Work with AI, better.
This week in AI
What changed and what it changes for you — triaged, not dumped.
GitSpawn: A Received Repo's .git/config Runs Code Outside Coding Agents' Sandboxes
GitSpawn: Git settings in a received repo's .git/config make coding agents run attacker commands outside the sandbox, with no prompt. Codex, Cursor, goose and Claude Code's first path are fixed. Four paths were open at Manifold's 1 September retest, and newer releases since are unverified. Clone, do not open received copies.
Nearly 1 in 10 Public LiteLLM Gateways Wiz Scanned Accepted the Docs' Example Master Key, sk-1234
Wiz found 3,074 internet-facing LiteLLM gateways; 294 accepted the example master key sk-1234, and 191 of those required no authentication at all. That key opens every provider API key stored on the gateway. Changing it needs no upgrade. Do it today, then move to LiteLLM 1.84.0 or later.
Security
OpenAI's Agents API Turns the Codex Harness Into a Managed Service, With No Platform Fee
OpenAI opened the Agents API in public beta on 10 September: the Codex harness as a managed service, with no fee beyond tokens and tools. No platform fee is not the same as cheap.
Agents
Report: OpenAI Pauses New $200 ChatGPT Pro Sign-Ups Over Astra Demand
OpenAI's Thibault Sottiaux said on X that new sign-ups to the $200-a-month ChatGPT Pro plan are paused because Pro puts the most strain on OpenAI's systems, TechCrunch reports. The API, Go and Plus stay open, and no end date was given. If you wanted Pro for Astra, the API and Plus both still reach it.
Pricing
The week, in one issue
What changed and how it changes our recommendations — including what we filtered out.
Same Name, Different Deal: DeepSeek's Swapped Model, Sonnet 5's Permanent Price and a Reported Pro Pause
Every story we published this week changed what an existing name buys you: the deepseek-v4-flash id now serves V4.1-Flash at $0.15/$0.60 per 1M off-peak, Claude Sonnet 5's $2/$10 launch price is now its standard rate, and GLM-5.3-Flash's $0.075/$0.25 launch rate gave way to $0.15/$0.50. TechCrunch reports OpenAI has paused new $200 ChatGPT Pro sign-ups, which leaves the API and Plus as the ways to reach Astra.
What changed our minds
Recommendation flips from this week — with the reason on record.
Claude Sonnet 5 (basis change, rating held)
The rating did not move, so this is not counted in the week's verdict changes. The basis did: our entry described $2/$10 per 1M as introductory pricing that expired on 31 August 2026. Anthropic cancelled the scheduled increase to $3/$15, so $2/$10 is now the standard rate, 40 percent of the $5/$25 Opus rate. Announced September 14 by claude-sonnet-5-price-cut-made-permanent.
GLM-5.3 (basis change, rating held)
The rating did not move, so this is not counted in the week's verdict changes. The summary was corrected: it said per-token pricing was unpublished, but Z.ai lists GLM-5.3 at $1.40/$4.40 per 1M, and the entry had stored the expired GLM-5.3-Flash launch promotion as the list rate. GLM-5.3 stays conditional because its headline coding and cyber scores come from Z.ai's own evaluations. Announced September 14 by glm-5-3-flash-launch-discount-ends.
From the blog
The reasoning behind the verdicts, long-form.
Typeform Alternatives That Are Not Just Cheaper Typeforms
Eight Typeform alternatives sorted by the reason you are leaving, not by vendor preference. Verified pricing, standing verdicts, and the response cap that sends most people looking.
Sep 7, 2026
AI Intake Software Compared: What the Term Means and What to Buy
Search AI intake software and you get two unrelated markets in one result page. Here is the split, the four things AI can actually do to intake, and verified pricing on the tools that do it.
Sep 7, 2026
Best Conversational Form Builders in 2026: 9 Tools With Verdicts
Nine conversational form builders, each carrying a standing verdict from our directory. Verified pricing, the three products hiding behind one label, and which one wins each job.
Sep 7, 2026
Never need to catch up again
The weekly delta — only verdict changes and act-now items. No digest filler.
What do you need to do?
Start here. Pick a task and we'll point you to the right resource.
Our tools
We built these because nothing else solved the problem.
Gnosari
Gnosari is a conversational data collection platform: it replaces forms with conversations. Feedback, details, contacts, anything you need to gather, you say what you want to collect and the agent drives the conversation.
"We built it because forms lose most of the people who reach a page."
ConvOps
ConvOps is the workflow engine for autonomous AI systems: describe a process once from the AI client you already use, and your agents run it as a governed workflow, step by step, run after run.
"We built it to run Neomanex itself."
NeoReader
NeoReader is a web-to-markdown API with discovery built in: point it at a URL or a whole site and get back clean, LLM-ready markdown, tuned end to end for high-throughput ingestion.
"We built it because feeding raw web pages to a model wastes tokens and drags in boilerplate."
This site updates itself
Every changelog entry, model comparison, and tool listing is maintained by the same AI pipelines we build for our clients. No manual updates, no stale data.