The day in one line
Three findings this week all say the same thing: the risky part of an AI agent is not the model, it is the configuration something else controls.
Your coding agent will run what a repo tells it to
Git's core.fsmonitor setting names a command Git runs during file status checks - and it lives in the repository's own .git/config. Point a coding agent at a repo you received and it executes that command, with no sandbox and no prompt.
Seven agents affected. goose, Codex CLI, Codex Desktop and Cursor are patched. Hermes Agent, Qwen Code and Grok Build are not - Qwen accepted the report on 7 July and has shipped nothing since.
The detail most coverage buried: Claude Code patched the core.fsmonitor path in 2.1.196, but a second path was confirmed live in 2.1.258. Updating does not close it.
One-line mitigation: git config --global core.fsmonitor false
Full version table, CVEs and what to check
349 agent skills point at domains nobody owns
Manifold Security found placeholder domains across roughly 359,000 GitHub files, used by 349 AI agent skills. Invented example domains are not reserved the way example.com is - they are merely unregistered, and anyone can buy them. Some now redirect to scam pages.
It matters more for skills than for ordinary code because skills fetch automatically, carry the agent's credentials, and nobody reads the response.
How to audit your installed skills
And a free fix for a different problem
A web-extraction benchmark found models invented 70.7% of fields that were absent from the page. Adding one sentence - "Use null for any field whose value is not on the page. Do not guess" - dropped it to 20.2%.
Gemini 3.8 Flash and GLM 5.3 fabricated 1 of 36. Firecrawl, a paid extraction API, invented 24 of 36. And a cheap verifier pass with GPT-6 Luna caught 38 of 49 fabrications while rejecting zero correct answers.
The full results and what to change in your prompts
Tomorrow
OpenAI DevDay, 29 September, San Francisco. OpenAI has confirmed the date and location; no agenda has been published. Plenty is circulating about what will be announced and none of it is sourced well enough to repeat here - we will cover what is actually shown.
What to watch
Whether Qwen Code and Grok Build ship a patch. Both have had the GitSpawn report for weeks, one closed it as informative, and how a vendor handles a disclosure is a better signal about a coding agent than any benchmark score.