Skip to content
Artwork for Overcommitted | Software Engineering and Programming Insights
Overcommitted | Software Engineering and Programming Insights · August 4 · 35 min

Closed That Tab: Agentic Identity, AI Security Incidents, and Loop Engineering

This week we're trying something new: Closed That Tab, a segment where each host shares one thing they finally read that was worth the time. Erika brings a post on agentic AI identity and delegation - covering why OAuth isn't quite enough for agents that accumulate permissions across a request lifecycle, and what transaction tokens (an IETF draft proposal) offer as a solution. Bethany covers Simon Willison's breakdown of the OpenAI security incident, where an eval harness escaped its sandbox by chaining zero-day vulnerabilities - and what responsible sandboxing and observability should have caught earlier. Brittany shares how she accidentally built a loop engineering system before knowing the term existed: a continuously running agent harness using git worktrees, sub-agents, and a memory file to close around 20 PRs a day, including self-healing flaky tests. Links: Erika’s Agentic AI Identity Read: https://khaledzaky.com/blog/delegation-is-the-real-identity-problem-in-agentic-ai Bethany’s OpenAI CyberAttack Read: https://simonwillison.net/2026/Jul/22/openai-cyberattack Empire of AI: https://bookshop.org/p/books/empire-of-ai-dreams-and-nightmares-in-sam-altman-s-openai-karen-hao Brittany’s Loop Engineering Read: https://addyosmani.com/blog/loop-engineering/ Superpowers: https://github.com/obra/superpowers Brittany’s Loop Engineering Blog post: https://brittany-ellich.offprint.app/a/3mrjj34puva23-108-prs-in-eight-days-accidentally-discovering-loop-engineering Hosts: Overcommitted: ⁠https://overcommitted.dev ⁠Bethany Janos: ⁠https://www.trustyduck.dev/⁠ Brittany Ellich: ⁠https://brittanyellich.com ⁠Erika Eggemeyer: ⁠https://github.com/eggyhead

0:00-35:27

transcript

No transcript — this publisher did not publish one.

show notes

This week we're trying something new: Closed That Tab, a segment where each host shares one thing they finally read that was worth the time. Erika brings a post on agentic AI identity and delegation - covering why OAuth isn't quite enough for agents that accumulate permissions across a request lifecycle, and what transaction tokens (an IETF draft proposal) offer as a solution. Bethany covers Simon Willison's breakdown of the OpenAI security incident, where an eval harness escaped its sandbox by chaining zero-day vulnerabilities - and what responsible sandboxing and observability should have caught earlier. Brittany shares how she accidentally built a loop engineering system before knowing the term existed: a continuously running agent harness using git worktrees, sub-agents, and a memory file to close around 20 PRs a day, including self-healing flaky tests.


Links:

Erika’s Agentic AI Identity Read: https://khaledzaky.com/blog/delegation-is-the-real-identity-problem-in-agentic-ai

Bethany’s OpenAI CyberAttack Read: https://simonwillison.net/2026/Jul/22/openai-cyberattack

Empire of AI: https://bookshop.org/p/books/empire-of-ai-dreams-and-nightmares-in-sam-altman-s-openai-karen-hao

Brittany’s Loop Engineering Read: https://addyosmani.com/blog/loop-engineering/ 

Superpowers: https://github.com/obra/superpowers 

Brittany’s Loop Engineering Blog post: https://brittany-ellich.offprint.app/a/3mrjj34puva23-108-prs-in-eight-days-accidentally-discovering-loop-engineering


Hosts:

Overcommitted: ⁠https://overcommitted.dev

⁠Bethany Janos: ⁠https://www.trustyduck.dev/⁠

Brittany Ellich: ⁠https://brittanyellich.com

⁠Erika Eggemeyer: ⁠https://github.com/eggyhead

links6