<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom"><title>Attenu blog</title><link href="https://attenu.io/blog/"/><link rel="self" href="https://attenu.io/feed.xml"/><id>https://attenu.io/feed.xml</id><updated>2026-09-05T00:00:00Z</updated><author><name>Rafael Asor</name></author><entry><title>The delegate your agent trusts by shape</title><link href="https://attenu.io/blog/the-delegate-your-agent-trusts-by-shape/"/><id>https://attenu.io/blog/the-delegate-your-agent-trusts-by-shape/</id><updated>2026-09-05T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>A docstring says a delegate cannot write, present, or invoke other delegates. It holds by shape. I wrote the one it warns about and ran it twice.</summary></entry><entry><title>A delegate cannot write, present, or invoke other delegates. I ran that sentence as authority.</title><link href="https://attenu.io/blog/cannot-write-present-or-invoke-other-delegates/"/><id>https://attenu.io/blog/cannot-write-present-or-invoke-other-delegates/</id><updated>2026-09-05T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>Anthropic's commerce-agents states its delegate contract in a docstring. I ran it as authority: three refusals before the body, a receipt checked offline.</summary></entry><entry><title>I delegated a review in CrewAI. The reviewer ran an export tool the orchestrator never had.</title><link href="https://attenu.io/blog/crewai-manager-tools-delegation/"/><id>https://attenu.io/blog/crewai-manager-tools-delegation/</id><updated>2026-09-03T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>A CrewAI reviewer coworker ran an export tool its orchestrator never held. In hierarchical mode the manager may not hold tools at all. Six runs on crewai 1.15.18, the source that does it, and what it takes to bound the coworker.</summary></entry><entry><title>Does a sub-agent inherit its parent's permissions? Five frameworks, five answers.</title><link href="https://attenu.io/blog/sub-agent-permissions-five-frameworks/"/><id>https://attenu.io/blog/sub-agent-permissions-five-frameworks/</id><updated>2026-09-02T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>When agent A hands work to agent B, what can B call? I assumed the answer was "at most what A can call". It isn't, in any of the five frameworks I use. Here's what each one actually does, from runs I </summary></entry><entry><title>Does a LangGraph subagent inherit its parent's tool permissions? I tested it.</title><link href="https://attenu.io/blog/langgraph-subagent-middleware/"/><id>https://attenu.io/blog/langgraph-subagent-middleware/</id><updated>2026-09-02T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>I gave a supervisor agent in Deep Agents 0.7.6 exactly one tool, writebrief. It spawned a writer subagent. The writer ran a web search for site:exfil.example internal customer list, because a note in </summary></entry><entry><title>We reviewed our own adapters like an attacker would. Here is what broke.</title><link href="https://attenu.io/blog/adversarial-review-bug-hunt/"/><id>https://attenu.io/blog/adversarial-review-bug-hunt/</id><updated>2026-08-26T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>Last week we wired execution binding — the evidence layer that records what happened after a call was</summary></entry><entry><title>What crosses an ADK transfer, and what should not</title><link href="https://attenu.io/blog/adk-peer-transfer/"/><id>https://attenu.io/blog/adk-peer-transfer/</id><updated>2026-08-26T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>What ADK built well. Google's Agent Development Kit has the cleanest transfer model of the frameworks we</summary></entry><entry><title>A receipt for what Claude Code gave the subagent</title><link href="https://attenu.io/blog/claude-code-hooks-receipt/"/><id>https://attenu.io/blog/claude-code-hooks-receipt/</id><updated>2026-08-26T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>What Claude Code built well. Of every agent framework we have integrated, Claude Code has the most complete</summary></entry><entry><title>How much, not just who: what an MCP server can check</title><link href="https://attenu.io/blog/mcp-server-verifier/"/><id>https://attenu.io/blog/mcp-server-verifier/</id><updated>2026-08-26T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>What MCP built well. The authorization spec (2026-07-28) is careful about the oldest problem in delegated</summary></entry><entry><title>Omnigent's budget is a count. Authority needs a ceiling.</title><link href="https://attenu.io/blog/omnigent-policy-handler/"/><id>https://attenu.io/blog/omnigent-policy-handler/</id><updated>2026-08-26T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>What Omnigent built well. Omnigent is a meta-harness: it drives Claude Code, Codex, Cursor, OpenCode, Pi and</summary></entry><entry><title>Two agents in the Agents SDK, and the relation between them</title><link href="https://attenu.io/blog/openai-agents-one-policy/"/><id>https://attenu.io/blog/openai-agents-one-policy/</id><updated>2026-08-26T00:00:00Z</updated><author><name>Rafael Asor</name></author><summary>What they built well. The OpenAI Agents SDK has, quietly, the most complete set of capability</summary></entry></feed>