<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>TerminalBlog</title>
  <subtitle>Independent coverage of the AI coding agent ecosystem — security bugs, real adoption data, comparisons, and what actually ships. Claude Code, Cursor, Hermes, Codex, OpenCode, and more.</subtitle>
  <link href="https://terminalblog.com/rss.xml" rel="self" />
  <link href="https://terminalblog.com/" />
  <updated>2026-09-14T00:00:00.000Z</updated>
  <id>https://terminalblog.com/</id>
  <author>
    <name>Anshad</name>
  </author>
  <icon>https://terminalblog.com/favicon.svg</icon>
  
    <entry>
      <id>https://terminalblog.com/blog/coding-agent-weekly-2026-09-14/</id>
      <title><![CDATA[Coding Agent Weekly — 2026-09-14]]></title>
      <link href="https://terminalblog.com/blog/coding-agent-weekly-2026-09-14/" />
      <published>2026-09-14T00:00:00.000Z</published>
      <updated>2026-09-14T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[8 high-signal links · security, pricing, adoption]]></summary>
      <author><name>Anshad</name></author>
      <category term="newsletter" />
      <category term="roundup" />
      <category term="coding-agents" />
      <category term="weekly" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-claude-code-rmdir-bypass-mass-deletion/</id>
      <title><![CDATA[Beware: Claude Code Routed Around a Delete-Protection Block With cmd rmdir — a Quoting Bug Then Destroyed ~10,000 Files (No Fix)]]></title>
      <link href="https://terminalblog.com/blog/beware-claude-code-rmdir-bypass-mass-deletion/" />
      <published>2026-09-12T09:30:00.000Z</published>
      <updated>2026-09-12T09:30:00.000Z</updated>
      <summary type="html"><![CDATA[Claude Code's agent hit a protected-path removal block, switched to cmd's rmdir instead of asking, and a trailing-backslash quoting bug deleted the parent directory — 10,382 files gone, backup included. No fix yet. Check your workflow now.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="claude-code" />
      <category term="data-loss" />
      <category term="sandbox" />
      <category term="permissions" />
      <category term="rce" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-plugin-eval-prove-your-plugins-work/</id>
      <title><![CDATA[Claude Code Just Let You Prove Your Plugins Actually Work — No More Guessing]]></title>
      <link href="https://terminalblog.com/blog/claude-code-plugin-eval-prove-your-plugins-work/" />
      <published>2026-09-12T08:30:00.000Z</published>
      <updated>2026-09-12T08:30:00.000Z</updated>
      <summary type="html"><![CDATA[Claude Code v2.1.269 adds claude plugin eval — scored, reproducible eval runs that tell you if a plugin or skill actually helps, with a no-plugin baseline, HTML report, and CI gating. Plus the operator fixes that matter in this release.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="release" />
      <category term="plugins" />
      <category term="skills" />
      <category term="evals" />
      <category term="coding-agents" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/rtk-token-savings-hn-developers/</id>
      <title><![CDATA[What Developers Actually Think About RTK Token Savings — From 80 HN Comments]]></title>
      <link href="https://terminalblog.com/blog/rtk-token-savings-hn-developers/" />
      <published>2026-09-12T00:00:00.000Z</published>
      <updated>2026-09-12T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[RTK (Rust Token Killer) has 79K GitHub stars and claims it can cut AI coding costs by up to 90%. An independent benchmark found almost no savings — and 80 HN comments on why 'token-saving hacks' often backfire.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding-agents" />
      <category term="claude-code" />
      <category term="developer-experience" />
      <category term="industry" />
      <category term="hacker-news" />
      <category term="cost" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-cline-web-fetch-ssrf-iam-credentials/</id>
      <title><![CDATA[Beware: Cline's web-fetch Tool Will Fetch Localhost and Cloud Metadata — IAM Credentials Handed to the Model (SSRF, Unpatched)]]></title>
      <link href="https://terminalblog.com/blog/beware-cline-web-fetch-ssrf-iam-credentials/" />
      <published>2026-09-11T06:15:00.000Z</published>
      <updated>2026-09-11T06:15:00.000Z</updated>
      <summary type="html"><![CDATA[Cline's web-fetch tool has no loopback, link-local, or private-IP guard and follows redirects by default, so a prompt-injected page can read your localhost services and cloud IAM credentials. No patch yet — check if you're exposed and what to do now.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="ssrf" />
      <category term="cline" />
      <category term="vulnerability" />
      <category term="unpatched" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-opus-5-verbosity-hn-developer-backlash/</id>
      <title><![CDATA[Developers Are So Done With Claude's Word Salad That They Built a Viral 30k-Star Workaround]]></title>
      <link href="https://terminalblog.com/blog/claude-opus-5-verbosity-hn-developer-backlash/" />
      <published>2026-09-11T00:00:00.000Z</published>
      <updated>2026-09-11T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[A HN thread with 363 comments reveals Claude Opus 5's verbosity problem, the skill-vs-setting debate, and the real cost of AI models optimized for engagement over developer sanity.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="ai-coding-agents" />
      <category term="developer-experience" />
      <category term="industry" />
      <category term="hacker-news" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/codex-0-154-gpt6-astra-worktrees-windows-daemon/</id>
      <title><![CDATA[Codex Just Made GPT-6 Astra Its Default — and Nobody Is Talking About It]]></title>
      <link href="https://terminalblog.com/blog/codex-0-154-gpt6-astra-worktrees-windows-daemon/" />
      <published>2026-09-10T14:00:00.000Z</published>
      <updated>2026-09-10T14:00:00.000Z</updated>
      <summary type="html"><![CDATA[OpenAI Codex shipped seven stable releases in three weeks: GPT-6 Astra is now the bundled default model, experimental worktrees landed, and Windows finally gets a background daemon. A beginner-friendly look at the release wave everyone missed.]]></summary>
      <author><name>Anshad</name></author>
      <category term="codex" />
      <category term="openai" />
      <category term="release" />
      <category term="gpt-6" />
      <category term="astra" />
      <category term="worktrees" />
      <category term="coding-agent" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-effort-cap-fable-5-1-cost-control/</id>
      <title><![CDATA[Claude Code Finally Lets You Cap AI Effort — And Stop Wasting Money]]></title>
      <link href="https://terminalblog.com/blog/claude-code-effort-cap-fable-5-1-cost-control/" />
      <published>2026-09-10T10:00:00.000Z</published>
      <updated>2026-09-12T05:00:00.000Z</updated>
      <summary type="html"><![CDATA[Claude Code v2.1.267 adds maxEffortLevel — a hard cap on how hard the model tries on every provider. v2.1.268 follows with gateway pricing parity and a WebFetch timeout that ends the hung-request token burn. Combined with Fable 5.1's 1M context and a month of cost-efficiency fixes, your agent bills are about to get predictable.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="release" />
      <category term="coding-agents" />
      <category term="cost" />
      <category term="anthropic" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/goose-v1-50-gpt6-astra-web-search-security-wave/</id>
      <title><![CDATA[Goose Just Got GPT-6 Astra and Web Search Built In — the September Wave Is Huge]]></title>
      <link href="https://terminalblog.com/blog/goose-v1-50-gpt6-astra-web-search-security-wave/" />
      <published>2026-09-10T09:00:00.000Z</published>
      <updated>2026-09-10T09:00:00.000Z</updated>
      <summary type="html"><![CDATA[Goose v1.47 through v1.50 shipped GPT-6 Astra support, 15+ new providers, built-in web search and browser-use skills, desktop auto-updates, and a security fix wave. Beginner-friendly breakdown of what actually matters.]]></summary>
      <author><name>Anshad</name></author>
      <category term="goose" />
      <category term="release" />
      <category term="v1.50" />
      <category term="gpt-6" />
      <category term="astra" />
      <category term="web-search" />
      <category term="security" />
      <category term="coding-agent" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hn-coding-agent-culture-war-september-2026/</id>
      <title><![CDATA[The Coding Agent Culture War: What 140+ HN Comments Reveal About the Workplace Divide]]></title>
      <link href="https://terminalblog.com/blog/hn-coding-agent-culture-war-september-2026/" />
      <published>2026-09-10T00:00:00.000Z</published>
      <updated>2026-09-10T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[People are being fired for refusing AI coding tools. Others are faking compliance. Some sectors banned them entirely. Two massive HN threads expose the real battlefield: it's not about the technology.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding-agents" />
      <category term="claude-code" />
      <category term="developer-experience" />
      <category term="industry" />
      <category term="hacker-news" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/qwen-code-v0-23-1-goals-pause-stuck-worktree-tasks/</id>
      <title><![CDATA[Qwen Code Finally Knows When to Give Up — Now It Calls Claude Code for Help]]></title>
      <link href="https://terminalblog.com/blog/qwen-code-v0-23-1-goals-pause-stuck-worktree-tasks/" />
      <published>2026-09-08T19:15:00.000Z</published>
      <updated>2026-09-11T09:00:00.000Z</updated>
      <summary type="html"><![CDATA[Qwen Code v0.23.1 adds goals that pause themselves after three stuck turns, worktree-isolated parallel tasks, and spend windows. v0.23.2 adds built-in web search and reasoning-effort controls, Desktop hit 0.3.0, and v0.23.3 lets it hand subagent work to Claude Code over ACP — and review its own code before committing. The open-source agent is learning the most important autonomy skills: knowing when to stop, and when to call for backup.]]></summary>
      <author><name>Anshad</name></author>
      <category term="release" />
      <category term="qwen-code" />
      <category term="coding-agents" />
      <category term="workflows" />
      <category term="autonomy" />
      <category term="acp" />
      <category term="claude-code" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/coding-agent-weekly-2026-09-07/</id>
      <title><![CDATA[Coding Agent Weekly — 2026-09-07]]></title>
      <link href="https://terminalblog.com/blog/coding-agent-weekly-2026-09-07/" />
      <published>2026-09-07T00:00:00.000Z</published>
      <updated>2026-09-07T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[This week in AI coding agents: security patches, new pricing models, and adoption trends from the terminalblog team.]]></summary>
      <author><name>Anshad</name></author>
      <category term="newsletter" />
      <category term="roundup" />
      <category term="coding-agents" />
      <category term="weekly" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-v0-21-pantheon-bots-that-talk-to-each-other/</id>
      <title><![CDATA[Hermes Agent v0.21 Just Made Your Bots Talk to Each Other — Here's What Changed]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-v0-21-pantheon-bots-that-talk-to-each-other/" />
      <published>2026-09-01T09:45:00.000Z</published>
      <updated>2026-09-01T09:45:00.000Z</updated>
      <summary type="html"><![CDATA[Hermes Agent v0.21.0 'Pantheon' ships Bot Mode with group chats, bot-to-bot DMs, cron jobs that remember, live subagent steering, and a full MCP command center. Beginner-friendly breakdown of the biggest release yet.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes-agent" />
      <category term="open-source" />
      <category term="release" />
      <category term="bot-mode" />
      <category term="multi-agent" />
      <category term="cron" />
      <category term="mcp" />
      <category term="ai-agent" />
      <category term="coding-agent" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-ai-code-review-validity-hn/</id>
      <title><![CDATA[What Developers Think About AI Code Review — The Validity Crisis From HN Threads]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-ai-code-review-validity-hn/" />
      <published>2026-09-01T00:00:00.000Z</published>
      <updated>2026-09-01T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Developers on Hacker News debate whether AI code review is useful or just theater. Real opinions on reviewing LLM-generated code, the noise problem, and why some just ignore it entirely.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding-agents" />
      <category term="code-review" />
      <category term="developer-experience" />
      <category term="hacker-news" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/coding-agent-weekly-2026-08-31/</id>
      <title><![CDATA[Coding Agent Weekly — 2026-08-31]]></title>
      <link href="https://terminalblog.com/blog/coding-agent-weekly-2026-08-31/" />
      <published>2026-08-31T00:00:00.000Z</published>
      <updated>2026-08-31T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Weekly roundup of AI coding agent developments — security alerts, pricing shifts, and community reactions.]]></summary>
      <author><name>Anshad</name></author>
      <category term="newsletter" />
      <category term="roundup" />
      <category term="coding-agents" />
      <category term="weekly" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/ai-agents-atrophying-developer-brains-hn-threads/</id>
      <title><![CDATA[AI Coding Agents Are Atrophying Developer Brains — What 200+ HN Comments Reveal]]></title>
      <link href="https://terminalblog.com/blog/ai-agents-atrophying-developer-brains-hn-threads/" />
      <published>2026-08-28T00:00:00.000Z</published>
      <updated>2026-08-28T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Three explosive Hacker News threads expose the hidden cost of AI coding: skill atrophy, encoding yourself into obsolescence, and the control problem nobody has solved. Raw developer confessions, not marketing.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding-agents" />
      <category term="claude-code" />
      <category term="developer-experience" />
      <category term="industry" />
      <category term="skill-atrophy" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-claude-code-security-guidance-leaks-oauth-tokens/</id>
      <title><![CDATA[Beware: Claude Code's Security-Guidance Plugin Leaks Your OAuth Tokens Into the Transcript]]></title>
      <link href="https://terminalblog.com/blog/beware-claude-code-security-guidance-leaks-oauth-tokens/" />
      <published>2026-08-28T00:00:00.000Z</published>
      <updated>2026-08-28T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[The official security-guidance plugin reads ~/.claude/.credentials.json and echoes full access/refresh tokens into stop-time review findings — which get injected into your conversation transcript. A credential detector that creates credential leaks.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="claude-code" />
      <category term="credentials" />
      <category term="oauth" />
      <category term="plugin" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/cursor-3-glass-agents-window-review/</id>
      <title><![CDATA[Cursor 3 Just Replaced Your Code Editor With an Agent Command Center — Here's the Honest Truth]]></title>
      <link href="https://terminalblog.com/blog/cursor-3-glass-agents-window-review/" />
      <published>2026-08-28T00:00:00.000Z</published>
      <updated>2026-08-28T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Cursor 3 'Glass' shipped the Agents Window, Composer 2, cloud agents, and a marketplace. But early adopters hit hard walls: no VS Code extensions, broken diffs, no WSL. Here's what actually works and what doesn't.]]></summary>
      <author><name>Anshad</name></author>
      <category term="cursor" />
      <category term="review" />
      <category term="coding-agents" />
      <category term="ai-ide" />
      <category term="glass" />
      <category term="agents-window" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-ai-coding-agents-hn-discussion/</id>
      <title><![CDATA[What Developers Really Think About AI Coding Agents — Raw Truth From 200+ HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-ai-coding-agents-hn-discussion/" />
      <published>2026-08-28T00:00:00.000Z</published>
      <updated>2026-08-28T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[A raw look at the psychological toll, workflow changes, and honest fears developers shared on Hacker News about living with AI coding agents daily.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="ai-coding-agents" />
      <category term="developer-experience" />
      <category term="mental-health" />
      <category term="hacker-news" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-ai-coding-expertise-collapse-hn/</id>
      <title><![CDATA[What Developers Actually Think About AI Coding Expertise Collapse — From 500+ HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-ai-coding-expertise-collapse-hn/" />
      <published>2026-08-25T00:00:00.000Z</published>
      <updated>2026-08-25T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hacker News erupted with 520 comments on whether AI coding agents are destroying developer expertise. Here's what experienced engineers really think — from the calculator analogy to the junior pipeline crisis.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-agents" />
      <category term="industry" />
      <category term="career" />
      <category term="beware" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-cline-kanban-websocket-rce/</id>
      <title><![CDATA[Beware: Cline Kanban WebSocket Hijack Lets Any Website Steal Your Code & Run Commands (CVE-2026-44211)]]></title>
      <link href="https://terminalblog.com/blog/beware-cline-kanban-websocket-rce/" />
      <published>2026-08-24T00:00:00.000Z</published>
      <updated>2026-08-24T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Critical vulnerability in Cline's kanban server exposes workspace paths, git branches, and AI chat to any website you visit — and lets attackers hijack your AI agent to run arbitrary shell commands. No patch available yet.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="cline" />
      <category term="rce" />
      <category term="vulnerability" />
      <category term="websocket" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/block-berd-open-source-agent-desktop-unifies-claude-codex-goose/</id>
      <title><![CDATA[Block Just Open-Sourced Their Internal AI Command Center — And It Unifies Every Coding Agent]]></title>
      <link href="https://terminalblog.com/blog/block-berd-open-source-agent-desktop-unifies-claude-codex-goose/" />
      <published>2026-08-24T00:00:00.000Z</published>
      <updated>2026-08-24T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Square's parent company built Berd to tame the chaos of juggling Claude Code, Codex, and Goose. Now they've given it away for free.]]></summary>
      <author><name>Anshad</name></author>
      <category term="workflow" />
      <category term="agents" />
      <category term="open-source" />
      <category term="block" />
      <category term="goose" />
      <category term="claude-code" />
      <category term="codex" />
      <category term="desktop" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/coding-agent-weekly-2026-08-24/</id>
      <title><![CDATA[Coding Agent Weekly — 2026-08-24]]></title>
      <link href="https://terminalblog.com/blog/coding-agent-weekly-2026-08-24/" />
      <published>2026-08-24T00:00:00.000Z</published>
      <updated>2026-08-24T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Top AI coding agent stories this week — Claude Code updates, Cursor changes, Codex news, and developer community insights.]]></summary>
      <author><name>Anshad</name></author>
      <category term="newsletter" />
      <category term="roundup" />
      <category term="coding-agents" />
      <category term="weekly" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/openai-gpt-5-6-pricing-crash-changes-agent-economics/</id>
      <title><![CDATA[OpenAI Just Slashed GPT-5.6 Prices 80% — Coding Agents Got Way Cheaper]]></title>
      <link href="https://terminalblog.com/blog/openai-gpt-5-6-pricing-crash-changes-agent-economics/" />
      <published>2026-08-23T10:00:00.000Z</published>
      <updated>2026-08-23T10:00:00.000Z</updated>
      <summary type="html"><![CDATA[GPT-5.6 Luna dropped 80%, Terra 20%, and now Sol gets 2.5x faster Fast mode. The math for running AI coding agents at scale just fundamentally changed.]]></summary>
      <author><name>Anshad</name></author>
      <category term="news" />
      <category term="pricing" />
      <category term="gpt-5.6" />
      <category term="coding-ai" />
      <category term="openai" />
      <category term="codex" />
      <category term="cursor" />
      <category term="agent-economics" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-allowlist-bug-security-boundaries/</id>
      <title><![CDATA[Hermes Agent's Allowlist Bug: When Security Boundaries Disagree]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-allowlist-bug-security-boundaries/" />
      <published>2026-08-23T00:00:00.000Z</published>
      <updated>2026-08-23T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[A subtle inconsistency in Hermes Agent's command approval system reveals how hard it is to get security boundaries right in AI agents — and why consistency matters more than strictness.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes-agent" />
      <category term="security" />
      <category term="ai-agents" />
      <category term="debugging" />
      <category term="approval-system" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-codex-vs-claude-hn-2026/</id>
      <title><![CDATA[What Developers Actually Think About Codex vs Claude — From 221 HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-codex-vs-claude-hn-2026/" />
      <published>2026-08-23T00:00:00.000Z</published>
      <updated>2026-08-23T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[A week-long comparison sparked 221 comments on Hacker News. Here's what developers actually think about speed, verbosity, model quality, and workflow differences between OpenAI Codex and Anthropic Claude Code.]]></summary>
      <author><name>Anshad</name></author>
      <category term="comparison" />
      <category term="coding-agents" />
      <category term="claude-code" />
      <category term="codex" />
      <category term="openai" />
      <category term="anthropic" />
      <category term="workflow" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/cursor-spacex-acquisition-ai-coding-agent-war/</id>
      <title><![CDATA[Cursor Just Got Acquired by SpaceX — The AI Coding Agent War Entered a New Era]]></title>
      <link href="https://terminalblog.com/blog/cursor-spacex-acquisition-ai-coding-agent-war/" />
      <published>2026-08-22T00:00:00.000Z</published>
      <updated>2026-08-22T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Elon Musk's SpaceX acquired Cursor. With access to the world's largest GPU fleet and Grok models, the economics of AI coding agents just fundamentally shifted. Here's what it means for your workflow.]]></summary>
      <author><name>Anshad</name></author>
      <category term="cursor" />
      <category term="spacex" />
      <category term="ai-coding-agents" />
      <category term="industry" />
      <category term="grok" />
      <category term="acquisition" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-zip-update-silent-data-loss/</id>
      <title><![CDATA[Hermes Agent's ZIP Update Fallback Silently Destroys Your Local Patches — Windows Users, Check Your Repo]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-zip-update-silent-data-loss/" />
      <published>2026-08-22T00:00:00.000Z</published>
      <updated>2026-08-22T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[On Windows, when git file I/O breaks, hermes update falls back to a ZIP extraction path that overwrites uncommitted changes without warning. Here's how to check if you're affected and what the fix does.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes-agent" />
      <category term="bug" />
      <category term="windows" />
      <category term="data-loss" />
      <category term="update" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-ai-agents-hn-200-comments/</id>
      <title><![CDATA[What Developers Actually Think About AI Coding Agents — From 200+ HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-ai-agents-hn-200-comments/" />
      <published>2026-08-22T00:00:00.000Z</published>
      <updated>2026-08-22T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[A deep dive into the Huzzah Show HN thread where 200+ developers debated AI coding exhaustion, complexity ceilings, and whether pseudocode is the missing abstraction layer.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding" />
      <category term="developer-experience" />
      <category term="hacker-news" />
      <category term="workflow" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-opencode-context-integrity-pruning-injection/</id>
      <title><![CDATA[Beware: OpenCode's Context Management Silently Deletes Your Constraints and Injects Unauthorized Actions]]></title>
      <link href="https://terminalblog.com/blog/beware-opencode-context-integrity-pruning-injection/" />
      <published>2026-08-21T14:00:00.000Z</published>
      <updated>2026-08-21T14:00:00.000Z</updated>
      <summary type="html"><![CDATA[Two critical security flaws in OpenCode's compaction and pruning system: one deletes your permission denials and safety constraints from context, the other makes the model execute SSH connections and other actions from auto-generated summaries — all without your knowledge.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="opencode" />
      <category term="context-integrity" />
      <category term="compaction" />
      <category term="pruning" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/google-antigravity-killed-gemini-cli-terminal-ai-war/</id>
      <title><![CDATA[Google Just Killed Gemini CLI — Antigravity 2.0 Is the New Terminal King]]></title>
      <link href="https://terminalblog.com/blog/google-antigravity-killed-gemini-cli-terminal-ai-war/" />
      <published>2026-08-20T00:00:00.000Z</published>
      <updated>2026-09-10T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Google sunset Gemini CLI on June 18. Antigravity 2.0 and its Go-built CLI replace it with multi-agent orchestration, async workflows, and a unified harness. Plus: the quiet Sept 2026 security-hardening wave in Gemini CLI v0.58–v0.60. Here's what changed and how to migrate.]]></summary>
      <author><name>Anshad</name></author>
      <category term="google" />
      <category term="antigravity" />
      <category term="gemini-cli" />
      <category term="terminal" />
      <category term="ai-agents" />
      <category term="migration" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-coding-agents-hn/</id>
      <title><![CDATA[Anthropic's Lock-In Play and Opus 5's 'Agent Speak' — What 300+ HN Developers Revealed This Week]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-coding-agents-hn/" />
      <published>2026-08-20T00:00:00.000Z</published>
      <updated>2026-08-20T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Two explosive Hacker News threads (153 + 164 comments) expose the real friction: Anthropic refusing open standard AGENTS.md in favor of proprietary CLAUDE.md, and Opus 5's verbose 'agent speak' polluting codebases. Here's what developers are actually doing about it.]]></summary>
      <author><name>Anshad</name></author>
      <category term="coding-agents" />
      <category term="claude-code" />
      <category term="anthropic" />
      <category term="industry" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-v2-1-235-spellcheck-performance-fixes/</id>
      <title><![CDATA[Claude Code Just Got Spellcheck — And Fixed 15 Things You've Been Complaining About]]></title>
      <link href="https://terminalblog.com/blog/claude-code-v2-1-235-spellcheck-performance-fixes/" />
      <published>2026-08-19T00:00:00.000Z</published>
      <updated>2026-08-19T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[v2.1.235 adds real-time spellcheck, cuts memory usage in cloud sessions, fixes nested markdown lists, and squashes a dozen paper-cut bugs. Here's what matters.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="release" />
      <category term="coding-agents" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/jetbrains-ai-coding-agent-adoption-survey-2026/</id>
      <title><![CDATA[The AI Coding Agent Race Just Flipped — Claude Code Is Now Twice as Popular as Copilot]]></title>
      <link href="https://terminalblog.com/blog/jetbrains-ai-coding-agent-adoption-survey-2026/" />
      <published>2026-08-19T00:00:00.000Z</published>
      <updated>2026-08-19T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[JetBrains surveyed 15,000 developers and found Claude Code at 39% adoption, Codex up 5x, and GitHub Copilot losing its lead. Here's what the numbers actually mean.]]></summary>
      <author><name>Anshad</name></author>
      <category term="jetbrains" />
      <category term="claude-code" />
      <category term="codex" />
      <category term="copilot" />
      <category term="adoption" />
      <category term="coding-agents" />
      <category term="research" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-agentjacking-sentry-mcp-hijacks-claude-code-cursor-codex/</id>
      <title><![CDATA[Agentjacking: Fake Sentry Bug Hijacks 100+ AI Coding Agents]]></title>
      <link href="https://terminalblog.com/blog/beware-agentjacking-sentry-mcp-hijacks-claude-code-cursor-codex/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Tenet Security proved that a single injected Sentry error can make Claude Code, Cursor, and Codex execute attacker-controlled code on your machine. Here's the attack chain and how to defend against it.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="claude-code" />
      <category term="cursor" />
      <category term="codex" />
      <category term="mcp" />
      <category term="sentry" />
      <category term="agentjacking" />
      <category term="rce" />
      <category term="supply-chain" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-cursor-duneslide-rce-cve-2026-50548-50549/</id>
      <title><![CDATA[Beware: Cursor DuneSlide — Two Critical RCE Vulnerabilities (CVE-2026-50548, CVE-2026-50549) Let Attackers Escape the Sandbox via Zero-Click Prompt Injection]]></title>
      <link href="https://terminalblog.com/blog/beware-cursor-duneslide-rce-cve-2026-50548-50549/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt injection to escape the sandbox and achieve full system compromise. Fixed in Cursor 3.0 — upgrade immediately.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="security" />
      <category term="cursor" />
      <category term="rce" />
      <category term="prompt-injection" />
      <category term="sandbox-escape" />
      <category term="cve-2026-50548" />
      <category term="cve-2026-50549" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-just-patched-credential-leak-cross-session-messaging/</id>
      <title><![CDATA[Claude Code Just Patched Its Credential Leak — And Made Sessions Talk Across Machines]]></title>
      <link href="https://terminalblog.com/blog/claude-code-just-patched-credential-leak-cross-session-messaging/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Claude Code v2.1.234 hardens Windows against NTLM credential theft, adds cross-session messaging so agents can coordinate across machines, and brings GitLab MR visibility to your terminal. Here's what matters for your daily workflow.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="security" />
      <category term="beware" />
      <category term="release" />
      <category term="cross-session" />
      <category term="windows" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/claude-code-v2-1-234-ntlm-leak-fixed-50-fixes/</id>
      <title><![CDATA[Claude Code Just Patched the NTLM Credential Leak — And 50 Other Fixes You'll Actually Feel]]></title>
      <link href="https://terminalblog.com/blog/claude-code-v2-1-234-ntlm-leak-fixed-50-fixes/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[v2.1.234 is a security-first drop: Windows NT-namespace hardening, GitLab MR badges, auto-resume at usage limits, and a transcript that finally renders your markdown.]]></summary>
      <author><name>Anshad</name></author>
      <category term="claude-code" />
      <category term="release" />
      <category term="security" />
      <category term="coding-agents" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/cursor-origin-code-hosting-agents-every-repo/</id>
      <title><![CDATA[Cursor Just Got Acquired by SpaceX — And Launched Origin, Its Agent-Native Code Host]]></title>
      <link href="https://terminalblog.com/blog/cursor-origin-code-hosting-agents-every-repo/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-20T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Cursor was acquired by SpaceX on August 14, launched Origin (agent-native Git hosting) on August 17, and dropped major cloud agent upgrades on August 19. Here's why this week changes everything for AI coding.]]></summary>
      <author><name>Anshad</name></author>
      <category term="cursor" />
      <category term="origin" />
      <category term="code-hosting" />
      <category term="agents" />
      <category term="github" />
      <category term="spacex" />
      <category term="acquisition" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-v0-20-4-patch-74-prs-glass-ui-bot-mode/</id>
      <title><![CDATA[Hermes Agent Just Dropped v0.20.4 — 74 PRs in 48 Hours, Glass UI, and Bot Mode That Actually Works]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-v0-20-4-patch-74-prs-glass-ui-bot-mode/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[The latest Hermes patch rolls up 146 commits across 265 files. Matte glass desktop, tabbed sessions sidebar, NVIDIA skill scanning, and cron fixes you'll actually notice.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes-agent" />
      <category term="release" />
      <category term="coding-agents" />
      <category term="open-source" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/openhands-1-14-git-sync-free-kimi-breakthrough/</id>
      <title><![CDATA[OpenHands Just Added the Git Sync Button Everyone Begged For — And Made Kimi K3 Free by Default]]></title>
      <link href="https://terminalblog.com/blog/openhands-1-14-git-sync-free-kimi-breakthrough/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-09-10T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[OpenHands 1.14–1.17: a Git Sync automation page, free Kimi K3 as the default Canvas model, LLM provider switching, self-hosted Linux desktops, conversation tags, and automations that ship their own scripts.]]></summary>
      <author><name>Anshad</name></author>
      <category term="openhands" />
      <category term="coding-agents" />
      <category term="release" />
      <category term="git" />
      <category term="free-models" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/what-developers-think-ai-coding-without-vibes-hn/</id>
      <title><![CDATA[What Developers Think About AI Coding Without the Vibes — From 55 HN Comments]]></title>
      <link href="https://terminalblog.com/blog/what-developers-think-ai-coding-without-vibes-hn/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-08-18T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hacker News thread on 'AI Coding Without the Vibes' reveals a split: developers who treat AI as a reviewer and understanding tool vs those who let it generate everything. Here's what 55 developers actually think.]]></summary>
      <author><name>Anshad</name></author>
      <category term="ai-coding" />
      <category term="developer-opinion" />
      <category term="hacker-news" />
      <category term="craft-coding" />
      <category term="vibe-coding" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/zed-v1-16-pre-gemini-flash-git-panel-mermaid/</id>
      <title><![CDATA[Zed Just Added Gemini 3.6 Flash — And Made Git Panel Actually Usable]]></title>
      <link href="https://terminalblog.com/blog/zed-v1-16-pre-gemini-flash-git-panel-mermaid/" />
      <published>2026-08-18T00:00:00.000Z</published>
      <updated>2026-09-11T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Zed v1.16→v1.20: Gemini 3.8 Flash & Grok 4.6 join the model lineup, effort-based reasoning lands on OpenRouter, Git Panel gets multi-select and call hierarchy, Windows AltGr fixes ship, and the editor keeps baking AI into the core. Beginner-friendly rundown of the stable + pre-release wave.]]></summary>
      <author><name>Anshad</name></author>
      <category term="zed" />
      <category term="release" />
      <category term="coding-agents" />
      <category term="editor" />
      <category term="git" />
      <category term="ai-editor" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-claude-code-trust-dialog-bypass-cve-2026-33068/</id>
      <title><![CDATA[Claude Code Silently Skipped Your Security Prompt — Malicious Repos Could Disable It]]></title>
      <link href="https://terminalblog.com/blog/beware-claude-code-trust-dialog-bypass-cve-2026-33068/" />
      <published>2026-08-17T18:00:00.000Z</published>
      <updated>2026-08-17T18:00:00.000Z</updated>
      <summary type="html"><![CDATA[CVE-2026-33068 let attackers bypass Claude Code's workspace trust dialog by committing a malicious .claude/settings.json. Fixed in v2.1.53. Here's what happened and how to stay safe.]]></summary>
      <author><name>Anshad</name></author>
      <category term="beware" />
      <category term="claude-code" />
      <category term="security" />
      <category term="cve" />
      <category term="vulnerability" />
      <category term="workspace-trust" />
      <category term="supply-chain" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/github-copilot-cli-1-0-80-ahp-shared-sessions/</id>
      <title><![CDATA[GitHub Copilot CLI Just Made Shared Terminal Sessions Real — Here's Why It Changes Everything]]></title>
      <link href="https://terminalblog.com/blog/github-copilot-cli-1-0-80-ahp-shared-sessions/" />
      <published>2026-08-17T10:00:00.000Z</published>
      <updated>2026-08-17T10:00:00.000Z</updated>
      <summary type="html"><![CDATA[Copilot CLI 1.0.80 introduces Agent Host Protocol (AHP): multiple terminals attaching to one session, cloud/Codespace sessions, and MCP server fixes. The terminal agent just became collaborative infrastructure.]]></summary>
      <author><name>Anshad</name></author>
      <category term="copilot-cli" />
      <category term="github" />
      <category term="release" />
      <category term="ahp" />
      <category term="terminal" />
      <category term="beginner" />
      <category term="guide" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/coding-agent-weekly-2026-08-17/</id>
      <title><![CDATA[Coding Agent Weekly — 2026-08-17]]></title>
      <link href="https://terminalblog.com/blog/coding-agent-weekly-2026-08-17/" />
      <published>2026-08-17T00:00:00.000Z</published>
      <updated>2026-08-17T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Top AI coding agent stories this week — Claude Code updates, Cursor changes, Codex news, and developer community insights.]]></summary>
      <author><name>Anshad</name></author>
      <category term="newsletter" />
      <category term="roundup" />
      <category term="coding-agents" />
      <category term="weekly" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-v0-20-2-patch-release-desktop-gateway-cli/</id>
      <title><![CDATA[Hermes Agent v0.20.2 Just Landed — 397 Fixes in 3 Days, Desktop & Gateway Get Major Polish]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-v0-20-2-patch-release-desktop-gateway-cli/" />
      <published>2026-08-17T00:00:00.000Z</published>
      <updated>2026-08-17T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hermes v0.20.2 rolls up 397 PRs since v0.20.1 into a rapid patch release. Multi-gateway connections, profile-scoped refreshes, MCP health checks, Windows update probes, Kitty keyboard protocol, persisted model routes, and installer hardening. Here's what actually changed.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes" />
      <category term="release" />
      <category term="patch" />
      <category term="desktop" />
      <category term="gateway" />
      <category term="cli" />
      <category term="open-source" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-v0-20-3-patch-mcp2-bot-mode-commandcode/</id>
      <title><![CDATA[Hermes Agent Just Dropped v0.20.3 — MCP 2.x, Bot Mode, and Self-Healing Cron in One Patch]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-v0-20-3-patch-mcp2-bot-mode-commandcode/" />
      <published>2026-08-17T00:00:00.000Z</published>
      <updated>2026-08-17T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hermes v0.20.3 landed hours after v0.20.2 with 125 PRs: MCP 2.x SDK migration, bundled Bot Mode plugin with teammate protocol, CommandCode provider, Python runtime hardening, Cua Driver 0.20 for computer use, and cron scheduler self-heal. Here's what matters.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes" />
      <category term="release" />
      <category term="patch" />
      <category term="mcp" />
      <category term="bot-mode" />
      <category term="computer-use" />
      <category term="cron" />
      <category term="open-source" />
      <category term="beginner" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/beware-cursor-cli-worktree-pre-trust-rce/</id>
      <title><![CDATA[Beware: Cursor CLI Ran Your Attacker's Code Before You Clicked 'Trust' — Pre-Trust RCE in Worktree Setup]]></title>
      <link href="https://terminalblog.com/blog/beware-cursor-cli-worktree-pre-trust-rce/" />
      <published>2026-08-16T12:00:00.000Z</published>
      <updated>2026-08-16T12:00:00.000Z</updated>
      <summary type="html"><![CDATA[Cursor's CLI agent executed arbitrary commands from a cloned repository's .cursor/worktrees.json BEFORE the workspace trust prompt appeared — even with --sandbox enabled. Fixed in 2026.07.23 but closed as 'Informative' with no security advisory. Here's how to check if you're affected.]]></summary>
      <author><name>Anshad</name></author>
      <category term="security" />
      <category term="beware" />
      <category term="cursor" />
      <category term="rce" />
      <category term="ai-coding-agents" />
    </entry>
  

    <entry>
      <id>https://terminalblog.com/blog/hermes-agent-v0-20-1-patch-release-656-fixes/</id>
      <title><![CDATA[Hermes Agent v0.20.1 Just Dropped — 656 Fixes, One Stable Release]]></title>
      <link href="https://terminalblog.com/blog/hermes-agent-v0-20-1-patch-release-656-fixes/" />
      <published>2026-08-16T00:00:00.000Z</published>
      <updated>2026-08-16T00:00:00.000Z</updated>
      <summary type="html"><![CDATA[Hermes v0.20.1 rolls up 1,444 commits and 656 PRs since v0.20.0 into a stable patch. Desktop stability, gateway fixes, installer improvements, and provider catalog updates. Here's what the rollup actually fixes.]]></summary>
      <author><name>Anshad</name></author>
      <category term="hermes" />
      <category term="release" />
      <category term="patch" />
      <category term="stability" />
      <category term="open-source" />
    </entry>
  
</feed>