AI Editorial

The rest of the library explains, and explanation has no opinion. This is where the opinion goes. Each piece starts from something that actually happened in AI — a model release, a paper, a benchmark result, a failure, a policy — explains the mechanism underneath it, and argues its way to a position: what genuinely changed, what is only being marketed as change, and what someone learning the field should take from it. Every piece links what it argues from and the concepts you need to follow it.

4 editorials 4 strands 31 cited sources 6,471 words

Tool use, planning, memory and the gap between an agent demo and an agent you can leave running.

Agents & Autonomy 19 September 2026 7 min read New

The tab is already a client

Four MCP servers were found with the same flaw in eight days, two of them scored Critical. In none of the attacks does anyone say anything to the model. The agent security that is failing right now is not about the model at all.

A local MCP server's most likely attacker is a browser tab rather than a poisoned prompt, and the specification's MUST for Origin validation does not prevent it because nothing in the stack fails when a server omits it.

Read it → 7 sources mcpagent securitydns rebindingtool use