MON, SEPTEMBER 28, 2026
Independent · In‑Depth · Practitioner‑Tested
✎ General

This Week the Dangerous Part Was Never the Model

A repository's Git config can make Claude Code or Codex execute arbitrary commands with three agents still unpatched, 349 agent skills reference domains nobody registered, and one added sentence cut fabricated extraction fields from 70.7% to 20.2%.

By AIToolsRecap September 28, 2026 5 min read 57 views
Home › Articles › General › AI News, 28 Sept 2026: .git, 349 Skills, 71%

The day in one line

Three findings this week all say the same thing: the risky part of an AI agent is not the model, it is the configuration something else controls.

Your coding agent will run what a repo tells it to

Git's core.fsmonitor setting names a command Git runs during file status checks - and it lives in the repository's own .git/config. Point a coding agent at a repo you received and it executes that command, with no sandbox and no prompt.

Seven agents affected. goose, Codex CLI, Codex Desktop and Cursor are patched. Hermes Agent, Qwen Code and Grok Build are not - Qwen accepted the report on 7 July and has shipped nothing since.

The detail most coverage buried: Claude Code patched the core.fsmonitor path in 2.1.196, but a second path was confirmed live in 2.1.258. Updating does not close it.

One-line mitigation: git config --global core.fsmonitor false

Full version table, CVEs and what to check

349 agent skills point at domains nobody owns

Manifold Security found placeholder domains across roughly 359,000 GitHub files, used by 349 AI agent skills. Invented example domains are not reserved the way example.com is - they are merely unregistered, and anyone can buy them. Some now redirect to scam pages.

It matters more for skills than for ordinary code because skills fetch automatically, carry the agent's credentials, and nobody reads the response.

How to audit your installed skills

And a free fix for a different problem

A web-extraction benchmark found models invented 70.7% of fields that were absent from the page. Adding one sentence - "Use null for any field whose value is not on the page. Do not guess" - dropped it to 20.2%.

Gemini 3.8 Flash and GLM 5.3 fabricated 1 of 36. Firecrawl, a paid extraction API, invented 24 of 36. And a cheap verifier pass with GPT-6 Luna caught 38 of 49 fabrications while rejecting zero correct answers.

The full results and what to change in your prompts

Tomorrow

OpenAI DevDay, 29 September, San Francisco. OpenAI has confirmed the date and location; no agenda has been published. Plenty is circulating about what will be announced and none of it is sourced well enough to repeat here - we will cover what is actually shown.

What to watch

Whether Qwen Code and Grok Build ship a patch. Both have had the GitSpawn report for weeks, one closed it as informative, and how a vendor handles a disclosure is a better signal about a coding agent than any benchmark score.

Tags
AI NewsClaude CodeCoding AIAI agents2026
⚑

Spot an inaccuracy?

We verify facts before publishing and correct errors promptly. If something in this article is wrong or outdated, let us know.

Report an error →
💡 AI Tools prompts
Prompt Guide
Best Claude AI Prompts for SEO (2026) — Content, Technical, and Comparison SEO
Claude Sonnet 5 and Opus 5 are strong for SEO work that requires writing quality, structured analysis, and long-form content generation. With 1M context, Claude can analyse an entire site's content structure, compare competing pages, and write complete article drafts in one session. These prompts cover the full SEO workflow: keyword research synthesis, content briefs, on-page optimisation, meta descriptions, technical audit interpretation, and comparison content that ranks above AI Overviews.
Get Prompts →
Prompt Guide
Best ChatGPT Prompts for SEO (2026) — GPT-5.6 and Browse
ChatGPT with GPT-5.6 Sol and Browse enabled is a capable SEO research tool — it can search the live web, analyse SERP results, and synthesise content briefs in a single session. GPT-5.6 Terra at $2.50/M offers a cost-efficient option for high-volume SEO content generation. These prompts are optimised for ChatGPT Plus with Browse, the ChatGPT Work product for larger projects, and the OpenAI API with web_search tool enabled.
Get Prompts →
Prompt Guide
Best Claude Opus 5 and Sonnet 5 Prompts for Writing (2026)
Claude Opus 5 and Sonnet 5 consistently produce the highest-quality long-form writing of any AI model in July 2026 — a lead documented across writing benchmarks and user testing since Claude 3 Opus. With 1M context and 128K output on Opus 5, Claude can write book chapters, complete reports, and long-form content without truncating. Sonnet 5 at $2/$10/M (intro through August 31) is the best value writing model available. These prompts are optimised for claude.ai Pro/Max, Claude Cowork, and the API.
Get Prompts →