{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "What changed in AX",
  "home_page_url": "https://agentexperience.tech/changes/",
  "feed_url": "https://agentexperience.tech/changes.json",
  "description": "A roughly fortnightly digest of public changes that affect how AI agents find, choose, use and recover with products: launches, documentation, specifications and preprints, each with its source and evidence class.",
  "language": "en-GB",
  "authors": [
    {
      "name": "Agent Experience",
      "url": "https://agentexperience.tech"
    }
  ],
  "_ax": {
    "cadence": "roughly fortnightly",
    "editions": [
      {
        "id": "2026-10-07",
        "number": 1,
        "title": "23 September to 7 October 2026",
        "from": "2026-09-23",
        "to": "2026-10-07",
        "published": "2026-10-08",
        "checked": "2026-10-08",
        "intro": "Two themes ran through this fortnight. Large platforms moved their whole API surface behind search-first discovery, and several vendors moved human confirmation and credential handling into the protocol itself. Preprints kept finding the same thing from different directions: agents report success that did not happen, and small, checkable details in a tool contract change what they do.",
        "url": "https://agentexperience.tech/changes/#edition-2026-10-07"
      }
    ],
    "note": "Each entry links to its source, checked live on the edition’s \"checked\" date. Vendor figures are labelled as vendor claims; paper figures are the paper’s claim."
  },
  "items": [
    {
      "id": "https://agentexperience.tech/changes/#change-cloudflare-mcp-code-mode",
      "url": "https://agentexperience.tech/changes/#change-cloudflare-mcp-code-mode",
      "external_url": "https://github.com/cloudflare/mcp-server-cloudflare",
      "title": "Cloudflare deprecates six product MCP servers in favour of its Code Mode server",
      "content_text": "Pull requests merged on 6 October deprecate Cloudflare's Logpush, AI Gateway, Workers Builds, DNS Analytics, Workers Bindings and Observability MCP servers. The repository README asks users to move to the Cloudflare API MCP server, which reaches the whole API through Code Mode: a handful of tools instead of one per endpoint. The Audit Logs server was deprecated on 24 September. Existing tools keep working for now.",
      "date_published": "2026-10-06T00:00:00Z",
      "tags": [
        "code-mode",
        "dynamic-tools",
        "context-budget"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Large APIs and tool catalogues",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://github.com/cloudflare/mcp-server-cloudflare",
            "label": "cloudflare/mcp-server-cloudflare README"
          },
          {
            "url": "https://github.com/cloudflare/mcp-server-cloudflare/pull/516",
            "label": "Pull request #516 (Observability)"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Agent tool catalogues need a pruning strategy",
            "url": "https://agentexperience.tech/insights/agent-tool-catalogs/"
          },
          {
            "kind": "Rubric check",
            "label": "FIND-06: There are few enough tools to choose from",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#find-06-there-are-few-enough-tools-to-choose-from"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-D017: Context footprint estimate",
            "url": "https://agentexperience.tech/checks/axc-d017/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-github-mcp-output-schemas",
      "url": "https://agentexperience.tech/changes/#change-github-mcp-output-schemas",
      "external_url": "https://github.com/github/github-mcp-server/releases/tag/v2.0.0",
      "title": "GitHub MCP Server 2.0 adds output schemas, sent only to clients that can read them",
      "content_text": "Version 2.0.0 of GitHub's MCP server adds typed output schemas to its tools. The release notes say the schemas are only advertised to clients that declare support for the MCP specification of 2026-07-28 or later, so older clients are not handed a contract they cannot read.",
      "date_published": "2026-10-06T00:00:00Z",
      "tags": [
        "schema-enum",
        "code-mode"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Large APIs and tool catalogues",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://github.com/github/github-mcp-server/releases/tag/v2.0.0",
            "label": "github-mcp-server v2.0.0 release notes"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Write tool descriptions an agent can act on",
            "url": "https://agentexperience.tech/insights/tool-descriptions/"
          },
          {
            "kind": "Rubric check",
            "label": "READ-04: Each tool is fully described",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#read-04-each-tool-is-fully-described"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-D019: Example does not match the schema",
            "url": "https://agentexperience.tech/checks/axc-d019/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-mcpacific",
      "url": "https://agentexperience.tech/changes/#change-mcpacific",
      "external_url": "https://arxiv.org/abs/2610.05319",
      "title": "Preprint maps 1.3 million MCP tool specifications",
      "content_text": "Tang, Chen, Yue and Xiao collected 124,267 unique MCP servers from 17 marketplaces and extracted 1,328,233 tool specifications. Their claim is that 98.5% of tools have at least one functional alternative, and that showing candidates through a capability taxonomy instead of a flat list raised task completion for all four models tested, by up to 12 points on crowded candidate sets.",
      "date_published": "2026-10-04T00:00:00Z",
      "tags": [
        "discovery",
        "selection"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Large APIs and tool catalogues",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2610.05319",
            "label": "arXiv 2610.05319"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Agent tool catalogues need a pruning strategy",
            "url": "https://agentexperience.tech/insights/agent-tool-catalogs/"
          },
          {
            "kind": "Rubric check",
            "label": "FIND-06: There are few enough tools to choose from",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#find-06-there-are-few-enough-tools-to-choose-from"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-D013: Near-duplicate descriptions",
            "url": "https://agentexperience.tech/checks/axc-d013/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-cloudflare-cf-cli",
      "url": "https://agentexperience.tech/changes/#change-cloudflare-cf-cli",
      "external_url": "https://blog.cloudflare.com/cloudflare-cf-cli-launch/",
      "title": "Cloudflare launches cf, a CLI for its whole API, built with agents in mind",
      "content_text": "Cloudflare released `cf` as an open beta. The launch post says it covers the Cloudflare API surface of over 3,000 operations and makes JSON the default interface. Cloudflare's agent guide suggests a one-line instruction for a user-level AGENTS.md or CLAUDE.md that tells agents to use `cf`. Vendor claim: The launch post says agents accounted for 48% of use of Cloudflare's older Wrangler CLI in the week before launch, up from about a quarter in March 2026. This is Cloudflare's own figure, without a published method.",
      "date_published": "2026-09-28T00:00:00Z",
      "tags": [
        "discovery",
        "non-interactive",
        "agents-md"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Large APIs and tool catalogues",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": "The launch post says agents accounted for 48% of use of Cloudflare's older Wrangler CLI in the week before launch, up from about a quarter in March 2026. This is Cloudflare's own figure, without a published method.",
        "sources": [
          {
            "url": "https://blog.cloudflare.com/cloudflare-cf-cli-launch/",
            "label": "Cloudflare blog, cf launch"
          },
          {
            "url": "https://developers.cloudflare.com/cf/agents/",
            "label": "Use cf with coding agents (Cloudflare docs)"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Agent tool catalogues need a pruning strategy",
            "url": "https://agentexperience.tech/insights/agent-tool-catalogs/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-07: There is a direct route, not only clicks",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-07-there-is-a-direct-route-not-only-clicks"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-C006: No machine-readable output flag",
            "url": "https://agentexperience.tech/checks/axc-c006/"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0033: Vendor claim: agents were 48% of Wrangler CLI use",
            "url": "https://agentexperience.tech/evidence/ev-0033/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-cloudflare-forge",
      "url": "https://agentexperience.tech/changes/#change-cloudflare-forge",
      "external_url": "https://blog.cloudflare.com/forge-open-source-generation-pipeline/",
      "title": "Cloudflare open-sources Forge, the pipeline that generates cf",
      "content_text": "Forge reads annotated OpenAPI descriptions and already generates what the `cf` CLI needs. Cloudflare says it will also power its API documentation and SDKs, and lists other input formats and SDK languages as planned, not shipped.",
      "date_published": "2026-09-28T00:00:00Z",
      "tags": [
        "description",
        "schema-enum",
        "drift"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Large APIs and tool catalogues",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://blog.cloudflare.com/forge-open-source-generation-pipeline/",
            "label": "Cloudflare blog, Introducing Forge"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Write tool descriptions an agent can act on",
            "url": "https://agentexperience.tech/insights/tool-descriptions/"
          },
          {
            "kind": "Rubric check",
            "label": "READ-04: Each tool is fully described",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#read-04-each-tool-is-fully-described"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-D007: Closed vocabulary hinted in prose, not declared as an enum",
            "url": "https://agentexperience.tech/checks/axc-d007/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-eve-requester-approval",
      "url": "https://agentexperience.tech/changes/#change-eve-requester-approval",
      "external_url": "https://github.com/vercel/eve/releases/tag/eve%400.72.0",
      "title": "eve binds an approval to the person who asked for the call",
      "content_text": "In eve 0.72.0, Vercel's open agent framework, an approval without a response policy can now be approved or cancelled only by the person whose turn requested the call. A tool that needs a different approver has to say so in its approval policy.",
      "date_published": "2026-10-07T00:00:00Z",
      "tags": [
        "approval"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://github.com/vercel/eve/releases/tag/eve%400.72.0",
            "label": "eve 0.72.0 release notes"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-02: Your system enforces approval",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-02-your-system-enforces-approval"
          },
          {
            "kind": "Rubric check",
            "label": "HANDBACK-04: Approvals are few and show the real action",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#handback-04-approvals-are-few-and-show-the-real-action"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-supabase-scoped-tokens",
      "url": "https://agentexperience.tech/changes/#change-supabase-scoped-tokens",
      "external_url": "https://supabase.com/changelog/scoped-personal-access-tokens-ga",
      "title": "Supabase scoped access tokens reach general availability, and a refusal names what is missing",
      "content_text": "Supabase's scoped personal access tokens are now available to everyone. A token's access cannot be changed after it is created, a 403 response lists the permissions the token lacks in a `missing_permissions` array, and the dashboard shows which MCP tools a token can call. Existing account-level tokens keep working.",
      "date_published": "2026-10-06T00:00:00Z",
      "tags": [
        "auth-scopes",
        "error-recovery"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://supabase.com/changelog/scoped-personal-access-tokens-ga",
            "label": "Supabase changelog, scoped PATs GA"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Agent error recovery: design the path back",
            "url": "https://agentexperience.tech/insights/design-for-recovery/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-05: Agent access can be narrow",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-05-agent-access-can-be-narrow"
          },
          {
            "kind": "Rubric check",
            "label": "RECOVER-02: Errors say how to succeed",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#recover-02-errors-say-how-to-succeed"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-C004: Error does not name a next step",
            "url": "https://agentexperience.tech/checks/axc-c004/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-permission-decisions",
      "url": "https://agentexperience.tech/changes/#change-permission-decisions",
      "external_url": "https://arxiv.org/abs/2610.06047",
      "title": "Preprint: how practitioners decide what an agent may do",
      "content_text": "Salerno and colleagues interviewed 18 practitioners and surveyed 115. Their recommendations: make consequential actions easier to review, separate what an agent is allowed to do from what the user intended, make reversibility clearer, do not treat repeated approvals as stable preferences, and tell apart rejecting one action from rejecting a whole approach.",
      "date_published": "2026-10-05T00:00:00Z",
      "tags": [
        "approval",
        "confirmation"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2610.06047",
            "label": "arXiv 2610.06047"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "HANDBACK-04: Approvals are few and show the real action",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#handback-04-approvals-are-few-and-show-the-real-action"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-supabase-elicitations",
      "url": "https://agentexperience.tech/changes/#change-supabase-elicitations",
      "external_url": "https://supabase.com/docs/guides/ai-tools/mcp#elicitations",
      "title": "Supabase MCP asks for confirmation before cost and destructive SQL",
      "content_text": "Announced at Supabase Select, the Supabase MCP server uses MCP elicitations to show a confirmation form before `create_project` or `create_branch` incurs a cost, and before destructive SQL through `execute_sql` or `apply_migration` outside read-only mode. Supabase's own docs say to treat elicitations as a guardrail, not a guarantee: they can be switched off per tool, and some clients answer them automatically.",
      "date_published": "2026-10-02T00:00:00Z",
      "tags": [
        "confirmation",
        "approval"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://supabase.com/docs/guides/ai-tools/mcp#elicitations",
            "label": "Supabase MCP docs, Elicitations"
          },
          {
            "url": "https://supabase.com/blog/supabase-select-2026-recap",
            "label": "Supabase Select recap"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-01: Effects are stated before the step",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-01-effects-are-stated-before-the-step"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-02: Your system enforces approval",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-02-your-system-enforces-approval"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-D009: Side-effect annotation contradicts the description",
            "url": "https://agentexperience.tech/checks/axc-d009/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-supabase-secrets",
      "url": "https://agentexperience.tech/changes/#change-supabase-secrets",
      "external_url": "https://supabase.com/docs/guides/ai-tools/mcp#elicitations",
      "title": "Supabase keeps secret values out of the conversation",
      "content_text": "For Edge Function secrets, the Supabase MCP server asks the person to type the value in the Supabase Dashboard through a URL-mode elicitation. The docs say secret values belong in the Dashboard, 'never in chat, model input, or MCP tool arguments'.",
      "date_published": "2026-10-02T00:00:00Z",
      "tags": [
        "secrets",
        "handoff"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://supabase.com/docs/guides/ai-tools/mcp#elicitations",
            "label": "Supabase MCP docs, Elicitations"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-05: Agent access can be narrow",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-05-agent-access-can-be-narrow"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0038: Dry-run output printed secrets until a fix redacted them",
            "url": "https://agentexperience.tech/evidence/ev-0038/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-neon-explain-default",
      "url": "https://agentexperience.tech/changes/#change-neon-explain-default",
      "external_url": "https://github.com/neondatabase/mcp-server-neon/pull/367",
      "title": "Neon makes a query-plan tool safe by default and corrects its annotations",
      "content_text": "The `explain_sql_statement` tool in Neon's MCP server defaulted to `EXPLAIN ANALYZE`, which PostgreSQL executes. A merged change makes plain `EXPLAIN` the default and corrects the tool's annotations, which had described it as read-only, non-destructive and idempotent.",
      "date_published": "2026-09-30T00:00:00Z",
      "tags": [
        "description",
        "confirmation"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://github.com/neondatabase/mcp-server-neon/pull/367",
            "label": "neondatabase/mcp-server-neon pull request #367"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Write tool descriptions an agent can act on",
            "url": "https://agentexperience.tech/insights/tool-descriptions/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-01: Effects are stated before the step",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-01-effects-are-stated-before-the-step"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-D009: Side-effect annotation contradicts the description",
            "url": "https://agentexperience.tech/checks/axc-d009/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-vercel-agent-credentials",
      "url": "https://agentexperience.tech/changes/#change-vercel-agent-credentials",
      "external_url": "https://vercel.com/changelog/vercel-agent-now-installs-private-packages-from-npm-and-custom-registries",
      "title": "Vercel Agent keeps registry credentials outside its sandbox",
      "content_text": "Vercel Agent sessions can now install private npm packages using team-shared variables, and the changelog says 'credential values stay outside the sandbox, so the agent cannot read them'. In the same fortnight Vercel Sandbox gained persistent Drives (public beta, 23 September) and private networking through Secure Compute for Enterprise teams (30 September).",
      "date_published": "2026-09-30T00:00:00Z",
      "tags": [
        "secrets",
        "auth-scopes"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://vercel.com/changelog/vercel-agent-now-installs-private-packages-from-npm-and-custom-registries",
            "label": "Vercel changelog, private packages"
          },
          {
            "url": "https://vercel.com/changelog/drives-for-vercel-sandbox-are-now-in-public-beta",
            "label": "Vercel changelog, Sandbox Drives"
          },
          {
            "url": "https://vercel.com/changelog/vercel-sandbox-now-supports-secure-compute",
            "label": "Vercel changelog, Sandbox Secure Compute"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-05: Agent access can be narrow",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-05-agent-access-can-be-narrow"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-vercel-connect-providers",
      "url": "https://agentexperience.tech/changes/#change-vercel-connect-providers",
      "external_url": "https://vercel.com/changelog/vercel-connect-service-submissions",
      "title": "Vercel Connect opens to third-party services and lists what they must support",
      "content_text": "Any service can now submit itself to the Vercel Connect directory, which brokers short-lived OAuth access for agents; Vercel reviews each submission. The provider documentation sorts OAuth features into required (authorisation server metadata through RFC 8414 or OpenID Connect discovery, supported grant types, `expires_in`), recommended (dynamic client registration, PKCE, refresh tokens) and optional (for example RFC 9728 protected resource metadata).",
      "date_published": "2026-09-29T00:00:00Z",
      "tags": [
        "auth-scopes",
        "secrets",
        "discovery"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://vercel.com/changelog/vercel-connect-service-submissions",
            "label": "Vercel changelog, Connect service submissions"
          },
          {
            "url": "https://vercel.com/docs/connect/providers",
            "label": "Vercel docs, Connect providers"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-05: Agent access can be narrow",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-05-agent-access-can-be-narrow"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-stripe-link-agents",
      "url": "https://agentexperience.tech/changes/#change-stripe-link-agents",
      "external_url": "https://stripe.com/blog/helping-personal-agents-shop-more-intelligently-and-reliably-with-link",
      "title": "Stripe Link for personal agents: the person approves, then the agent pays",
      "content_text": "Stripe's Link wallet for personal agents, for consumers in the US and Canada, has the agent create a spend request that the customer approves on the Link website or mobile app. The launch post shows a failure returned with a structured next step the agent can act on. Vendor claim: Stripe says agentic purchases made with Link rose 38 times over the past month. Vendor claim, with no published method.",
      "date_published": "2026-09-29T00:00:00Z",
      "tags": [
        "approval",
        "error-recovery"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": "Stripe says agentic purchases made with Link rose 38 times over the past month. Vendor claim, with no published method.",
        "sources": [
          {
            "url": "https://stripe.com/blog/helping-personal-agents-shop-more-intelligently-and-reliably-with-link",
            "label": "Stripe blog, Link for personal agents"
          },
          {
            "url": "https://docs.stripe.com/agentic-commerce/agents/link-agent-wallet/use-link-wallet-pay-online",
            "label": "Stripe docs, Link agent wallet"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-02: Your system enforces approval",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-02-your-system-enforces-approval"
          },
          {
            "kind": "Rubric check",
            "label": "RECOVER-02: Errors say how to succeed",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#recover-02-errors-say-how-to-succeed"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-consent-outlives-context",
      "url": "https://agentexperience.tech/changes/#change-consent-outlives-context",
      "external_url": "https://arxiv.org/abs/2609.33910",
      "title": "Preprint: approvals that outlive their task raise attack success",
      "content_text": "Zhang and colleagues report that approvals persisted beyond the context that justified them raised prompt-injection attack success by up to 35.1 percentage points on 508 AgentDojo cases, and by 24.9 points in live tests on three production coding agents (the paper's claim).",
      "date_published": "2026-09-27T00:00:00Z",
      "tags": [
        "approval",
        "prompt-injection"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2609.33910",
            "label": "arXiv 2609.33910"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-02: Your system enforces approval",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-02-your-system-enforces-approval"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0015: Approvals that outlive their task raise attack success",
            "url": "https://agentexperience.tech/evidence/ev-0015/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-vercel-connect-consent",
      "url": "https://agentexperience.tech/changes/#change-vercel-connect-consent",
      "external_url": "https://vercel.com/changelog/vercel-connect-tanstack-ai",
      "title": "Vercel Connect sends a consent problem to the person, not the model",
      "content_text": "Vercel Connect's support for TanStack AI checks consent before the model runs. The changelog explains why: otherwise 'a consent error raised within a tool call would reach the model as an error string rather than the user as a redirect'.",
      "date_published": "2026-09-24T00:00:00Z",
      "tags": [
        "auth-scopes",
        "handoff"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://vercel.com/changelog/vercel-connect-tanstack-ai",
            "label": "Vercel changelog, Connect for TanStack AI"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Agent context handoff: carry the reason for the work",
            "url": "https://agentexperience.tech/insights/preserve-context-through-handoffs/"
          },
          {
            "kind": "Rubric check",
            "label": "RECOVER-02: Errors say how to succeed",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#recover-02-errors-say-how-to-succeed"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-approval-laundering",
      "url": "https://agentexperience.tech/changes/#change-approval-laundering",
      "external_url": "https://arxiv.org/abs/2609.28586",
      "title": "Preprint: approval records miss what a command goes on to do",
      "content_text": "Zhang and colleagues compared coding-agent approval records with execution traces. Across 111 pairs, effects left out of the record fell from 40 with explicit fields to 17 with command semantics and 13 with decision-time metadata (the paper's claim).",
      "date_published": "2026-09-23T00:00:00Z",
      "tags": [
        "approval",
        "confirmation"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Approval, confirmation and access",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2609.28586",
            "label": "arXiv 2609.28586"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "HANDBACK-04: Approvals are few and show the real action",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#handback-04-approvals-are-few-and-show-the-real-action"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0016: Approval records omit the effects a command goes on to trigger",
            "url": "https://agentexperience.tech/evidence/ev-0016/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-benchmark-contract-audit",
      "url": "https://agentexperience.tech/changes/#change-benchmark-contract-audit",
      "external_url": "https://arxiv.org/abs/2609.37315",
      "title": "Preprint: agent benchmarks that trust their own simulated tools",
      "content_text": "Bellibatlu, Wang and Zhang treated the advertised behaviour of benchmark tools as a contract and checked the code against it. Across 34 mutating tools in four benchmarks they confirmed seven tool defects and one evaluator property, including a clinical benchmark whose tool reports writes that never happen (the paper's claim).",
      "date_published": "2026-09-29T00:00:00Z",
      "tags": [
        "evaluation",
        "false-success"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Exit codes, errors and false success",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2609.37315",
            "label": "arXiv 2609.37315"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Evaluate the decisions in an agent workflow",
            "url": "https://agentexperience.tech/insights/evaluating-agent-workflows/"
          },
          {
            "kind": "Guide",
            "label": "Agent evaluation loop: run, judge, triage, fix, repeat",
            "url": "https://agentexperience.tech/insights/build-a-reliable-agent-evaluation-loop/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-cf-aborted-exit-zero",
      "url": "https://agentexperience.tech/changes/#change-cf-aborted-exit-zero",
      "external_url": "https://developers.cloudflare.com/cf/agents/",
      "title": "Cloudflare documents that a refused deletion exits with status 0",
      "content_text": "Cloudflare's agent guide for `cf` says that in a non-interactive session a destructive command without `--force` prints 'Aborted.' to standard error and exits with status 0, and warns that a successful exit does not mean the resource was deleted. An open issue, cloudflare/cf#94, asks for a non-zero exit.",
      "date_published": "2026-09-29T00:00:00Z",
      "tags": [
        "exit-codes",
        "false-success",
        "non-interactive",
        "confirmation"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Exit codes, errors and false success",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://developers.cloudflare.com/cf/agents/",
            "label": "Use cf with coding agents (Cloudflare docs)"
          },
          {
            "url": "https://github.com/cloudflare/cf/issues/94",
            "label": "cloudflare/cf issue #94"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Agent error recovery: design the path back",
            "url": "https://agentexperience.tech/insights/design-for-recovery/"
          },
          {
            "kind": "Rubric check",
            "label": "RECOVER-03: The agent can check what happened",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#recover-03-the-agent-can-check-what-happened"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-C002: Error exits with status 0",
            "url": "https://agentexperience.tech/checks/axc-c002/"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0036: A CLI exits 0 when a destructive command is refused",
            "url": "https://agentexperience.tech/evidence/ev-0036/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-developer-error-messages",
      "url": "https://agentexperience.tech/changes/#change-developer-error-messages",
      "external_url": "https://arxiv.org/abs/2609.35381",
      "title": "Preprint: error messages written for developers hurt capable agents most",
      "content_text": "Xu and Wu tested five OpenAI models. An expired-credential error that named a terminal command left 45% of tasks recovered; naming the server's login tool raised that to 84%. On rate limits, naming the call to repeat raised recovery from 6% to 88% (the paper's claim).",
      "date_published": "2026-09-28T00:00:00Z",
      "tags": [
        "error-recovery",
        "description"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Exit codes, errors and false success",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2609.35381",
            "label": "arXiv 2609.35381"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Agent error recovery: design the path back",
            "url": "https://agentexperience.tech/insights/design-for-recovery/"
          },
          {
            "kind": "Rubric check",
            "label": "RECOVER-02: Errors say how to succeed",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#recover-02-errors-say-how-to-succeed"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-C004: Error does not name a next step",
            "url": "https://agentexperience.tech/checks/axc-c004/"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0003: Error text that names the next tool lifts recovery",
            "url": "https://agentexperience.tech/evidence/ev-0003/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-failure-transparent-agents",
      "url": "https://agentexperience.tech/changes/#change-failure-transparent-agents",
      "external_url": "https://arxiv.org/abs/2609.35732",
      "title": "Preprint: an evidence contract cuts false reports of success",
      "content_text": "Zhu and colleagues report that after a required tool failed, six models falsely reported success in 22.8% of responses by default, 9.3% with a transparency instruction and 0.8% with a structured evidence contract (the paper's claim).",
      "date_published": "2026-09-28T00:00:00Z",
      "tags": [
        "false-success",
        "evaluation"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Exit codes, errors and false success",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2609.35732",
            "label": "arXiv 2609.35732"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Record retries as product history",
            "url": "https://agentexperience.tech/insights/retries-are-product-history/"
          },
          {
            "kind": "Rubric check",
            "label": "HANDBACK-01: The person has a record",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#handback-01-the-person-has-a-record"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0006: An evidence contract cuts false-success reports after tool failures",
            "url": "https://agentexperience.tech/evidence/ev-0006/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-limbo-idempotency",
      "url": "https://agentexperience.tech/changes/#change-limbo-idempotency",
      "external_url": "https://arxiv.org/abs/2609.29095",
      "title": "Preprint: idempotency keys cut duplicate writes by agents",
      "content_text": "In LIMBO, Li reports that offering an idempotency key on every write cut duplicate side effects from 28% to 4% of episodes, because agents use keys when they exist, and that agents reported success in 90% of the episodes in which they had duplicated an effect (the paper's claim).",
      "date_published": "2026-09-24T00:00:00Z",
      "tags": [
        "idempotency",
        "false-success"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Exit codes, errors and false success",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2609.29095",
            "label": "arXiv 2609.29095"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Record retries as product history",
            "url": "https://agentexperience.tech/insights/retries-are-product-history/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-03: Writes are safe to retry",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-03-writes-are-safe-to-retry"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0005: Idempotency keys cut duplicate writes from 28% to 4%",
            "url": "https://agentexperience.tech/evidence/ev-0005/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-vercel-plugin-drift",
      "url": "https://agentexperience.tech/changes/#change-vercel-plugin-drift",
      "external_url": "https://github.com/vercel/vercel-plugin/pull/306",
      "title": "Vercel's agent plugin fixes instructions that drifted from reality",
      "content_text": "Merged pull requests in vercel/vercel-plugin corrected agent instructions that no longer matched reality. Pull request #306 removed a tip recommending a package that is not published on npm and fixed AI SDK version claims. Pull request #307, merged on 6 October, stopped plugin instructions advertising interactive deployment cards that the production MCP server does not expose.",
      "date_published": "2026-10-05T00:00:00Z",
      "tags": [
        "drift",
        "skills"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Instructions, skills and drift",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://github.com/vercel/vercel-plugin/pull/306",
            "label": "vercel/vercel-plugin pull request #306"
          },
          {
            "url": "https://github.com/vercel/vercel-plugin/pull/307",
            "label": "vercel/vercel-plugin pull request #307"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Write agent-readable documentation",
            "url": "https://agentexperience.tech/insights/make-documentation-legible/"
          },
          {
            "kind": "Rubric check",
            "label": "BOUND-03: Your signals agree",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#bound-03-your-signals-agree"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-F003: Claimed npm package does not exist",
            "url": "https://agentexperience.tech/checks/axc-f003/"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-F006: Claimed MCP tool is not served",
            "url": "https://agentexperience.tech/checks/axc-f006/"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0040: Agent skills recommended a package that does not exist",
            "url": "https://agentexperience.tech/evidence/ev-0040/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-skill-evolution",
      "url": "https://agentexperience.tech/changes/#change-skill-evolution",
      "external_url": "https://arxiv.org/abs/2610.04832",
      "title": "Preprint: skill rules that name a command change what agents do",
      "content_text": "Wang and colleagues studied revisions to 3,159 skills. Adding a checkable rule raised the rate at which four coding agents took the required action by +0.23 on average, with most of the gain coming from rules that name a command or path the old skill did not mention (the paper's claim).",
      "date_published": "2026-10-04T00:00:00Z",
      "tags": [
        "skills",
        "description"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Instructions, skills and drift",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2610.04832",
            "label": "arXiv 2610.04832"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Write agent-readable documentation",
            "url": "https://agentexperience.tech/insights/make-documentation-legible/"
          },
          {
            "kind": "Rubric check",
            "label": "READ-10: Repository instructions give commands and limits",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#read-10-repository-instructions-give-commands-and-limits"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0018: Skill rules that name a command or path change what agents do",
            "url": "https://agentexperience.tech/evidence/ev-0018/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-state-of-agent-skills",
      "url": "https://agentexperience.tech/changes/#change-state-of-agent-skills",
      "external_url": "https://vercel.com/blog/state-of-agent-skills",
      "title": "Vercel predicts skills will be judged by tests, not installs",
      "content_text": "Vercel published a report on its skills.sh registry and predicted that 'the measure of a skill will also shift from popularity to effectiveness', with tests and benchmarks to match. Vendor claim: Vercel says the registry reached one million skills and nearly 280 million installs in the seven months to August, and that 375 skills (0.04%) account for 62% of installs. Vercel notes that its install counters do not represent unique people.",
      "date_published": "2026-09-25T00:00:00Z",
      "tags": [
        "skills",
        "measurement"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Instructions, skills and drift",
        "evidence_class": "vendor-claim",
        "evidence_class_label": "Vendor claim",
        "vendor_claim": "Vercel says the registry reached one million skills and nearly 280 million installs in the seven months to August, and that 375 skills (0.04%) account for 62% of installs. Vercel notes that its install counters do not represent unique people.",
        "sources": [
          {
            "url": "https://vercel.com/blog/state-of-agent-skills",
            "label": "Vercel blog, State of agent skills"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "How do you measure agent experience?",
            "url": "https://agentexperience.tech/insights/measure-agent-experience/"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-D022: SKILL.md frontmatter missing or invalid",
            "url": "https://agentexperience.tech/checks/axc-d022/"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-D024: Skill description over 1,024 characters",
            "url": "https://agentexperience.tech/checks/axc-d024/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-mcp-server-cards",
      "url": "https://agentexperience.tech/changes/#change-mcp-server-cards",
      "external_url": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2127",
      "title": "MCP Server Cards proposal merged as Final, with the card format still experimental",
      "content_text": "SEP-2127, which defines Server Cards (static metadata a client can read before it connects, with `<server URL>/server-card` as the recommended location), was merged on 6 October with the status Final, as an optional extension. The SEP leaves the wire format to a separate extension repository, which still described itself as experimental, and its discovery document as a draft, when last updated.",
      "date_published": "2026-10-06T00:00:00Z",
      "tags": [
        "server-cards",
        "discovery"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Discovery, standards and starting without an account",
        "evidence_class": "specification",
        "evidence_class_label": "Specification",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2127",
            "label": "modelcontextprotocol pull request #2127"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Agentic Resource Discovery, implemented",
            "url": "https://agentexperience.tech/insights/agentic-resource-discovery/"
          },
          {
            "kind": "Guide",
            "label": "The state of agent-web standards",
            "url": "https://agentexperience.tech/insights/agent-web-standards/"
          },
          {
            "kind": "Rubric check",
            "label": "FIND-05: APIs and tools are described where agents look",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#find-05-apis-and-tools-are-described-where-agents-look"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-F006: Claimed MCP tool is not served",
            "url": "https://agentexperience.tech/checks/axc-f006/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-mcp-local-server-security",
      "url": "https://agentexperience.tech/changes/#change-mcp-local-server-security",
      "external_url": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/3072",
      "title": "MCP documentation adds a security guide for local servers",
      "content_text": "A local server security guide was merged into the MCP documentation. It says 'the stdio transport is not a sandbox' and that a local MCP server is not a plugin running inside a sandbox the protocol provides.",
      "date_published": "2026-10-05T00:00:00Z",
      "tags": [
        "prompt-injection",
        "secrets"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Discovery, standards and starting without an account",
        "evidence_class": "specification",
        "evidence_class_label": "Specification",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/3072",
            "label": "modelcontextprotocol pull request #3072"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Human approval workflows for AI agents",
            "url": "https://agentexperience.tech/insights/approval-is-a-workflow/"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-05: Agent access can be narrow",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-05-agent-access-can-be-narrow"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-clerk-accountless",
      "url": "https://agentexperience.tech/changes/#change-clerk-accountless",
      "external_url": "https://clerk.com/blog/accountless-setup-clerk-init-nextjs",
      "title": "Clerk lets an agent start an app before anyone signs up",
      "content_text": "Run while signed out, Clerk's CLI creates an accountless development application that is not attached to any account yet, and it runs without prompting when it detects a non-interactive agent environment. The missing-key error names the exact command to run next. Claiming the application stays a step for the person.",
      "date_published": "2026-09-30T00:00:00Z",
      "tags": [
        "claim-later-onboarding",
        "non-interactive",
        "error-recovery"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Discovery, standards and starting without an account",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://clerk.com/blog/accountless-setup-clerk-init-nextjs",
            "label": "Clerk blog, accountless setup"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Agent error recovery: design the path back",
            "url": "https://agentexperience.tech/insights/design-for-recovery/"
          },
          {
            "kind": "Rubric check",
            "label": "RECOVER-02: Errors say how to succeed",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#recover-02-errors-say-how-to-succeed"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-C001: Command hangs without a terminal",
            "url": "https://agentexperience.tech/checks/axc-c001/"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-C004: Error does not name a next step",
            "url": "https://agentexperience.tech/checks/axc-c004/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-vercel-domain-search",
      "url": "https://agentexperience.tech/changes/#change-vercel-domain-search",
      "external_url": "https://vercel.com/changelog/search-domains-without-authentication",
      "title": "Vercel opens domain search without sign-in",
      "content_text": "Domain names, availability and pricing can now be checked through Vercel's CLI and API without signing in or an access token. Buying or managing a domain still needs authentication.",
      "date_published": "2026-09-28T00:00:00Z",
      "tags": [
        "claim-later-onboarding",
        "auth-scopes"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Discovery, standards and starting without an account",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://vercel.com/changelog/search-domains-without-authentication",
            "label": "Vercel changelog, domain search without authentication"
          }
        ],
        "affects": [
          {
            "kind": "Rubric check",
            "label": "FIND-01: The job's pages are open to the assistant",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#find-01-the-jobs-pages-are-open-to-the-assistant"
          },
          {
            "kind": "Rubric check",
            "label": "ACT-05: Agent access can be narrow",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#act-05-agent-access-can-be-narrow"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-citation-study",
      "url": "https://agentexperience.tech/changes/#change-citation-study",
      "external_url": "https://arxiv.org/abs/2609.35077",
      "title": "Preprint: page checklists showed no citation effect within a domain",
      "content_text": "Moore and Dunne studied about two million citations from AI answer engines. FAQ blocks, structured data and Core Web Vitals showed positive effects in pooled data that reversed or fell to zero once each domain was compared with itself (the paper's claim, from an observational study of B2B software pages).",
      "date_published": "2026-09-28T00:00:00Z",
      "tags": [
        "discovery",
        "measurement"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Discovery, standards and starting without an account",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2609.35077",
            "label": "arXiv 2609.35077"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "AX, UX, DX, and GEO: where each fits",
            "url": "https://agentexperience.tech/insights/ax-vs-ux-dx-geo/"
          },
          {
            "kind": "Guide",
            "label": "Does llms.txt actually work?",
            "url": "https://agentexperience.tech/insights/state-of-llms-txt/"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0013: FAQ blocks and structured data showed no citation effect within a domain",
            "url": "https://agentexperience.tech/evidence/ev-0013/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-microsoft-what-is-ax",
      "url": "https://agentexperience.tech/changes/#change-microsoft-what-is-ax",
      "external_url": "https://developer.microsoft.com/blog/what-is-agent-experience-ax/",
      "title": "Microsoft publishes 'What is Agent Experience (AX)?'",
      "content_text": "Microsoft's developer blog defines AX as 'the experience AI agents have when discovering, choosing, and using your technology', credits the term to Mathias Biilmann of Netlify (January 2025), and splits measurement into propensity (does the agent find your technology and choose it?) and efficacy (does it use it correctly?). Its argument: best practices are hypotheses until you measure them.",
      "date_published": "2026-10-06T00:00:00Z",
      "tags": [
        "measurement",
        "propensity",
        "evaluation"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Definitions and measurement",
        "evidence_class": "vendor-documentation",
        "evidence_class_label": "Vendor documentation",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://developer.microsoft.com/blog/what-is-agent-experience-ax/",
            "label": "Microsoft for Developers, What is Agent Experience (AX)?"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "What is Agent Experience?",
            "url": "https://agentexperience.tech/insights/what-is-agent-experience/"
          },
          {
            "kind": "Guide",
            "label": "How do you measure agent experience?",
            "url": "https://agentexperience.tech/insights/measure-agent-experience/"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0029: A warning that names the failing plan redirected agents; a tip did not",
            "url": "https://agentexperience.tech/evidence/ev-0029/"
          }
        ]
      }
    },
    {
      "id": "https://agentexperience.tech/changes/#change-tool-registry-rhetoric",
      "url": "https://agentexperience.tech/changes/#change-tool-registry-rhetoric",
      "external_url": "https://arxiv.org/abs/2605.23916",
      "title": "Preprint adds a preregistered test: praise and order move tool choice",
      "content_text": "A revised version of Wang and Zhang's paper adds a preregistered study with two small OpenAI models. Stacked praise in a tool listing raised its pick rate by about 43 percentage points, and with identical listings the first-listed tool was picked about 72 points more often (the paper's claim).",
      "date_published": "2026-09-30T00:00:00Z",
      "tags": [
        "selection",
        "description"
      ],
      "_ax": {
        "edition": "2026-10-07",
        "theme": "Definitions and measurement",
        "evidence_class": "preprint",
        "evidence_class_label": "Preprint",
        "vendor_claim": null,
        "sources": [
          {
            "url": "https://arxiv.org/abs/2605.23916",
            "label": "arXiv 2605.23916 (version 2)"
          }
        ],
        "affects": [
          {
            "kind": "Guide",
            "label": "Write tool descriptions an agent can act on",
            "url": "https://agentexperience.tech/insights/tool-descriptions/"
          },
          {
            "kind": "Rubric check",
            "label": "FIND-06: There are few enough tools to choose from",
            "url": "https://agentexperience.tech/insights/agent-readiness-rubric/#find-06-there-are-few-enough-tools-to-choose-from"
          },
          {
            "kind": "ax-check rule",
            "label": "AXC-D020: Promotional language in a description",
            "url": "https://agentexperience.tech/checks/axc-d020/"
          },
          {
            "kind": "Evidence record",
            "label": "EV-0020: Praise and list order move tool selection",
            "url": "https://agentexperience.tech/evidence/ev-0020/"
          }
        ]
      }
    }
  ]
}
