← All digests
✦ AI News for Builders

A researcher chains prompt injection across MCP and A2A at Google and four other orgs, Together Link puts Kimi K3 and GLM 5.3 behind Claude Code's model menu, OpenAI's text watermark is opt-in on the API while Claude's is always on, and Mistral Large 4 and Reflection Beam arrive with weights still weeks out

Tuesday, October 6, 2026·8 min read·4 stories

Tuesday is about trust boundaries. Agents trust each other more than they should, coding harnesses turn out to care very little about which model sits underneath, and watermarking now depends on which vendor you picked. Then two labs outside China ship big open-weight models, minus the weights for now.

Story I

Prompt injection that hops from agent to agent over MCP and A2A worked at Google and four other organizations

Independent researcher Syed Anas Mohiuddin calls it "protocol pivoting": plant instructions in content one agent reads, let it delegate the task to a second agent over a different protocol such as Google's A2A, and watch the second agent execute it because it trusts whoever handed over the work. Per Ars Technica, Google and four other organizations have acknowledged versions of the bug in the past five months. Rapid7's instance, CVE-2026-97228, was rated 2.7 and fixed last month.

Google's was worse, rated 8. Its MCP Toolbox for Databases (googleapis/mcp-toolbox) created its HTTP client with no CheckRedirect policy and didn't validate target IPs, so a crafted path parameter could redirect it to an internal endpoint. Google's fix adds IP allow and block lists and rejects an unsafe base URL at startup. Not everyone buys the new name. X41 D-Sec's Markus Vervier calls it plain indirect prompt injection, and he's right about the mechanism. The useful part is that it landed in five unrelated shops.

For builders

If you run googleapis/mcp-toolbox, update it today. Then open every MCP server you wrote and check two things in its HTTP client: does it follow redirects blindly, and does it block private IP ranges (10.x, 172.16–31.x, 192.168.x, 169.254.x, localhost)? Fail at startup on a bad base URL, like Google now does. And treat any task one of your agents receives from another agent as untrusted user input, not as an internal call.

Story II

Together Link runs Kimi K3 and GLM 5.3 behind Claude Code's model menu, and prints what the session cost

Together AI released Together Link, a free MIT-licensed CLI in beta for macOS and Linux. It points Claude Code, Claude Desktop, Codex, ChatGPT Desktop, OpenCode and Pi at open models on Together's hosted gateway. There's no local proxy. Terminal agents get a temporary per-launch config that disappears when the session ends, so your ~/.claude settings stay put. Inside Claude Code, the /model tiers map to Kimi K3 (Opus), GLM 5.3 (Fable), GLM 5.3 Flash (Sonnet) and DeepSeek V4.1 Flash (Haiku).

The default is an auto router that reads the first task and picks once per session, so prompt caching survives. With an Anthropic key it routes between Opus 5.5 and GLM 5.3. Without one, between GLM 5.3 and GLM 5.3 Flash. Listed prices: Kimi K3 at $3.00 in and $15.00 out per million tokens, GLM 5.3 at $1.40 and $4.40. Together claims 50 to 80% savings against all-Opus 5.5 sessions. That's the vendor's number, measured on the vendor's routing, so check it against your own.

For builders

Don't migrate. Measure. Pick five real tasks you finished in Claude Code last week, rerun them with togetherlink claude, and compare the diff quality and the exit receipt. togetherlink usage --last 7d gives you the weekly total. If you want a clean comparison without the router guessing, pin one model with togetherlink --main zai-org/GLM-5.3 claude. Headless runs need < /dev/null or they hang.

Story III

OpenAI's textGrain watermark is opt-in on the API worldwide. Claude's is on everywhere, and that's now a vendor decision

OpenAI is rolling out textGrain, a statistical watermark in word choice, to ChatGPT and Codex for EU users over the coming weeks to meet EU labeling rules. API customers anywhere can opt in starting now, and OpenAI says cloud partners will follow. The Decoder points out the contrast: Anthropic watermarks all Claude output globally, however you reach it. OpenAI also says it will open-source the technique.

The detection numbers are honest and not great for anyone counting on them. At a 1% target false-positive rate, the detector catches about 95% of 400-token psychology passages, about 80% at 200 tokens, and much less on math. Swapping 10% of words for synonyms drops detection from roughly 92% to 66%. Swapping a quarter drops it to 17%. The detector itself goes only to approved researchers for now, through an application form.

For builders

Write down a watermark policy before a customer asks. If you sell generated copy or reports, find out which model produced each output, because on Claude it is marked whether you wanted that or not, and on the OpenAI API it's your call. If an enterprise buyer requires provenance, OpenAI's opt-in is now a feature you can turn on. And if someone asks you to build "AI text detection," show them the 17% number first.

Story IV

Mistral Large 4 and Reflection Beam ship the APIs and benchmarks now. The open weights come later this month

Mistral Large 4 has 1.05 trillion total parameters, 49 billion active, and a 1M-token context, according to The Decoder. It's in Mistral Studio now at preview pricing of $0.68 per million input tokens and $2.09 output, though the docs also list double those rates. Weights are due around the end of October. On Artificial Analysis's Intelligence Index it scores 38, tied with GLM-5.2 and well behind Claude Opus 5.5 at 58. Mistral's real pitch is security work that closed US models refuse: it reproduced and patched a real open-source vulnerability 82% of the time.

Reflection's Beam is smaller and aimed at coding: 501 billion parameters, 23 billion active, Apache 2.0, weights also due later this month. Reflection claims it matches GLM 5.2 with three to four times less compute. On SWE Bench Pro v1 it posts 65.5 to GLM 5.2's 62.1, and on Terminal Bench v2.1 it trails slightly, 80.1 to 81.0. Both are first-party numbers until someone else runs them.

For builders

If your blocker for self-hosting was "we can't send code to a Chinese-built model," put a calendar reminder on October 31 and plan a small eval for whichever weights actually ship. Until then, Large 4's API is cheap enough to test on a security triage queue, but don't build pricing around preview rates when the docs already show double. Beam's 23B active parameters is the number to watch if you care about inference cost.

Sources

  1. Ars Technica — protocol pivoting across MCP and A2A, Google mcp-toolbox SSRF (8), Rapid7 CVE-2026-97228 (2.7), researcher quotes
  2. MarkTechPost — Together Link setup, auto router, /model mapping, prices, commands
  3. OpenAI — EU text provenance approach: scope, API opt-in, detector access
  4. The Decoder — textGrain detection rates, edit robustness, Anthropic comparison
  5. The Decoder — Mistral Large 4 specs, preview pricing, Intelligence Index, security results
  6. TechCrunch — Mistral Large 4 launch, open weights after safety testing
  7. The Decoder — Reflection Beam size, Apache 2.0, benchmarks vs GLM 5.2

— The Vibe Gate news desk. We read the firehose so you can keep building.

← All digests  ·  The blog