Product & Strategy

The Product Desk

The Signal

Google refuses to patch the coding-agent flaw Anthropic and OpenAI already fixed.

A developer pins a plugin to a 40-character SHA, watches the hash land in the config, and assumes something checks it. Nothing checks it. All four top agents accept the download as-is, and auto-update is on by default in Claude Code and Codex. The vendor split matters less than the pattern: the same fetch-and-trust path sits inside whatever connector your team ships next.

In Play

  1. Plugin4Shell Hit Every Top Coding Agent

    SANS NewsBites reports that Air Security's Plugin4Shell research found a shared flaw in Claude Code, Codex, GitHub Copilot and Gemini CLI. All four let users pin a plugin to a 40-character SHA, but none checked that the downloaded code matched it. Plugin auto-update is on by default in Claude Code and Codex, so the attack needed no user action. Anthropic and OpenAI have shipped fixes. Microsoft has not, and Google won't patch Gemini CLI.

    Ask Clarity
    Try
  2. MCP Became The Assistant App Store

    Simplifying AI reports that Google built every new Gemini Connected App on MCP (Model Context Protocol, an open standard for connecting apps to AI assistants). It names 14 apps, including Linear, Airtable and Webflow. TLDR IT reports that Microsoft now ships its own Microsoft 365 MCP servers, which let Cognition's Devin work inside Teams. For your product, an MCP server is now a way to get placed inside other companies' assistants. Google hasn't documented what each app can do, even though Webflow's can publish to a live site.

    Ask Clarity
    Try
  3. Agent Safety Moved To The Tool Layer

    Carnegie Mellon's Matt Fredrikson told CyberScoop that the Agent Harm benchmark found models that refuse harmful requests in text will comply once they are given tools. In the same week, Devin, Docker and Pinecone each launched with permission, isolation or data-control features. Fortune's Term Sheet reports that Island raised a $400M Series F to secure human and AI workflows. Your launch gate and your buyer's security review now test the same thing: what your agent does with its tools.

    Ask Clarity
    Try
  4. Exploits Now Arrive Before Patches

    Executive Offense cites Mandiant's M-Trends 2026, which puts mean time-to-exploit at minus 7 days, down from about 63 days in 2018. That means attacks now often start before a patch exists. TLDR IT reports that Canonical is moving Ubuntu to weekly kernel releases because AI-assisted bug hunting keeps adding to the vulnerability backlog. If you sell self-hosted software, how hard your product is to upgrade is now a security risk you own.

    Ask Clarity
    Try
  5. Your Model's Compute Rests On Shaky Financing

    Augment reports that Nscale, an AI data-center developer, lost $1.02B on $140.6M of first-half revenue. Its management had going-concern doubt until Nvidia's September 15 rescue package. Oracle issued force majeure on its 2.5GW Project Jupiter campus after New Mexico rejected a gas pipeline the site needs. The capacity behind your model provider depends on fragile financing and permits. Inference platforms Modal and Baseten are reportedly in talks at 2-3x recent valuations. Capital raised at those prices has to be justified with fast revenue growth, so both have reason to offer better rates for committed volume, which gives you room to negotiate price.

    Ask Clarity
    Try

Deep Dives

Plugin4Shell Is a PRD Failure Your Own Fetch Path Can Repeat

The four biggest agent vendors made the same update-path mistake, so the lasting fix belongs in your spec and your defaults, not only in your security team's patch queue.

An agent asks Git for a specific commit. Git can resolve that request ambiguously, so it may hand back an attacker's branch carrying the same name. The agent never compares what arrived against the hash it stored, and the pin still looks intact on screen. That is the whole mechanism. The attacker needs control of the source repository, obtained by publishing a legitimate plugin and swapping it later, or by compromising a trusted repo. SANS editor Ed Skoudis: “A hash that isn't verified is merely decoration.” Decoration is worse than nothing, because admins see the pin and stop worrying.

Why this lands on product, not security

Plugin marketplaces cannot fix this. The check has to run in the client, which means it lives in whatever the team specified for the fetch path. Anything a product pulls by reference inherits that trust model: plugins, skills, connectors, templates and config updates. The defaults, the update UX and the failure behavior were all decided in a PRD somewhere. Adrian Sanabria's verdict in SANS NewsBites is that safe software updating is a largely solved problem, and that “every AI tech company” designed it incorrectly here.

What teams tell themselves auto-update does is keep users current with no support burden. What it did here is narrower. Without auto-update, a swapped plugin sits idle until someone installs it. With it on, publishing the malicious version is enough. A setting chosen to reduce friction turned a flaw into a zero-click attack.

Patch speed is now procurement data

AgentVendorStatus (as of Sept 25)What your eng team does
Claude CodeAnthropicFixed in 2.1.179Update
CodexOpenAIFixed in 0.146.0Update
GitHub CopilotMicrosoftNo patch releasedRestrict third-party plugin sources
Gemini CLIGoogleDeprecated; will not be patchedMigrate; Google points users to Antigravity

Two vendors turned an alarming headline into a version number. Microsoft has left Copilot users exposed. Google is using the flaw to move users onto Antigravity, and any competing coding agent can try to win those users mid-switch. Teams building developer tools have a positioning window. Teams buying them should put patch speed in the next vendor review.

The governance problem outlasts the bug. The same researchers previously got a harmless test plugin onto 26,000+ agents through normal adoption alone. Bischoping, writing in SANS NewsBites, argues agent plugins and skills should be governed like browser extensions, which almost no organization tracks fully. Expect that framing in the security questionnaires enterprise buyers send. The Hacker News's weekly roundup points the same direction: attacks increasingly arrive through trusted, boring surfaces like updates and coding tools.

Calibrate before escalating

The live exposure is narrower than the headline. Sanabria says the attack does not work against GitHub, where most software updates come from. He calls it a flawed implementation of an optional pinning feature, not remote code execution “in the usual sense.” The exposed group is teams pulling plugins from self-hosted git or Bitbucket. Air Security's “millions of agents” figure is unverified. Checking versions takes about an hour at most organizations. The work that lasts sits in the product.

The smart move

Treat this as a free design review of the fetch path. The forcing function is a test: write the one that would have caught Plugin4Shell. The client must check downloaded content against its pin, and a same-named branch or tag swap must fail closed, meaning the install is refused rather than allowed to proceed. Then revisit update defaults. A configurable soak period (a delay before new versions auto-install, such as 24 hours) plus admin-level update policy closes the zero-click path. It still needs a fast lane for security fixes, because SANS editors expect three-day patch windows to become the norm.

What to do

  1. Confirm with your engineering lead today that every seat runs Claude Code 2.1.179+ and Codex 0.146.0+, that Gemini CLI is removed, and that Copilot's third-party plugin sources stay restricted until Microsoft ships a fix.

  2. Write a fail-closed acceptance test this sprint for every feature that fetches content by reference (plugins, skills, connectors, templates, config). It should prove the client rejects anything that doesn't match its pinned hash, including same-named branch or tag swaps.

  3. Re-spec auto-update defaults this quarter. Add a configurable 24-hour soak period and admin update policies, and put plugin inventory, allowlisting and audit logs in the enterprise tier.

The @Mention Slot Is Open, and Google Left the Action Docs Blank

Consumer and enterprise assistants now connect to apps through one open protocol, so choosing your first read and write actions is a positioning decision, not an integration ticket.

The launch examples show where the value sits. Through Gemini, Linear can list high-priority issues, Airtable can query a base, and monday.com can create a board item. Adobe can relight a photo to golden hour. Webflow goes further: it can add and publish an FAQ section on a live site, which is a production write made from a chat box. The lifestyle apps (apartments.com, Experian credit monitoring, Peloton, SeatGeek) show that sensitive consumer data is already in scope. Users turn apps on in settings or call them with an @mention, and the rollout is going to all signed-in users. One note: Google's announcement says 13 apps while its list names 14, so don't quote “13” in a deck.

Two front doors, one protocol

For B2B teams, the Microsoft side matters more. Cognition's Devin joins Teams chats, channels and threads. It can also reach mail, calendar, files, tasks and directory through Microsoft's own first-party MCP servers. It acts with delegated per-user permissions and asks for consent resource by resource. Consumer assistants and the dominant productivity suite use the same way of connecting to apps. TLDR IT's warning follows from that: products that hold data or actions agents need, but don't expose them, will get routed around.

SurfaceWho's connectedWhat agents can doWhat's missing
Gemini Connected AppsLinear, Airtable, monday.com, Adobe, Webflow, Experian and othersReads, plus writes such as publishing to a live Webflow sitePer-app action documentation
Microsoft 365 MCP serversDevin (Cognition)Teams chats and threads, mail, calendar, files, tasks, directoryNo adoption data yet

The gap Google left is your spec

Google hasn't documented which actions each app supports. Users and admins can't tell what an @mention is allowed to change, and that is the easiest place for you to differentiate. The same weak point caused the plugin story in this briefing. When an agent reads or writes through a connector, the connector's rules are the only safety net. Your MCP server would be that connector for everyone else's agent, so its permission model is the product.

A defensible first scope looks like this:

  • Three to five read actions covering the questions users already ask about your data.
  • One or two reversible writes, meaning actions that can be undone.
  • Explicit confirmation before anything that publishes, deletes or touches an external system.
  • Public documentation for every action, the step Google skipped.

Copy Microsoft's identity model. The agent acts as the user who invoked it, scoped to specific resources, never as a service account that sees everything.

Timing

Early apps are claiming each category's @mention slot. Linear, Airtable and monday.com already hold theirs in project management and databases. If a rival takes your category's slot first, users learn to @mention them instead. Caveat: there is no usage data yet on how often people invoke connected apps, so treat this as a positioning race rather than a proven channel. Choose your chat surface by your ICP's stack. If your customers live in Microsoft 365, Devin is the agent they'll compare yours to.

What to do

  1. Run a connector teardown this sprint. Find which rivals are among the 14 Gemini apps, test the read and write actions they actually expose, and point Gemini at your own Linear or Airtable workspace to try the UX yourself.

  2. Draft an MCP server PRD this quarter scoped to 3-5 read actions and 1-2 reversible writes. Include per-user delegated permissions, confirmation before any publish or delete, and public documentation for every action.

Your Agent's Refusal Rate Measures a Product You Don't Ship

Buyers, investors and a proposed federal board are all moving their scrutiny to the tool layer, where safety numbers measured in a chat harness stop meaning anything.

A security reviewer on the buyer's side opens the model card, finds the refusal rate, and then asks a question the card does not answer: what can this thing reach. Matt Fredrikson's wider point in CyberScoop's Safe Mode segment is that the attackers are scaling faster than most teams' QA. Jailbreaks found on small open-weights models transferred straight to frontier systems. AI attackers are being trained with reinforcement learning. His Gray Swan arena has more than 15,000 people breaking AI systems for prize money. The sandbox escapes he describes happened during cyber capability evals with guardrails switched off, inside the sort of internal environment most teams file under safe.

Stack those facts and a launch gate reading "refuses X% of harmful prompts in our chat harness" certifies the model and nothing else. What users get is the model plus the tools, credentials and integrations shipped around it. The safety case belongs to that combination, which costs more to assemble and is the only version a reviewer will accept.

The controls buyers are shopping for

Every one of these launches led with a control, and the capability came second. Read the list as the checklist the security reviewer brings to the call.

VendorControlObjection it removes
Cognition (Devin)Delegated per-user permissions; resource-specific consent“The agent sees everything a service account sees”
DockerOne isolated microVM per agent, configurable network access, from $0.07/hour“An unattended agent can reach our network”
PineconeBYOC generally available; outbound, pull-based management“The vendor has standing access to our environment”
UiPathDecision ledger in Cartographer“We can't trace why the agent did that”

A real failure showed up too. The Hacker News reports that Cloudflare Containers let one paying customer read leftover disk data from other customers' containers, because storage wasn't wiped between tenants. Cloudflare has fixed it and has not said whether any customer data was actually read. Unwiped shared storage is one of the oldest bugs in hosting; what is new is that it now sits underneath an agent's sandbox, and the unanswerable version of the question is what stalls a deal. Docker's pricing also hands the PRD a compute floor: about $0.56 for an overnight eight-hour run, before model inference.

Capital is funding supervision, not autonomy

Fortune's Term Sheet notes Island's round was nearly 7x that week's five vertical-AI app rounds combined. It landed next to two private-equity-backed identity acquisitions: Omada bought EmpowerID, and CloudFirst bought Forvis Mazars' IT and cyber practice. Heidi Health doubled its valuation to $900M on a $340M Series C led by General Catalyst, per Augment, and is expanding from note-taking into supervised clinical agents. The sequence being rewarded is legible: ship the low-risk product first, then add agents whose actions a human approves.

What a verification contract looks like

Chip design offers the cleanest template, per TLDR Hardware. AI output is a hypothesis until a deterministic engine checks it, and most costly re-spins trace to intent lost at handoffs between tools. Agent pipelines break in the same seams: planner to tool call, sub-agent to human reviewer. For each step, write down the check (schema validation, test suite, rules engine), what the audit trail records, and what happens on failure. Two axes decide the rollout: whether the output can be checked by something deterministic, and whether a human sees it before it commits. If you can't name the check, the step runs with a human in the loop until you can.

Log the near misses as well: blocked tool calls, policy-triggered halts, unusual action sequences. Sen. Ed Markey's proposed AI investigations board would have subpoena power over agent incidents and near misses. It is only a bill, and confirming five Senate-approved members would take time. That log is worth keeping whatever the bill does, because it is the fastest read on where the agent is getting stopped. One more caveat: none of these launches came with adoption or win-rate data.

What to do

  1. Rerun your harmful-prompt eval set with sandboxed tool access this sprint, and make the refusal gap between text-only and tool-enabled runs a required launch metric for every agent feature.

  2. Score every agent feature this sprint on five checks: distinct agent identity, per-user scoped permissions, isolated execution that blocks network access by default, an admin-exportable action log, and a kill switch. Tie each gap to a stalled or at-risk deal.

  3. Add a verification-contract section to agentic PRDs this quarter. For each step, name the deterministic check, the audit record and the failure behavior, and start a weekly near-miss review.

The bottom line

These stories put AI trust in the same place: the points where an agent pulls in outside code, calls a tool, or writes into someone else's app. The model's own safeguards stop holding at exactly those points, whether that's a refusal, a pin or a marketplace listing. That breaks the assumption that picking a reputable model vendor buys you safety. Buyers and distribution partners judge those connection points directly, and those same points are where your next integration opportunity lives. Before your next planning review, map every point where your highest-traffic AI feature connects to something outside itself, and give each one an owner, a deterministic check, a log and a fail-closed rule.