← All issues

The Agentic Index Brief

July 4 to July 11, 2026 · Published July 11, 2026

The week in one line

Two security researchers publicly broke two agentic coding platforms this week. One vendor patched within days. The other said the behavior was working as designed. How a vendor answers the disclosure call just became part of the spec sheet.

Theme 1: The disclosure era begins

Last issue was about vendors shipping governance features. This week, the market received its first public red-team scorecards, and the results split neatly in two.

Cybersecurity firm Wiz disclosed GhostApproval, a technique that uses symbolic links inside malicious repositories to trick AI coding assistants into modifying files outside their intended workspaces. Several vendors patched. Augment Code disputed the vulnerability classification entirely, arguing that agents inherently operate under user credentials and that file-system sandboxing is a shared responsibility. No patch. No isolation fix. More of a philosophical disagreement with the concept of boundaries.

Days earlier, researchers at Sand Security disclosed WriteOut, a session-isolation flaw in Writer's managed sandbox that allowed agent previews to leak session tokens across tenants. Writer deployed a server-side patch promptly, removed credentials from sandbox previews, isolated the preview origin, and confirmed that no customer data was compromised.

Both vendor positions are technically defensible. They are not remotely equivalent from a procurement chair. One says, "We fixed it." The other says, "Please forward this to your endpoint team."

The supporting cast reinforces the shift. ThreatModeler shipped curated threat libraries mapping agentic tool compromise and MCP vulnerabilities to MITRE ATLAS and OWASP Agentic AI Threats, which means the threat-modeling industry now has standard taxonomies for attacking agents. Progress, of a sort.

Assail also released Sidewinder, a redesign of its offensive-security platform built around 12 autonomous agents that continuously pentest, audit their own work, and repair their own mistakes. The attackers are agentic now too. Symmetry is beautiful, except in security.

Our read: the era of agent platforms being tested in public has begun, and it will not stop. Vendor security posture is no longer just "Do you have guardrails?" It is also "What did you do the last time a researcher called?"

Buyer question this week: ask every coding-agent vendor two things: what files can your agent touch outside the workspace, and what is your disclosure-response record? A vendor that has never been publicly tested is not necessarily safer than one that patched quickly. It may simply be earlier in the queue.

Theme 2: The enterprise CLI land grab

Enterprise platforms spent this week building interfaces for a new user: your coding agent.

UiPath opened a public preview of UiPath for Coding Agents, introducing a new uip CLI and a set of skills that let Claude Code, Cursor, and Codex CLI build automations, orchestrate tests, and manage a UiPath organization in natural language.

In the same window, UiPath upgraded Autopilot into a fully autonomous coding agent inside Studio, moved Document Understanding to per-operation billing, and shipped its July cloud updates. Four releases in four business days, for anyone still keeping score after last issue's Copilot streak.

SAP released a Joule Studio extension for VS Code and a new CLI, extending its agent tooling from low-code users to professional engineering teams and CI/CD pipelines.

Ramp launched Ramp for Agents: incorporate a business, apply for corporate cards, and stand up a finance stack from a single prompt, backed by an MCP integration and a CLI with more than 50 finance playbooks. Day-zero incorporation via prompt is either the future of company formation or a very efficient way to generate Delaware paperwork.

Add HubSpot's Agent CLI beta from the prior window and the pattern is unmistakable: systems of record are concluding that the next buyer persona types --help.

Our read: if a platform cannot be driven by a coding agent, it is becoming invisible to a growing share of enterprise workflows. Expect every major system of record to ship a CLI-plus-MCP pair by year-end, followed shortly by "agent accessibility" appearing on RFPs as though it had always been there.

Theme 3: The meter is running

UiPath restructured its AI Unit consumption model for Document Understanding: digitization is now free, while classification and extraction are billed per operation rather than at a flat per-page rate.

Box published documentation clarifying exactly which agentic actions consume AI Units, ahead of daily AI usage limits it begins enforcing this month.

And last issue, GitHub introduced AI credit session limits in the Copilot CLI and SDK.

Three vendors, three weeks, one direction: metered AI consumption, published unit tables, and hard caps are becoming standard kit.

Our read: usage-based AI billing is arriving faster than most procurement teams' forecasting models. Get the unit-consumption table before the pilot, not after the first invoice. The invoice is a much more expensive teacher.

Action item: assume symlinks are hostile

If your organization runs Augment Code, or any coding agent that operates under user credentials, treat third-party repositories as untrusted input.

The vendor has stated that it will not patch the GhostApproval symlink behavior, which means the mitigation burden sits with you: enforce strict endpoint controls, independently vet external code before it enters privileged environments, and assume that a malicious repository may be able to read from and write to locations outside the workspace.

This is not a drill with a deadline, like last issue's E2B cutover. It is a standing posture change, effective immediately. Very convenient for everyone except the people responsible for implementing it.

Also notable

  • Voice agents: Cartesia released Ink-2, a streaming speech-to-text model with native turn detection, removing the need for an external Voice Activity Detection module in voice-agent stacks.
  • Orchestration: Taskade launched TSK-1, a system kernel coordinating memory, multi-agent reasoning, and workflows while routing tasks across more than 15 models.
  • Agent identity: Stacklok added Enterprise-Managed Authorization to ToolHive, so every MCP tool call carries the identity of the user who initiated it, governed through Okta or Entra ID. Accountability, now with headers.
  • Email infrastructure: Infobip acquired SocketLabs, folding vendor-agnostic deliverability observability into its AI-powered Email Deliverability Agent.
  • Financial crime: Unit21 shipped the Agentic Task Builder, letting fraud and compliance teams create custom AI investigation tasks in plain English, with no engineering ticket required. A small miracle, by enterprise-software standards.
  • MSP automation: Thread took Super Magic to general availability, chaining multi-step service-desk work with a one-tap confirmation before any write.
  • Sandboxes: Unikraft introduced hardware-isolated microVMs that boot in milliseconds and scale to zero, aimed squarely at safely detonating untrusted agent tool calls.

The Agentic Index Brief is published weekly by Agentic Index, the verified directory of 892 agentic AI vendors. Compare platforms by capability at agenticindex.io/compare. Methodology at agenticindex.io/methodology.

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.