0

New: free GitHub Actions Security Workshop: July 2026

Homepage
Courses Membership The Guild
Content
Newsletter Blog YouTube Podcasts Discord Server GitHub Examples Sponsor
Consulting
Private Training Workshops
About
About Me Link Tree
Log In
← Back to all posts

Agents Are Changing Everything, So Where Do We Focus?

Aug 30, 2026

While the agent harnesses iterate, I think it's time to focus on the other core principles of agent harnesses: Skills + Tools + MCP.

A few years ago, I felt like every dev or ops tool added AI in its name or description, yet it was mostly hype, and the word AI had lost its meaning. Then MCP came along, and I wasn't convinced that everything needed an MCP endpoint (still debated, but I think MCP is here to stay). Then agent harnesses and agent skills became the hot thing in 2026. I've been focused on those two all year.

For months, I've been in a "control everything from my harness" mood now that we have 4 principles to do everything new on top of:

  1. Agents (LLM loops, now with sub-agents and scheduled tasks)
  2. Skills (centralized context management & procedure docs)
  3. Tools (local shells and executables)
  4. MCP (remote control and data access)

That powerhouse combo is something we'll build on and optimize for years.  I mentioned this in a local engineering meetup this week when people talked about the struggle of "keeping up with all the new agents, harnesses, etc." 

I think we're going to be iterating on this harness + agents idea for years. I haven't seen a single harness (of the dozens and dozens) that trully changed our capabilties in 2026 byeond what we had in 2025. Models got better, and we got better at context management, but agent harnesses are now 80% the same thing and I think matured quickly. So, rather than being distracted by new tools at the harness/orchestrator level, I think it's more important right now to stick with a single harness and become an expert in how it works and how to become advanced at using (and expecially making) Skills and MCP tools inside that harness. Any of the top 20 harnesses have the same core features and controls to enable you to be an advanced LLM operator with a dozen agents/sub-agents automating your work, but that depends on how well you can automate your work with Skills, tools (CLI/MCP), and data (MCP/API).

Right now, agent harnesses are in their "2.0 phase": they worked OK in 1.0, and we've tweaked them a lot over the last year, but really, they are just smoothing out the initial 1.0 design. We've matured from the 1.0 to 2.0 era: they've added mobile/remote control, sub-agents that can be local or cloud, better "auto tool call permissions", better context management, voice input, memories, computer use... but nothing that's forcing us to rethink what the initial idea of agent harnesses was.

It may take a few years of iterating before a new wave of agent harness and orchestration products deserve our attention as a replacement for today's harnesses.

So now's a good time for us to become better at what we can do with our current agent harnesses:
  • Making and testing Skills for every repeatable task in our work
  • Trusting our agents a bit more with controlling CI and our systems
  • Creating event-triggered agents and Skills
  • Learning to limit agent permissions with a sandbox (not just local permissions, but also HTTP and secrets control)
For more on what it's like to drive your CI entirely from your harness, see my podcast episode with Semaphore:
CI/CD via agent tools: Skills, CLIs, MCP, and more with Semaphore
For more about how external sandboxes work, and seeing how advanced they've got and how easy it can be to get started, see my podcast episode on the nono project:
AI Agent Sandboxing with Nono

Talk to ya again soon,

Bret

 

 

 

Agentic Workflows Are Here
Recent happenings: I streamed with the Semaphore team on how they are making their CI/CD platform "ai-native" and what that really means. They've got a claude/codex plugin system that comes with a CLI, skills, and MCP for controlling your CI. Podcast coming soon. I streamed with the co-founder of nono.sh, my go-to agent sandboxing tool, that can now, more or less, sandbox anything on Linux and...
My GitHub Security Hardening workshop is free next week
Sign up for my live hands-on workshop that's on Tuesday. I've been working on it for months, then I spoke about it at the Accelerate Chicago conference last month, and I finally get to bring it to you wonderful people. I found this content so useful for my own repos and orgs, that I created an open-source tool to complement the training and help you harden your repositories and find where you ...
AI-Native Kubernetes: What Does it Mean?
Join my stream Thursday 6/4/26 with guests from OpenChoreo, a new CNCF Kubernetes "AI abstraction" with built-in agents and all the fixin’s for managing K8s with agents. KubeCon has been talking about AI in every keynote since the launch of ChatGPT, but it wasn't what you think. Before that moment in consumer AI, the language of AI was MLOps-specific and rarely highlighted at KubeCon. Soon aft...

Cloud Native DevOps

CNDO is a weekly-ish email from Bret Fisher on content he's creating. Agentic DevOps, automation, containers, Docker, Kubernetes, GitOps, GitHub Actions, and everything cloud native.
Homepage
© 2026 bretfisher.com
Courses Membership The Guild
Newsletter Blog YouTube Podcasts Discord Server GitHub Examples Sponsor
Private Training Workshops
About Me Link Tree

Join Our Free Trial

Get started today before this once in a lifetime opportunity expires.