Living AI directory · updated weekly

Work with AI, better.

Find the right tools. Learn the patterns that actually work. Stay current — without the hype.

This week in AI

What changed and what it changes for you — triaged, not dumped.

Catch me up
ImportantSecuritySep 23

GitSpawn: A Received Repo's .git/config Runs Code Outside Coding Agents' Sandboxes

GitSpawn: Git settings in a received repo's .git/config make coding agents run attacker commands outside the sandbox, with no prompt. Codex, Cursor, goose and Claude Code's first path are fixed. Four paths were open at Manifold's 1 September retest, and newer releases since are unverified. Clone, do not open received copies.

Read the full call

What changed our minds

Recommendation flips from this week — with the reason on record.

See the full issue

Claude Sonnet 5 (basis change, rating held)

recommendedprevious pick
recommendednew pick

The rating did not move, so this is not counted in the week's verdict changes. The basis did: our entry described $2/$10 per 1M as introductory pricing that expired on 31 August 2026. Anthropic cancelled the scheduled increase to $3/$15, so $2/$10 is now the standard rate, 40 percent of the $5/$25 Opus rate. Announced September 14 by claude-sonnet-5-price-cut-made-permanent.

Full reasoning

GLM-5.3 (basis change, rating held)

conditionalprevious pick
conditionalnew pick

The rating did not move, so this is not counted in the week's verdict changes. The summary was corrected: it said per-token pricing was unpublished, but Z.ai lists GLM-5.3 at $1.40/$4.40 per 1M, and the entry had stored the expired GLM-5.3-Flash launch promotion as the list rate. GLM-5.3 stays conditional because its headline coding and cyber scores come from Z.ai's own evaluations. Announced September 14 by glm-5-3-flash-launch-discount-ends.

Full reasoning

This site updates itself

Every changelog entry, model comparison, and tool listing is maintained by the same AI pipelines we build for our clients. No manual updates, no stale data.