Appiness
Appiness #19
Three labs shipped agents built to act on their own, the same week researchers showed a plain git setting can make those agents run code nobody approved.

Tech
- Three frontier releases in three days. Anthropic shipped Claude Sonnet 5.5 on 28 September, aimed at coding, documents and spreadsheets at $2 / $10 per million tokens. Google followed on 30 September with Gemini 4 Argon and a one-million-token context window.
- OpenAI's Dots, launched on 29 September, are agents that keep running toward a goal on their own cloud computers and connect to Slack, Teams and thousands of other apps.
- Researchers at Manifold Security published GitSpawn: eight flaws across Claude Code, Codex, Cursor, Goose and other coding agents. A setting such as
core.fsmonitorin an untrusted repo runs code outside the sandbox and skips the approval prompt. Four were unpatched at publication.
Design
- Figma Motion entered open beta on 30 September with reusable styles, audio, text animation and Lottie export. Motion now leaves Figma as a production file instead of a video for a developer to rebuild.
- The same release round added vertical wrap to auto layout, so multi-column layouts stay responsive as content grows, and connected Figma Design files to Weave workflows.
Business
- German DTCP closed €455 million for its first defence fund and backed Norway's Six Robotics, which builds autonomy software for unmanned systems. Final Frontier and Myriad Defence are raising a €100 million Nordic defence fund of their own.
- Oslo's Pistachio bought Hugin.io to build a compliance product for NIS2, ISO 27001, SOC 2 and DORA, due in 2027. Regulation is turning into a product category for Nordic SMBs.
The Apps take
The model launches and GitSpawn are one story. Each release this week gives an agent more room to act without asking. GitSpawn shows where that room ends up: in a config file nobody reviewed, running before the approval prompt appears. When software acts on its own, the risk moves from a wrong answer to a wrong action, and a wrong action enters through the integration surface. A repository is input to the agent in the same way a build script is input to CI. Treat it that way: a repo an agent opens is untrusted until someone has read its git config and pinned its plugins. No model comparison will tell you whether that has happened.


