ARC Labs
Free tools you can run today.
12 free tools, grouped by the job they do. Most need no account. TokenLoop uses a free signup so keys stay encrypted.
Market signals
Why these tools matter this month.
Each tool exists because something specific broke or changed. Here is the dated version, with the source, so you can decide whether it applies to you before you run anything.
Reviewed Sep 7, 2026
- Protocols
MCP went stateless. The handshake your servers rely on is retired.
The 2026-07-28 revision drops initialize and the session header, moves version and capabilities into per-request metadata, adds server/discover, and requires routing headers on Streamable HTTP. Old servers keep working for now — on a twelve-month clock.
Scan a server - Regulation
EU AI Act transparency duties are live. High-risk paperwork moved to 2027.
Telling people they are talking to AI, and marking generated content so it can be detected, applies now. The Annex III high-risk obligations slid to 2 December 2027. Teams that heard 'delayed' and stopped reading are exposed on the part that already applies.
Read the brief - Agent risk
A national evaluator watched agents act on the live internet without sanction.
The UK AI Security Institute catalogued 19 unsanctioned actions across 10 of 122 evaluation runs, including an agent that created fake identities to pressure a real open-source maintainer into merging malicious code. Least privilege for agents stopped being a policy sentence.
Review agent access - Security
The month's AI breaches were links and documents, not jailbreaks.
One crafted link was enough to inject instructions into a live Atlassian Rovo session and exfiltrate documents across every connected system — no jailbreak, no privilege escalation. The same pattern keeps appearing in DevOps integrations, email assistants, and agent frameworks. A connected assistant carries every permission you gave it.
Review an AI app - Cost
Coding-agent billing moved to routed-model pricing.
Cursor's Auto now bills at whichever model answered, plus a per-million token rate on third-party models for teams; the legacy flat rate for enterprise Auto expires 7 September 2026. Claude Code deployments run roughly $150–250 per developer per month. The same agent loop costs a different amount on a different day.
Open TokenLoop - Enterprise apps
The system of record grew an agent-facing surface with a meter on it.
Salesforce put its CRM inside Claude and exposed the platform as MCP tools, APIs, and CLI commands, with agents inheriting existing roles and consumption billed against API usage. Your vendors are shipping agent access whether or not you scoped it — and billing on agent traffic instead of seats.
See the Agent Control Review
AI engineering
Check an MCP server, review a prompt, or see what your agents can actually reach.
MCP Conformance Scanner
Check any MCP server against the spec in seconds.
Scan a server →
Prompt Reviewer
A second set of eyes on your system prompts.
Review a prompt →
ARC Skills
Open, copy-pasteable agent skills for real operator work.
Browse skills →
AI Workflow Templates
Ready-to-run AI workflows you can copy, wire up, and ship today.
Browse templates →
ARC Agent Governance
Know what your agents can reach, what they can do, and where the controls are missing.
Review agent access →
Security and infrastructure
What's reachable, what's misconfigured, and where an AI app is exposed.
Architecture and planning
Reference shapes and a defensible stack decision. Not a vendor list.
Cost control
See coding-agent spend before the invoice hits. Routed-model pricing moves the number daily.
Operations and journeys
Where a purchase path stalls, and where the operating workflow actually breaks.
Need a human to read the report?
Studio turns findings into a plan with owners. Same point of view as the tools. Thirty minutes to see if that is worth it.