One task moves through memory, tools, approval, artifacts, and handoff. The blue route marks every place the work can wait, change, or pass to someone else. AI-assisted editorial illustration.
In this editionA live index of what you can read today.
656
sourced records
301
systems and frameworks
157
terms and concepts
2
records held for more proof
The week in the field
What made agents easier to trust this week?
Five releases changed what agents may touch, keep, and pass along. Each note begins with the official release record. If one touches your work, read the source. Better boundaries make an agent easier to use without giving it the run of the place.
01
Framework release
A good trace shows the route, every checkpoint, and the place a person stopped the work. AI-assisted editorial illustration.
Pydantic AI adds capability hooks and trace controls
Pydantic AI 2.13.0 adds hooks for model-resolution capabilities. It also lets operators leave model-request parameters out of span attributes. That can reduce what traces record, but it does not make a full telemetry review optional.
A file boundary has to hold from the first check to the place where the session writes. AI-assisted editorial illustration.
Strands Agents hardens file-backed sessions
Strands Agents TypeScript 1.10.0 fixes symlink attacks in FileSessionManager. It also adds intervention handlers and unified storage. The fix closes a specific hole in one component; other storage backends still need their own review.
The valid path continues. The rejected action waits where someone can inspect it. AI-assisted editorial illustration.
OpenAI limits schema expansion and trace-error exposure
Agents SDK Python 0.18.3 limits $ref expansion during strict-schema conversion and hides non-tool details in trace errors. Both fixes narrow known risks. Neither proves that every agent or trace is secure.
A skill can be picked and reused like a tool. Someone still has to own its permissions and release. AI-assisted editorial illustration.
CrewAI takes its Skills Repository out of experimental status
CrewAI 1.15.4 moves its Skills Repository beyond the experimental label. That makes CrewAI’s own surface more settled. It does not guarantee that the repository will work with every other skills format.
The tool call crosses a confirmation gate before it can touch the artifact. AI-assisted editorial illustration.
Google ADK tightens tool confirmation and file access
ADK Python 2.5.0 blocks forged continuations in tool confirmation, rejects user-written function calls in resumable mode, and checks artifact paths for cross-user access. These are useful fixes to named problems, not a promise that every ADK system is secure.
Choose the desk that answers the question in front of you. The glossary explains a term. Systems compares frameworks. Ecosystem shows who is building. Standards shows the rules they share. Start where the thing you need to know is easiest to name, then follow the links.
New to the field? Read these five in order. They cover the agent itself, the work it follows, the rules that hold it in bounds, the protocol it uses for tools, and the test that tells you whether it worked.
Start with any term, system, organization, or standard. The map shows the records sitting closest to it, then lets you open each source for yourself. Use those connections to choose what to read next. A line suggests a path; it does not prove that the two things belong together.