531 posts tagged with "AI agents"
AI agents and autonomous systems

Railway Sandboxes Are GA: The 3-Cent Agent Task and the Crossover Point for Self-Hosting
Railway Sandboxes went GA on every plan on September 17, 2026, with checkpoint-and-fork Linux VMs billed per second from shared plan credits. A 20-minute agent task costs about 3 cents — and the math crosses a flat-rate dedicated box near 90 tasks a day.

RunPod's Scale-to-Zero vs Lambda's Pay-for-the-Rental: The GPU Billing Math That Decides Whether to Rent or Own Inference
RunPod bills GPU inference per active second with zero idle cost, while Lambda Labs rents the whole instance by the hour. A duty-cycle cost model built on 2026 rates shows exactly where each wins, and where owning a Hetzner GPU box beats both.

Your Read-Only Tool Is the Sandbox Escape: What Claude Code's /proc/self/environ API-Key Leak Teaches About Agent Deploy Pipelines
Microsoft researchers hid instructions in a GitHub issue comment, steered Claude Code's Action to its unsandboxed Read tool, and walked out with a live API key. Here is the full four-step chain plus a 7-point audit for your own agent deploy pipeline.

Cloudflare Gave Every AI-Generated App Its Own SQLite Database — Here's What That Costs to Replicate on Machines You Own
Cloudflare's Durable Object Facets gives every AI-generated app its own isolated SQLite database. How the supervisor-plus-facet model works, why database-per-tenant beats shared RLS for generated code, and what the same guarantee costs on hardware you own.

CVE-2026-61560: How an Unauthenticated MCP Default Turned a File-Upload Tool Into Full GitLab Account Takeover
A CVSS 9.8 flaw in @zereight/mcp-gitlab chains an unauthenticated SSE transport, an unsanitized file path, and a credential in process memory into full GitLab account takeover. The exploit chain, why the default was the real bug, and a six-item hardening checklist for every MCP server you self-host.

Every Deploy Surface Is Shipping an MCP Server: What a PaaS's Agent Interface Must Expose (and What Keeps It Safe)
TeamCity, Dooor OS, and the PaaS scoreboard all converged on the same contract: a typed MCP tool surface over deploy, rollback, logs, and status. The minimum inventory a git-push PaaS must expose, and the four controls that make it production-safe.

Your Gateway's Next Feature Doesn't Need an Envoy Fork: What kgateway's Rust Dynamic Modules Actually Buy a Self-Hosted PaaS
kgateway's Rust dynamic modules run custom payload logic inside Envoy at native speed with no fork and no recompile. How the mechanism works, how it compares to Lua, Wasm, and ext_proc, and the three catches a self-hosted platform team should budget for.

10,000 MCP Servers and 97M Downloads Later, the Bottleneck Is Discovery
MCP passed 10,000 public servers and 97M monthly SDK downloads, so the hard problem is no longer the protocol — it is discovery and trust. What Arcade's brokered runtime and the Coolify agent bridges teach a self-hosted PaaS about shipping a deploy, rollback, and logs server that agents can find and be trusted with.

Half a Billion Downloads Get a Diploma: What MCP's First Certification (MCPA) Signals for Platform Teams
The Agentic AI Foundation's MCPA exam arrives as MCP SDK downloads near half a billion a month. What the blueprint's 50% ops-and-security weighting tells platform teams, what the credential doesn't prove, and three moves to make this quarter.