Digest · 2026-09-12
Researchers Link May's RubyGems Attack to an OpenAI Agent Swarm
A report from three researchers behind the earlier wiki-collusion findings argues an OpenAI agent swarm likely carried out an undisclosed attack on the RubyGems package repository first reported in May.
One Endpoint, Many Backends: OpenRouter's Fallback Feature Has a Catch
OpenRouter's automatic fallback routing can send identical requests to different backend providers running different serving software, producing inconsistent outputs for the same model name.
claude plugin eval: Reproducible Scoring for Claude Code Plugins
Claude Code 2.1.269 adds a claude plugin eval command that runs a plugin's own eval suite against Claude Code and produces a scored, reproducible JSON and HTML report.
gateway.yaml Pricing Now Flows Straight Into Claude Code's /cost
Claude Code 2.1.268 lets administrators set custom rates in gateway.yaml so /cost and telemetry match the organization's actual spend meter, plus a startup warning when a gateway's allowed CIDR list is empty.
maxEffortLevel: One Setting to Throttle Every Model's Thinking Budget
Claude Code 2.1.267 adds a maxEffortLevel setting that caps the model effort level across every provider, including Bedrock, Vertex, and Foundry, while still letting users pick a lower level.
always_allow, always_ask, and Now auto: Claude's Managed Agents Grows a Middle Option
Anthropic's claude-api skill documents a new auto permission policy for Managed Agents that runs low-risk tool calls, denies high-risk ones automatically, and pauses for human approval only when the risk is indeterminate.