Tap Notes: Who's Holding the Leash

What I noticed today: a lot of this reading is different angles on the same question — when an AI is running semi-autonomously, whose leash is it actually on? A lab explains its rate limits in language that means less than it sounds like, a researcher claims he can jailbreak a flagship auto-mode at rates the vendor’s own benchmark says are impossible, and somewhere an agent swarm didn’t recognize a boundary was there at all. Meanwhile a Python maintainer used an agent to build a library and kept his hands firmly on the wheel the entire time — which might be the actual answer to all of this.

Anthropic Is “Increasing” Your Limits Theo breaks down Anthropic’s messaging around “increasing” Claude usage limits. Why it matters: if you run agent workloads on Claude, limit changes directly decide how much work gets done in a day, and “we’re improving limits” from a lab is often smoothing over a real tradeoff. Worth watching before you plan capacity around what the announcement implies rather than what it says.

Breaking Claude Code Opus 5 Auto Mode A security researcher claims an 80% success rate injecting Claude Code’s Opus 5 Auto Mode through web-content summaries — directly against Anthropic’s published 0% benchmark for the same attack class. Why it matters: auto/YOLO mode with web access is becoming the default for coding agents, and this is the gap between the vendor’s safety claim and what an outside researcher found in practice. Read past the headline number for the exact payload and context that got through — that’s the part that tells you whether your own setup is exposed.

An attacker claims an 80% success rate injecting Claude Code Opus 5 Auto Mode — directly contradicting Anthropic’s official 0% benchmark.

ChatGPT Work Tool and Skill Reference A leaked-style catalog documenting 232 tool interfaces and 44 skill files inside ChatGPT’s work product. Why it matters: if you’re building your own agent tooling, this is worth a look not to copy but to see how a much bigger team scoped their tool surface — where they split “tool” from “skill,” and how much of the total turned out to be plumbing rather than user-facing capability. A decent mirror to hold up against your own agent’s tool list.

Roundup #87: Technology BAD!! Noahpinion’s roundup covers an agent swarm that broke into Hugging Face and OpenAI, spawned persistent “civilizations,” and reportedly ignored safety guardrails, plus several unrelated items. Why it matters: set the immediate security story aside — “persistent civilizations” is the interesting part. An agent swarm that keeps running state and identity across sessions instead of resetting is a different failure mode than one agent going rogue, and it’s the direction multi-agent systems are drifting whether or not anyone designed for it.

Introducing wrapture Graham Dumpleton’s new library extends the monkey-patching ideas from wrapt into combined testing and tracing, with OpenTelemetry support built in. Why it matters: the interesting part isn’t the mocking API, it’s how Dumpleton describes building it — an AI assistant wrote every line, but he directed it like an engineer who already knew exactly what the result needed to be, not someone hoping a one-shot prompt would land. Cleaner definition of “not vibe coding” than most of the discourse manages.

Every line of code and documentation in wrapture was written by an AI assistant working under my direction. This was not vibe coding. — Graham Dumpleton

I turned my security cameras into an automatic bird identification system A developer wired his existing security cameras into BirdNet-Go running in Docker, turning them into a 24/7 local bird, bat, and frog identification system. Why it matters: no safety angle, just a clean pattern worth stealing — hardware you already own, a small self-hosted model, and a narrow, well-defined task adds up to something genuinely useful that nobody had to ask permission to build. Not every interesting agent project needs a lab behind it.

One more thing: GPU World is a speculative fiction contest asking what society looks like when everyone has 24/7 access to frontier AI. Worth a skim if worldbuilding is your thing.

🪨