R
Refacto Agents
The Agent Stack, With Analysis
by Ken Rona

Scoreboard

Every call we make, graded in public.

View record →

This issue

Daily Brief — Mon, Jul 20


Top story · Analyzed

Pydantic AI v2.13.0 adds capability hooks and cache-hit tracking — Pydantic Ai Releases

Full Analysis →

No prediction yet

Pydantic AI's v2.13.0 release is quietly useful for anyone running agents at production scale. The new capability hooks (get_model, resolve_model_id, for_agent) hand developers runtime control over model selection and agent wiring — the kind of flexibility that matters once you're managing multiple models in a real system. The cache_hit_ratio property on usage objects is the other one worth paying attention to: knowing exactly how often you're hitting cache versus paying for fresh inference is basic cost hygiene that most frameworks skip.


Top story · Analyzed

Google Named Leader in 2026 Gartner Conversational AI Magic Quadrant — Google Cloud Blog

Full Analysis →

No prediction yet

Google topping the 2026 Gartner Conversational AI Magic Quadrant — furthest on both Vision and Execution, #1 in three of four Critical Capabilities — is less a surprise than a confirmation of where the enterprise AI stack is consolidating. The real signal is the Home Depot deployment: AI voice agents built on CX Agent Studio identifying caller intent in under 10 seconds, resolving calls up to 4x faster than traditional phone menus. That's a production benchmark at scale, and it raises the bar for every competitor still selling pilots.


Top story · Analyzed

Google documents first AI-built zero-day exploit in the wild — Google Cloud Blog

Full Analysis →

No prediction yet

AI has crossed a line. Google's Threat Intelligence Group just documented the first zero-day exploit built entirely by AI — and the scarier number buried in the same report is that AI-assisted multi-stage attack handoff times have collapsed from eight hours to 22 seconds over the past year. Google caught and patched this one before it launched.


Top story · Analyzed

Google launches AI Threat Defense platform combining Gemini, Wiz, and Mandiant — Google Cloud Blog

Full Analysis →

No prediction yet

Google just bolted together three serious assets — Wiz's cloud scanning, Mandiant's threat intelligence, and Gemini's reasoning — into a single platform, and the early numbers from Morgan Stanley are hard to ignore: mean time to detect dropping from 45 minutes to 90 seconds. That's not a marginal improvement; that's a different category of defense. The real question is whether the autonomous Red, Blue, and Green agents hold up outside a marquee reference customer, or whether 99.9% is a controlled-environment number that softens in the wild.


Top story · Analyzed

Wiz MCP integration brings AI-driven security agents to cloud context — Google Cloud Blog

Full Analysis →

No prediction yet

Security tooling is getting colonized by AI agents, and Wiz just made itself the connective tissue. Google Cloud's announcement puts Wiz at the center of agentic workflows via MCP — the protocol that lets AI agents pull from external tools and data sources — so any AI system can now query real-time cloud security posture and trigger Wiz's AI Skills directly. The play is clear: own the layer that agents trust for security context, and you become infrastructure, not just a product.


Top story · Analyzed

GhostApproval: Wiz uncovers trust-boundary blind spot in AI coding assistants — Google Cloud Blog

Full Analysis →

No prediction yet

The human-in-the-loop safety model for AI coding assistants has a structural problem. Wiz researchers demonstrated a vulnerability class they're calling GhostApproval — attacks that exploit trust boundaries to slip malicious code past human review in tools like GitHub Copilot and Cursor. The safety model assumes a developer can catch what the AI misses.


Top story · Analyzed

Google open-sources k8s-aibom for automated AI bills of materials on Kubernetes — Google Cloud Blog

Full Analysis →

No prediction yet

Shadow AI is the governance problem nobody has a clean answer to — employees spinning up models and agents outside IT's view, and no one knowing what's actually running in production. Google's answer is k8s-aibom, an open-source Kubernetes controller that continuously scans cluster environments and auto-generates standardized ML Bills of Materials. The bet is that if you can inventory what's running, you can govern it.


Top story · Analyzed

Google's Scion orchestrator runs multi-agent film crews to completion — Google Cloud Blog

Full Analysis →

No prediction yet

Google just turned its own hackathon into a stress test for multi-agent orchestration — and the results are worth studying. Ten Scion crews, each running an Idea Person, Technical Lead, Editor, and supervising Coach, produced 25+ short films and 44 minutes of delivered content by routing work through shared files rather than message chains. That design choice matters: files survive agent crashes and restarts; message context doesn't.

Get Refacto Agents free in your inbox, every weekday.

Subscribe free