SyndaiSign inStart free

Blog

Thoughts, updates, and insights from the Syndai team.

EU AI Act Article 12: prove what your AI agent did

Article 12 asks high-risk AI systems to keep automatic logs over their lifetime. Syndai signs a receipt for every run: the conditions, the checks, and the file tree. It is the record an auditor takes.

#ai-agents#compliance#eu-ai-act#product

The Black Hat 2026 coding-agent flaws, and the pattern behind them

At Black Hat USA 2026, Novee Security disclosed flaws in Claude Code (CVE-2026-54316), Gemini CLI (CVE-2026-12537), and Codex. Each is the same shape: untrusted input reaching an agent with more reach than it needed. Here is what happened and how to harden.

#ai-agents#security#coding-agents#cve

The model or the harness: which one is doing the work?

Frontier coding models have converged. Run Claude Code, Codex, and Cursor on the same task and the outputs rhyme. What still varies is the harness around the model. Here is what a harness is responsible for, and why it now decides the outcome.

#ai-agents#coding-agents#harness#context-engineering

MCP's 2026-07-28 spec goes stateless: what changes for tool builders

The Model Context Protocol's 2026-07-28 revision re-architects MCP from a stateful bidirectional protocol into a stateless request/response model, adds Multi Round-Trip Requests, and deprecates Dynamic Client Registration and the HTTP+SSE transport.

#ai-agents#mcp#coding-agents#tooling

The npm worm that plants itself in your coding agent's config

On August 4, 2026, a self-propagating worm compromised the keyv and cacheable npm packages and set up persistence by writing to .claude/settings.json and .vscode/tasks.json. Here is what happened and why the config file is the part worth studying.

#ai-agents#security#coding-agents#supply-chain

How to write an agent skill that works across Claude Code, Codex, and Cursor

A skill is a folder with a SKILL.md file that teaches a coding agent how to do one job. The format is becoming portable across harnesses. Here is how to write one that survives the move from Claude Code to Codex to Cursor.

#ai-agents#agent-skills#coding-agents#tutorial

Prime Agent and the self-improving harness: what RLM actually means

PrimeIntellect open-sourced Prime Agent on August 5, 2026: a coding agent whose context is a variable and whose subagents are function calls. Its headline result is credited to the harness rather than the model. Here is what that means and where it gets hard.

#ai-agents#coding-agents#harness#prime-agent

Run receipts: what your coding agent actually did

What a signed Syndai receipt records: checked conditions, validators, the checked file tree, and the gaps that remain.

#ai-agents#coding-agents#product

Securing coding agents: the untrusted-input-to-CI attack, and how to harden against it

The dangerous chain in a coding agent is untrusted input reaching an agent that has more reach than it needs. A GitHub issue becomes a command, the command reaches CI secrets. Here is the threat model and the controls that break the chain.

#ai-agents#security#coding-agents#prompt-injection

More code reviewers kept finding the same bug

I review the code my agents write. By hand it stopped scaling past twenty agents. CodeRabbit capped at three hundred files. More reviewers just re-found the same bug. Giving each reviewer its own lane fixed the overlap, and it runs inside Syndai's preflight.

#ai-agents#code-review#build-log

Welcome to Syndai

Syndai turns a written spec into a pull request that carries its own evidence, including the criteria it could not check.

#announcement#product