# A rumour is not a named web operation.

This Monday 31 August 2026 sourced take starts from [Anil Madhavapeddy’s 22 August 2026 essay](https://anil.recoil.org/notes/rumour-is-the-exploit), as linked from the [Hraness Reading page](https://hraness.com/reading/rumour-is-the-exploit). The essay’s claim is that a rumour of a bug is now enough for agentic search. [Wrench](https://wrench.rip/) does not treat that search direction as its job. It names a provider operation a session can call on purpose, attests whether the current contract can run it, and refuses to reconstruct an attack from a description.

This sourced take uses the [Hraness Reading page](https://hraness.com/reading/rumour-is-the-exploit), Madhavapeddy’s essay as linked there, and the public v0.16.7 pages for the [Wrench home](https://wrench.rip/), [provider capability attestation](https://wrench.rip/provider-capabilities/), [VM-containment argument](https://wrench.rip/vms-cannot-contain-agents/), and [PayPal GrapheneOS device-policy argument](https://wrench.rip/paypal-grapheneos-attestation/). Operation counts are the current release attestation, substituted at site build time. This page does not reprint the essay, the Reading digest, or any exploit procedure.

## Monday sourced a rumour claim, not a Wrench contract

The live essay title is “Just a rumour of a bug is enough to find a security exploit these days,” published 22 August 2026 by Anil Madhavapeddy. The [Hraness Reading page](https://hraness.com/reading/rumour-is-the-exploit) saved that essay on 29 August 2026 and keeps the same title. This page names both. It does not reprint the Reading digest or the essay’s reconstruction notes.

Madhavapeddy writes that matching probes reached his server minutes after he opened a public cohttp fix, and that his agents reconstructed an exploit from a rough description in under a minute. He treats those events as evidence that a rumour is now a usable search direction. This page keeps that bound. It does not describe the defect, the probes, or the reconstruction.

[Hraness](https://hraness.com/) publishes Wrench and this site. The essay is an independent maintainer argument about disclosure timing. It is not a Wrench release note, and a rumour does not add a provider operation.

## A search direction is not a named operation

The essay’s governing claim is that conventional embargoes assume secrecy still buys time. Madhavapeddy argues that mean time to exploit is now negative, so a public description can arrive after search has already started. He cites Fang and colleagues: giving a CVE description to a GPT-4 agent raised success on a 15-vulnerability benchmark from 7 percent to 87 percent. This page records that citation. It does not treat a CVE text as an instruction.

He also writes that all an agent needs today is a broad direction to search in. That is the object under test: a rumour as a search hint. The [provider capability attestation](https://wrench.rip/provider-capabilities/) names a different object. It lists operations a session can call on purpose. A rumour does not name `messaging.list`, bind an account, or mark a reservation ready.

Wrench’s product is the outbound contract, not a search from an incomplete description. The [Wrench home](https://wrench.rip/) states that each authenticated operation is typed, bounded, and tied to one account and transport. The caller brings the model and interface. Wrench supplies the local capability and custody layer. It is not an AI agent, planner, or approval shell. It does not reconstruct exploits, accept caller-selected endpoints, or treat a rumour as a capability grant.

## Attestation names the operation a caller chose

When a rumour is enough for agentic search, the capability layer still has to name the outcome. The current release attests 327 operations across 23 bundled public adapters. 139 are `observed`. 188 remain `capture-required`. Those figures are the same release-bound counts published on the [provider capability attestation](https://wrench.rip/provider-capabilities/). This page does not add a provider, invent an exploit operation, or treat a reservation as ready. Telegram is absent from those manifests. Wrench does not install a Telegram Bot API substitute or claim Telegram contact access.

`observed` means the current contract can plan and execute after local doctor and auth checks pass. `capture-required` is an inert reservation. The attestation page says a missing or `capture-required` operation stays unavailable rather than falling back to general browser control. A rumour that is enough for search does not mark a Wrench reservation `observed`, and a completed embargo does not invent one.

## Rumour, guest machines, and device policy answer different questions

The [VM-containment argument](https://wrench.rip/vms-cannot-contain-agents/) asks whether a guest machine can stand in for attestation. The [PayPal GrapheneOS device-policy argument](https://wrench.rip/paypal-grapheneos-attestation/) asks whether a rooted-phone check can stand in for a named web job. This page asks whether a rumour that is enough for agentic search can stand in for that same named job. The pages refuse different substitutes.

| Decision | Rumour-driven agentic search | Wrench attested operation |
| --- | --- | --- |
| What is named | A search direction or incomplete description | A named outbound outcome such as `messaging.list` |
| What is attested | Nothing about the outbound contract | Exact provider, transport, account realm, contract version, implementation, input, and risk |
| Failed check | A rumour can still be enough to start a search | The operation stops. A `capture-required` reservation stays inert |
| Missing proof | An embargo or secret patch is still not a named operation | The reservation cannot plan or execute, and Wrench does not invent a browser fallback |
| Job of the layer | Search from a rumour | Name the operation a caller chose and attest whether it is available |

A rumour that is enough for search still does not name `messaging.list` or mark a reservation `observed`. The essay is evidence that disclosure timing has changed. It is not a Wrench capability grant.

Read the VM page for containment. Read the PayPal page for device policy. Read this page for why a rumour is not an attested operation. A news take covers [why a desktop that lets any user process escalate to root is still not a named web operation](https://wrench.rip/omarchy-root-escalation/). The pages do not reprint one another.

## Read the essay and the Reading page, then the current contract

Start with [Just a rumour of a bug is enough to find a security exploit these days](https://anil.recoil.org/notes/rumour-is-the-exploit). Keep the [Hraness Reading page](https://hraness.com/reading/rumour-is-the-exploit) as the dated digest. [hraness.com](https://hraness.com/) is the publisher of Wrench. Then read the [provider capability attestation](https://wrench.rip/provider-capabilities/) for every current operation and completeness mark, the [VM-containment argument](https://wrench.rip/vms-cannot-contain-agents/) when the question is a guest machine rather than a rumour, the [PayPal GrapheneOS device-policy argument](https://wrench.rip/paypal-grapheneos-attestation/) when the question is a rooted-phone check rather than agentic search, and the [Omarchy desktop-root news take](https://wrench.rip/omarchy-root-escalation/) when the question is a host privilege grant rather than a rumour.
