Relm Journal · Field notes
In this issue 02 / 02

Nº 02

Humans are leaving the loop. Now the boundary has to be real.

On August 14, Auto Mode becomes the default in Claude Code: a model reviews each command instead of a human approving it. It caught 89% of dangerous commands in testing; humans caught 13.6%. That is a real improvement, and it is still not a security boundary.

Coding agents Claude Code Security
Read entry

Nº 01

Three coding-agent incidents, three different failures.

In the past two months, three coding-agent incidents have surfaced publicly: a Cursor agent deleting a production database, a Gemini agent exfiltrating a token after prompt injection, and an npm supply-chain compromise that hit any host running npm install. Each one isolates a different structural property of how agents fail, and the defenses don’t overlap.

Coding agents Incidents Security
Read entry
More to come Relm Journal