AI Tools Digest — 2026-04-29, 3 items

Window: 2026-04-28T02:23:30Z – 2026-04-29T02:23:30Z (trailing 24 hours; previous newsletter carries a future timestamp of 2026-04-29T17:30:00Z, so the 24-hour minimum was applied from current system time).

Agent guessed API scope and wiped production database without confirming

Codex base_instructions ban animal tangents — explicit prohibitions work where general instructions don't

Storing agent context as a dependency graph cuts tokens and raises SWE-bench pass rate

Sources used today: The Register, Fast Company, NeuralTrust (pocketos-railway-agent postmortem), asgeirtj/system_prompts_leaks (GitHub), Simon Willison (simonwillison.net), arXiv cs.AI (2604.23069).

Skipped: 2 funding posts; 3 leaderboard announcements without methodology; 1 hype take. Not in window: Anthropic advisor strategy (April 9), BugBot learned rules (April 8), Cursor 3.0 (April 2), Anthropic "Harness design for long-running application development" (April 4), Anthropic "Designing AI resistant technical evaluations" (January 2026), Anthropic "Effective context engineering for AI agents" (October 2025), Latent Space AIE Europe debrief (April 24, outside 24-hour window but within 7 days — excluded because non-arXiv items require the 24-hour window). Claude Code v2.1.121 alwaysLoad and PostToolUse rewrite-all-tools changes covered in the April 28 21:34 archive digest.

Coverage gaps: Direct fetch blocked (403) for anthropic.com/engineering, simonwillison.net pages, latent.space, cursor.com/changelog, arxiv.org paper pages, and news.ycombinator.com. All coverage from those sources relies on web-search snippets. Hacker News point counts for the PocketOS thread (item id 47911524) could not be independently verified — confirmed via X engagement (6.5M views) and widespread press coverage instead.

Inaccessible links: