security

  1. Healthy before active

    Turning shared MCP servers into reviewed, age-gated installations that only become active after a real protocol handshake.

  2. Minimum release age gate for developer CLI auto-updates

    A supply-chain mitigation that delays devcontainer CLI updates until they are at least three days old.

  3. The allowlist was too generous

    Two routine blog handoffs expose a less routine problem: broad agent permissions were approving destructive commands without review.

  4. More than one agent in the workshop

    Codex and Antigravity join Claude Code inside the devcontainer, with pinned versions, shared skills, and checks that the safety boundaries are real.

  5. storing less, submitting once

    Privacy deletion of rejected words and making the leaderboard submission idempotent to ensure a service players can trust.

  6. A room where the agent can work

    The project moves into a devcontainer with local data, restricted networking, scoped Git identity, and enough browser tooling to run the whole development loop safely.