AI++ // Langflow 1.7 released, context engineering and agentic security under the microscope


It is almost the end of the year, so this is the last edition of the AI++ newsletter for 2025. But we're going out with a bang, announcing the release of Langflow 1.7. This release upgrades Langflow's MCP transports to use Streamable HTTP, adds more agent options with CUGA and ALTK, and brings a bunch of new components for your flows.

In other news, Anthropic, OpenAI and Block founded the Agentic AI Foundation gifting the community with the MCP, AGENTS.md, and goose projects. Meanwhile OWASP released their top 10 security risks for agentic applications, gifting the community with a bunch of things to worry about. So good news and bad news I guess.

2025 has been an exciting year for building AI-powered applications, I can't wait to see what 2026 will bring. All I know is that AI++ will be there to help keep you up to date.

โ€‹Phil Nashโ€‹
Developer relations engineer for
Langflowโ€‹

๐Ÿ› ๏ธ Building with AI, Agents & MCP

โ€‹Langflow 1.7 releasedโ€‹

There is a lot to love about the new Langflow 1.7 release: the MCP client and server functionality now supports Streamable HTTP, you can set up authentication for webhook flow triggers, and there are some model-powered flow control components that will level up your flows. Check out the launch video for more on those features.

Also new to Langflow 1.7 is the CUGA agent component. CUGA is a benchmark topping agent built by IBM that reliably supports complex, multi-step tasks. You can read more about using CUGA in Langflow and check out this intro to CUGA on Hugging Face.

The Agentic AI Foundation

The Agentic AI Foundation was co-founded under the Linux Foundation by Anthropic, OpenAI and Block with support from Google, Microsoft, AWS, Cloudflare and Bloomberg. Anthropic donated MCP to the foundation, OpenAI contributed AGENTS.md and Block donated its open source agent goose.

Context Engineering

Context engineering is evolving and Phil Schmid shares the challenges that need to be solved, including context rot, pollution and confusion. Google also wrote up how their ADK has been designed to support the discipline of context engineering.

Agentic security

What do goal hijacking, tool misuse, and unexpected code execution have in common? They are all potential attacks on agentic systems highlighted in OWASP's top 10 for agentic applications for 2026. Take a read and consider all the ways your agents could be compromised.

One interesting paper that came out recently discussed how "semantic leakage" means that seemingly innocent phrases can weigh the probabilities of LLM output towards particular answers. Just because you like yellow doesn't make you a school bus driver.

And in a reminder that old security practices should not be forgotten, one developer reverse-engineered a legal AI tool valued at over a billion dollars.

๐Ÿง  New models

๐Ÿ—ž๏ธ Other news

๐Ÿง‘โ€๐Ÿ’ป Code & Libraries

๐Ÿ”ฆ Langflow Spotlight

I've mentioned this in the newsletter already, but there's so much more I can say about the CUGA Agent component. It performs task decomposition, sequences multiple step processes, and has robust error handling. It does this by handing tasks to specialist subagents that make decisions and perform actions without bloating the context. Check out this tutorial in which we build a CUGA agent that uses the file system and two different APIs to automate a fiddly process.

Enjoy this newsletter? Forward it to a friend.

2755 Augustine Dr, 8th Floor, Santa Clara, CA 95054
โ€‹Unsubscribe ยท Preferencesโ€‹

AI++ newsletter

Subscribe for all the latest news for developers on AI, Agents and MCP curated by the Langflow team.

Read more from AI++ newsletter

Happy birthday MCP! ๐Ÿฅณ The world's fastest growing protocol was released on 26th November 2024 and has captivated developers and users alike. I am certain that everyone reading this newsletter has used MCP in one way or another, and will be happy to hear that there is plenty of work going on to keep improving and evolving the protocol. In the newsletter this week we have stories on prompt caching, JSON outputs, product evals, and the evolution of LLM extensions that has brought us to the state...

There has been a flurry of new frontier models dropping over the last week that you can already use in your applications. Gemini 3 was released today, and Grok 4.1 and GPT-5.1 both arrived last week. This week we're also learning a lot of lessons from how coding agents are built, including building a coding agent in Langflow if you want hands-on experience with your own. There's also much debate over the efficiency of MCP and whether other tools fit the job better. Phil NashDeveloper...

The topic of security, specifically around prompt injection, is often raised and then dropped with a bit of a shrug as the path to a solution isn't very clear. Thankfully there are people out there thinking hard about it. In AI++ today, there are articles from Meta and Perplexity on this, with ways to mitigate the issue that we should all read and learn from. We've also got news of some great AI events coming up, including the online OpenRAG Summit, along with news of introspective AI models,...