Founding member access recorded.
Checkout cancelled.

Signals · Agent Zero profile

Agent Zero

Every signal accepted for Agent Zero. Each links to the run that produced it. The Agent Zero profile carries the current evergreen state.

June 2026

  1. 2026-06-03 · Agent Zero

    Computer-use screenshots now persist to durable chat-scoped storage by default

    • Reverses the prior ephemeral-by-default posture for computer-use screenshots, so operators who relied on screenshots being transient must now account for retained artifacts
    • Changes deployment storage characteristics: long-running computer-use sessions accumulate screenshots in chat context, requiring storage planning and retention/cleanup review
    • Directly hits the Grid/workcell calibration concern of persistence and cleanup for real computer access
  2. 2026-06-03 · Agent Zero

    Office, Desktop, and Editor plugins become toggleable behind a protected plugin-state API

    • Operators can disable Office, Desktop, or Editor plugins (Desktop computer-use especially) on deployments that should not hold those capabilities, via the v1.19 plugin-toggle endpoint.
    • The endpoint is described as 'protected' but the release note documents no auth model or role-based capability management, so treat it as a disable lever, not yet an audited capability register.
  3. 2026-06-03 · Agent Zero

    Remote Link renamed to Remote Control with selectable tunnel providers and handshake version advertisement

    • Operators managing distributed deployments must update remote-connectivity terminology (Remote Link -> Remote Control) and can now choose among Cloudflare, Microsoft Dev Tunnels, Serveo, and Tailscale
    • Version advertisement in connector handshakes lets CLI clients detect server compatibility, changing how operators coordinate client/server upgrades across a fleet

May 2026

  1. 2026-05-27 · Agent Zero

    Host desktop control with required visual verification

    • Operators evaluating Agent Zero for host control must decide whether `computer_use_remote` is allowed at all on the host — the default trust mode is opt-in but the runtime checks are enforceable.
    • Workcell operators should know that screenshot capture is now ephemeral and context-scoped by default; auditing what the agent saw requires explicit durable capture.
    • Operators using the existing `linux-desktop` skill: verify your skill routes to the path you expect; host and container desktops are now cleanly separated.
  2. 2026-05-12 · Agent Zero

    ODF-first document defaults, persistent desktop lifecycle, multi-tab browser fanout

    • Operators running Agent Zero should verify that downstream workflows handle ODT/ODS/ODP output from v1.13+. OOXML output now requires explicit configuration.
    • Operators running long-horizon desktop sessions should plan for persistent desktop state: the Xpra Desktop no longer resets on canvas navigation. Accumulated desktop state (open apps, browser sessions) persists until explicitly shut down.
  3. 2026-05-07 · Agent Zero · OpenHands

    Real computers are becoming the agent work surface.

  4. Accessibility is becoming a frontier capability.

  5. Bitter needs a wrap, adapt, refuse decision for every frontier surface.

  6. The agent interface is becoming a visible computer

    • A serious agent harness increasingly needs browser, desktop, file, runtime, sandbox, and artifact surfaces that can be inspected.
  7. Permissions, secrets, and sandboxes are moving into the foreground

    • The harness must make trust state visible: what can be read, what can be changed, which credentials are exposed, and where execution happens.
  8. Accessibility is a frontier capability, not marketing polish

    • Everyday adoption depends on setup recovery, visible progress, voice/chat surfaces, readable UI, OAuth clarity, and fewer dead ends.

← All signals