Coding agents
What Claude Code, Codex, Copilot, Cursor and similar tools can and can't do. Every brief item about Coding agents, newest first, each with its primary source.
Where it stands
Coding agent updates over the past two weeks are about governing them once they're in the engineering workflow. In early October GitHub opened Copilot code review as an API; on October 7 Copilot local sandboxing went GA and a purpose-built secret detection model shipped; the same day Copilot CLI 1.0.94-0 started discovering local Ollama models in /model, and Codex CLI 0.161.0 made GPT-6.1 Sol the default and fixed escalation so it still honors denied reads and network limits.
Two trends: model choice is getting flexible, with local, cloud and different vendors switchable in one session; and permissions and data boundaries are the main battleground, with sandboxes, offline modes and escalation rules all getting finer. Flexibility also breeds misunderstandings: choosing a local model in Copilot doesn't mean offline, since telemetry and remote providers may still reach the network.
What to watch next: when Copilot's announced intelligent routing with local models arrives, whether other coding agents follow with OS-level sandboxing, and how default model changes hit team bills.
My advice: give your team's coding agents one shared config that pins model versions, forces offline mode on confidential repos and limits the sandbox to the current repo and an allowlisted network; wire review and security checks in before push, and cap the budget for anything metered.
Darius · Updated Oct 9, 2026
Timeline 6 items
-
Oct 9 · Fri · 2 items
- Tools github.blog ↗GitHub Copilot CLI 1.0.94-0 discovers local Ollama models in /model and switches to them in-session
Take · The easy trap is the last point: switching to a local model doesn't mean your code stays on the machine. For teams with confidentiality requirements, I'd put COPILOT_OFFLINE=true in shared config instead of relying on everyone to remember to switch models.
From the Oct 9 brief · item 04 → - Tools github.com ↗Codex CLI 0.161.0 makes GPT-6.1 Sol the default and lets you pick a cyber access program per turn
Take · When the default model changes, the same scripts change in cost and output style. If you run codex exec in CI, I'd pin the model explicitly and switch only after comparing Sol's results and bill on non-critical jobs.
From the Oct 9 brief · item 05 →
-
-
Oct 8 · Thu · 2 items
- Tools github.blog ↗Local sandboxing for GitHub Copilot is generally available, restricting agent commands’ file, network and credential access with enforceable enterprise policies
Take · The biggest worry about letting coding agents run freely has always been what they can touch on your machine. I'd set the team default to: write only to the current repo, no access to Git credentials, network via an allowlist, with local MCP servers included. That beats reviewing every command after the fact, and teams on other coding agents should hold their isolation to the same bar.
From the Oct 8 brief · item 03 → - Safety github.blog ↗GitHub ships a purpose-built model for leaked secrets that reads surrounding code to catch unformatted passwords, coming to push protection and Copilot /security-review
Take · With agents committing at every step, the odds of a secret slipping into history only go up, and blocking it at push time is far cheaper than rotating it later. I'd pilot push protection on repos that already have GHSP and set a budget cap on AI Credits, since checks bill even when nothing is blocked. GitHub's note that agents shouldn't enable credit-consuming features without explicit authorization is worth copying straight into a team's agent rules.
From the Oct 8 brief · item 04 →
-
-
Oct 6 · Tue · 1 item
- Tools aws.amazon.com ↗AWS releases the aws-ai-ml skill so Claude Code, Codex and Kiro can benchmark SageMaker inference endpoints and generate deployment code
Take · Skills are becoming how cloud vendors compete for the coding-agent entry point: whoever's deployment know-how lives inside the agent gets picked more often. I like that it produces code rather than opaque actions, but benchmarks spin up real endpoints and real bills; give the agent a separate account with a budget cap before letting it run.
From the Oct 6 brief · item 02 →
-
-
Oct 5 · Mon · 1 item
- Tools github.blog ↗GitHub Copilot code review gets REST and GraphQL APIs; Balanced becomes the default effort level
Take · With an API, AI review can plug into your own release flow, for example raising the effort only when a change touches payments or permissions. The default effort changed, so review time and usage may shift too; check your bill and PR wait times this week. I wrote on the blog about how to split review work when AI writes most first drafts.
From the Oct 5 brief · item 03 →
-