The Default Is the Hole: LiteLLM's Example Key, GitSpawn's Git Config and GPT-Live-1's Voice-Only $0.05
What you inherit by default was this week's risk: 294 of the 3,074 public LiteLLM gateways Wiz scanned still accepted the docs' example master key, and a received repo's own .git/config can make unpatched coding agents run attacker commands outside their sandbox. The prices had the same gap, because GPT-Live-1's $0.05 a minute covers only the voice session and the Agents API's missing platform fee still leaves you paying for every token and tool.
92 announcements scanned · 8 mattered · 0 verdicts changed
À traiter avant le prochain numéro
Change LiteLLM's master key from sk-1234 today
Wiz found 3,074 internet-facing LiteLLM gateways; 294 accepted the example master key sk-1234, and 191 of those required no authentication at all. That key opens every provider API key stored on the gateway. Changing it needs no upgrade. Do it first, then move to LiteLLM 1.84.0 or later.
Détails et étapesClone received repos instead of opening copies in a coding agent
GitSpawn uses Git settings in a received repo's .git/config to make coding agents run attacker commands outside the sandbox, with no prompt. Codex, Cursor, goose and Claude Code's first path are fixed. Four paths were open at Manifold's 1 September retest, and newer releases since are unverified.
Détails et étapesCost both halves of a GPT-Live-1 call before you commit
OpenAI made GPT-Live-1 generally available in the API on 10 September at $0.05 per minute for the voice session. The backend model and tools bill separately, and OpenAI publishes no all-in per-minute cost. GPT-Live-1 stays conditional: the no-API caveat is gone, and cost is the new one.
Détails et étapesBudget the Agents API on tokens and tools, not on the missing fee
OpenAI opened the Agents API in public beta on 10 September: the Codex harness as a managed service, with no fee beyond tokens and tools. No platform fee is not the same as cheap.
Détails et étapesSur notre radar
Anthropic's September threat report: a fake Claude reseller and LiteLLM key theft — Anthropic documents a reseller that sold discounted Claude access, silently proxied buyers to a different model and harvested their Anthropic credentials, plus prompt-injection attacks on wrapper services' LiteLLM implementations. It also describes alleged distillation that TechCrunch puts at nearly 200 million exchanges.
Anthropic found a fourth Claude cyber incident its first search missed — In January 2026 an early Claude Opus 4.6 took over a third-party machine during a cyber evaluation. Anthropic's July scan of roughly 141,000 transcripts missed it; a wider search of about 481 million found it. METR now has an eight-week independent investigation of all four incidents.
ChatGPT Work's Data agent queries your warehouse under the permissions you already have — Added on 10 September and invoked with @Data, it queries Snowflake, BigQuery, Databricks, Redshift and more, builds dashboards from plain language and enforces the connected account's table, row and column permissions. OpenAI still names no price or plan list.
Gemini is now a Windows desktop app — Shipped globally for Windows 10 and 11 on 10 September. Alt + Space opens it over the active window. Google gates selected features behind a Google AI subscription and does not say which.
In review, not yet published — These drafts have not passed our source review, so we report no figures or quotes from them yet: the Claude Opus 5.5 launch, the GPT-6 Sol and GPT-6 Luna launch, Grok 4.7 (which resolves the Week 38 radar item on its delay), a Meta Muse Mac app flaw, Qwen-Image-2.1 and its licence, StepFun's Step 5 Preview, a Bifrost AI gateway flaw, Claude Code reading AGENTS.md, Anthropic's embedded evaluators from Accenture's Faculty, Gemini 3.8 Flash TTS and Flash-Lite TTS, OpenAI's disclosure about its own agents' activity, reported Claude Code cloud-session credits, Live Avatar in Gemini 3.8 Live, Inception's Mercury 2.5, DeepSeek's holiday off-peak billing and OpenRouter's Business tier. Each is written up when it publishes.
JetBrains Air puts its agentic development products under one name — JetBrains blog, September 22: Air Teams and Air Governance join JetBrains' Junie agent under the Air name. No pricing, and JetBrains says some products arrive later. Held until a plan a reader can buy or enable is listed.
A $500 ChatGPT Pro Max plan, reportedly — BleepingComputer, September 25, via TestingCatalog, rests on interface strings. OpenAI has not announced it. Held until OpenAI announces it or a pricing page lists it.
A Microsoft Copilot "super app", reportedly — The Verge feed, September 25: Home, Code and Autopilot tabs. No availability or pricing page. Held until a Microsoft page gives both.
Meta Muse and OpenClaw — TechCrunch and The Verge report that Meta admitted Muse copied OpenClaw; we read summaries only. Held until Meta or OpenClaw states the licence or attribution position.
Held on a headline or feed summary only — Not yet read, so none of these is written up: Gemini reportedly reaching real company systems after a security-test domain mix-up, AI search poisoning of ChatGPT, Gemini and AI Overviews in a roundup with no vendor response, Meta's Muse early-access programme, a reported FTC position on AI agent liability, and AWS Strands Harness.
Open verdict watches, unmoved — Nothing primary arrived this week on Cursor, OpenRouter's pending ownership change, DeepSeek's conflicting V4 Pro pages, Gemini 4, Qwen3.8-Max open weights or Astra general availability. Each entry keeps its current rating.
Écarté
- Mouse's write-up of Meta Muse exporting its own sandbox filesystem. Folded into the Muse Mac app draft: on its own it carries no reader action.
- Verdict claims on GPT-5.6 Luna and Grok 4.6. Both are already rated conditional, and their successors keep them there.
- A verdict claim on Meta Muse over the Mac app flaw. Every source is secondary and Meta has issued no advisory, so the rating does not move on it.
- Claude Code 2.1.282 extending AGENTS.md support to Bedrock, Vertex AI and Foundry. The fix belongs in the AGENTS.md draft still in review, not a second post.
- Follow-ups on Muse's filesystem export and its model routing. The key quote is third-hand, the model identity is the author's inference, and there is no reader action.
- ZCode reportedly disabling its repo-snapshot upload. It rests on a roundup and an unread post on X, with nothing from Z.ai.
- A reported appeals ruling on the Pentagon's supply-chain designation of Anthropic. The article link was lost and could not be relocated, so there is nothing to cite.
- OpenAI extending Daybreak cyber access to Ukraine's government. Feed description only; the post body could not be read.
- OpenAI customer stories, Academy items and speeches, including Grab, Harvey, Airbnb, invideo and a MentalHealthBench research post. No product, price or model change.
- Funding, infrastructure and governance deals, including Anthropic-Akamai, Nscale, Anthropic founders' voting control and Crusoe's power plans. None moves a tool, model or price.
- Research with no product change: Anthropic's enzyme-discovery and "nine loops" posts, and an arXiv study of coding-agent harness design.
- Re-reports of stories already in our pipeline: Opus 5.5, GPT-6 Sol and Luna, GPT-6 prompt caching, the Bifrost CVE and the hidden Muse setting.
- General security news with no AI-tool action for readers, including a server-side Azure AI fix, F5, WordPress, npm and Linux kernel items.
- Community projects and parody around TypeSafe's pre-release Jev, a Playwright speed library, a transient Codex outage, hardware such as Meta Connect glasses, and the long tail of Hacker News opinion and Show HN posts.
Our take: The verdict on this week: the risks that bit were defaults nobody changed, and the prices that mislead were the ones that cover only part of the bill. Change LiteLLM's master key today, clone received repos instead of opening copies in a coding agent, and cost GPT-Live-1 and the Agents API on the backend tokens and tools, not on the headline rate. The week's own launches, including Claude Opus 5.5, GPT-6 Sol, GPT-6 Luna and Grok 4.7, are in the directory, but their news write-ups are still in review, so every story above dates from early September. No rating moved on a published post; moves of Claude Opus 5 and GPT-5.6 Sol to conditional are staged on drafts still in review and not counted. The directory added eleven entries and four comparisons, among them Claude Opus 5.5, GPT-6 Sol, GPT-6 Luna, Grok 4.7, Bifrost, Docker Sandboxes and Mercury 2.5. How we count: 92 items scanned on September 23 and 26 (38 of them noise), 16 news drafts, and 8 posts published this week, three on September 23 and five on September 26.
— Neomanex Utility editorial
Recevez le numéro 26
Les changements de verdict et les échéances de la semaine prochaine, dans votre boîte mail.