Agent Frameworks & Harnesses 2026-10-09

Framework Watch: Claude Code Hooks Can Now Fail Closed; Codex 0.162 Hardens Its Linux Sandbox; OpenAI's Decisions API Reaches LangChain

Claude Code 2.1.295 (October 8) adds onFailure: 'block' so a broken hook stops the action instead of waving it through, after 2.1.294 fixed instruction-style hooks allowing what they should block. Codex 0.162.0 tightens sandbox construction. OpenAI's Decisions API beta, out October 6, got LangChain support two days later -- and an early calibration warning.

On October 7 this digest noted that Microsoft's new Copilot Studio hooks fail open. On October 8, 2026, Anthropic shipped Claude Code 2.1.294 (05:03 UTC) and 2.1.295 (19:48 UTC), and the second adds a fail-closed option for its own hooks.

Claude Code 2.1.294 and 2.1.295: what operators should act on

  • Fail-closed hooks. "Added onFailure: "block" for command and HTTP hooks: a hook that can't start, times out, or exits with an unexpected code blocks the action instead of letting it through." Teams that use hooks as security guards should turn it on.
  • Instruction-style hooks. 2.1.294 "Fixed prompt and agent hooks written as instructions (such as "Block commands that...") allowing what they should block."
  • Guards that saw truncated input. 2.1.295 fixed "a mod's hook being handed a deeply nested tool input cut short with no error, so a guard could pass content it never saw."
  • Permission scope. Fixed "--tools and --restricted not applying to built-in tools that register after launch," and improved Bash permission checks for for-loops over glob patterns.
  • Managed settings and MCP. Fixed "a tampered cache of server-managed settings making a person's own plugin count as organization-managed"; WebSocket MCP messages over 16 MiB now close the connection.

Codex 0.162.0 (October 8)

  • "Fix Linux sandbox startup with multiple denied files, reject writable sandbox-construction executables, and keep ripgrep configuration from weakening deny-glob masks." One change rejects sandbox-writable bubblewrap executables found on PATH.
  • "Honor server Retry-After advice" for retryable failures, and a signed PowerShell installer for Windows.

OpenAI Decisions API, now in LangChain

OpenAI opened the Decisions API in public beta on October 6: a POST /v1/decisions endpoint where "gpt-6-luna is the only model currently available." It returns typed judgments -- Predicates ("the probability that a statement is true"), Choices ("with confidence scores") and Scores ("against a numeric range") -- for jobs such as "classify content, route requests, and prioritize work." Pricing is "$0.10 per 1M tokens" of input with no output or cache charges, and OpenAI claims it is "up to 10x faster" than calling Luna through the Responses API; MIXED notes the claim came with no benchmark. ZDR, HIPAA and data residency in the US and Europe (EEA and Switzerland) are supported. langchain-openai 1.7.0 (October 8) added "support decisions api."

The early warning comes from OpenAI's own forum: a tester simulating a coin biased to heads 70% of the time got about 70% with a predicate, but "when I setup the question as a choice... I got it 98% of the time," and concluded, "don't use choice questions." One user's test, not a benchmark, but worth reproducing.

Analysis: the theme across all three is guardrails that fail safely. Turn on fail-closed hooks, check whether your Codex hosts had writable bubblewrap binaries, and calibrate Decisions API outputs on your own labelled data before letting a probability drive routing.

Claude Code 2.1.295 lets command and HTTP hooks fail closed and 2.1.294 fixed instruction-style hooks allowing what they should block; Codex 0.162.0 hardens Linux sandbox construction; OpenAI's input-only-priced Decisions API reached LangChain within two days, but an early forum test found its choice format badly miscalibrated.