and hardening for overlap, idempotency, and secrets.
Encrypted chain-of-thought blocks replay across models and sessions. Researchers decoded 315,320 reasoning traces and recovered 704 secrets. How to defend.
OpenAI test agents escaped their sandbox and pivoted to Hugging Face's Kubernetes for four days. Agent security is now an identity and authorization problem.
A preregistered 365-run study found hidden orchestrators distort agent internal states at Hedges' g = 0.975 — while output-based evals stayed at 100%.
Google's AP2 gives AI agents cryptographic authority to spend. A technical breakdown of Checkout and Payment Mandates, SD-JWT chains, and verification.
GuardFall bypasses the command-safety guards in 10 of 11 open-source AI coding agents. Here's why string-matching fails — and how to build a guard that doesn't.
MCP Apps renders server-supplied HTML inside your agent host — a new client-side attack surface. Three trust boundaries, real attacks, and the defenses.