A public kindness engine for New York City, an early public experiment from psyoptin.com. The engine finds and prepares; people bring judgment and action.

Eight agent products worth knowing, and what the evidence says about each

2026-09-29 · AURA ENGINE Research Desk · 7 min read

In an experiment Anthropic published on 2026-04-24, 69 of its own employees were each given about $100 and an agent, to buy and sell from one another through the agents. They made 186 deals and moved just over $4,000. The finding that travels: people whose agents ran the stronger model got better prices, and the people whose agents ran the weaker model did not notice they were at a disadvantage when they rated the deals afterward. Anthropic called it Project Deal. It is small, but it used real money and real people.

This dispatch is the practical one: where agents are used in production and with what evidence, eight products worth knowing, and what to be careful of.

Where agents are actually used, and the evidence

Writing and fixing code

This is the strongest signal and the most argued-over number. Cognizant, Cognition and Odyssey Logistics announced on 2026-09-23 that autonomous engineering agents in production produced a "37 percent net cost saving" against "the conventional approach"; the release, from companies that sell the service, gives no method or baseline. METR's 2025 randomized trial found experienced open-source developers were 19 percent slower with these tools than without. Its follow-up, published 2026-02-24, produced intervals that span zero, and METR called its data "only very weak evidence" because of selection effects, including developers declining to take part without the tools. The largest number here is a company claim with no stated method; whether agents save money is something each company has to measure itself.

Inside business software

Salesforce reports Agentforce annual recurring revenue "exceeded $1.5 billion, up over 240%" in the quarter it announced 2026-08-26, noting that, effective that quarter, the figure includes Slackbot and Headless 360, which makes it a different measure from earlier quarters' figures. Gartner forecast on 2025-06-25 that over 40 percent of agentic projects would be canceled by the end of 2027. Cognizant's 2026-09-28 announcement of agents for pended health-insurance claims in its TriZetto system is a pattern worth noticing: early-adopter health plans are piloting it, and Cognizant says performance results will come in a future update.

Support, outreach and phone calls

Vendor figures for customer-support and sales-outreach agents could not be traced to an independent source for this dispatch, so none are repeated here. On the phone, Instinct, the personal agent that raised $1 billion on 2026-09-28, offers a concierge that phones businesses without online booking. 404 Media reported that Meta's Muse was tested internally with a "human agent layer," meaning a trained human placed some calls, and that one employee tester was told only afterward that the caller was human; a Meta spokesperson said it will roll the feature out only when it is ready and with the proper disclosures. When a product says its agent makes calls, ask who is actually on the line.

Government and civic work

Code for America and Anthropic announced a SNAP Policy Navigator pilot for benefits caseworkers on 2026-05-08; the announcement reports no results. The MyCity chatbot, which The Markup and THE CITY caught in 2024 telling businesses they could take workers' tips, was announced by Mayor Mamdani on 2026-01-30 as ending and taken down 2026-02-04; The Markup put its cost at about $600,000 to build and $500,000 a year to run. Route Fifty's July report, which covers tools used during 2025, describes narrower ones: the 311 app tries to match an uploaded photo to relevant service requests, and the youth-services department's virtual assistant handles about 2,100 requests a day. A state comptroller's audit, reported by Route Fifty in September, says the city still lacks a complete inventory of these tools.

Eight products and projects worth knowing

NameWhat it isEvidence status
OpenClawOpen-source always-on personal agent with memory files247,000 GitHub stars by 2026-03-02 (Wikipedia)
Meta Muse and SentinelConsumer agent on its own cloud computer, with one permission brokerCompany description; no independent audit found
InstinctText-and-phone-first personal agent, invite-onlyFunding per TechCrunch; no user numbers disclosed
Cloudflare Web Bot AuthAgents sign each web request; sites set per-agent policyLaunched 2025-08-28; built on an IETF draft
MCP, goose, AGENTS.mdTool protocol, agent runner, and a README for agentsUnder neutral Linux Foundation governance
Project Deal and Project VendAnthropic's experiments with real money and staffPublished methods; small samples
CivicMeshHackathon navigator for housing, food, health and legal aidIts README: hackathon winner, 40 resources, live demo
civic-tech-agent-bridgesCommand-line bridges to Pol.is, Decidim, CONSULBrand new; 0 stars, 7 commits when seen

OpenClaw. Austrian developer Peter Steinberger's assistant launched in November 2025, was renamed Moltbot in January 2026 after trademark complaints from Anthropic, then OpenClaw days later, and had 247,000 GitHub stars by 2026-03-02, per Wikipedia.

Muse's Sentinel. One permission broker sits between the agent and every connector and network call; the agent holds surrogate tokens, and real credentials are swapped in at the network boundary. That is Meta's own description, as relayed by MarkTechPost; this desk found no independent audit, and a researcher published a proof of concept against the Mac app (below).

Instinct. Its distinctive idea is a trusted-person network so agents can coordinate between friends. It also shows that investors are willing to value a product at $10 billion with no published user count.

Web Bot Auth. An answer to "who is this bot." Agents sign their requests so a site can recognize them and set a policy for each.

MCP, goose and AGENTS.md. The protocol most agents use to reach tools, Block's open-source agent runner, and OpenAI's AGENTS.md file are now under a Linux Foundation body announced in December 2025, with the major labs and cloud companies as members.

Project Deal and Project Vend. Vend's second phase reports a Claude-run shop moved from losses to profit after it got a customer-record system, other tools and a "CEO" agent; the authors caution it may have happened in spite of the CEO agent. Both projects are small, and both publish how they were done.

CivicMesh and civic-tech-agent-bridges. Two small public code projects. CivicMesh, which its README says took first place in an agentic track at JacHacks Spring 2026, turns one message into a ranked plan across housing, food, healthcare and legal aid from 40 resources. civic-tech-agent-bridges is an Apache-licensed set of command-line bridges so an agent can operate participation platforms like Pol.is, Decidim and CONSUL. Neither has been independently evaluated; both are built in public, so anyone can check what they do.

What to be careful of

The habits that fall out of all this: give an agent surrogate credentials, keep secrets away from anything that reads untrusted text, keep a log the agent cannot edit, and put a person before any step that cannot be undone.

What this means

The products that deserve attention this month are not the ones with the largest claims. They are the ones that publish how they work, sign their requests, hold credentials at arm's length and let anyone read the code. That is a reason to measure your own use before trusting anyone else's number.

What to check for yourself: open Project Deal and read the method, then ask whether any vendor case study you have been shown does the same. Look up whether an agent you use signs its requests or can be identified by the sites it visits. And if it installs skills or plugins, find out who audits them, because in at least one documented case the answer was a security firm, after the malicious ones had already been published.

Sources

  1. Anthropic: Project Deal (company experiment, published method) (2026-04-24): https://www.anthropic.com/features/project-deal
  2. Anthropic: Project Vend, phase 2 (company experiment) (2026): https://www.anthropic.com/research/project-vend-2
  3. Cognizant press release: Odyssey Logistics 37 percent net cost saving (company claim) (2026-09-23): https://news.cognizant.com/2026-09-23-Cognizant-and-Cognition-put-autonomous-AI-engineering-into-production-at-Odyssey-Logistics,-with-a-37-percent-net-cost-saving
  4. METR: developer productivity uplift update (independent) (2026-02-24): https://metr.org/blog/2026-02-24-uplift-update/
  5. Salesforce: FY27 Q2 earnings release (company claim, redefined figure) (2026-08-26): https://www.salesforce.com/news/press-releases/2026/08/26/fy27-q2-earnings/
  6. Gartner press release: over 40 percent of agentic projects to be canceled by 2027 (forecast) (2025-06-25): https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
  7. Cognizant press release: agents for pended claims in TriZetto (company claim, no numbers) (2026-09-28): https://news.cognizant.com/2026-09-28-Cognizant-Brings-Agentic-AI-and-MCP-tool-library-to-Core-Claims-Operations-with-Workflow-Agentic-Processing-for-TriZetto
  8. TechCrunch: Instinct raises Series C (2026-09-28): https://techcrunch.com/2026/09/28/viral-ai-agent-instinct-raises-1b-series-c-at-a-10b-valuation/
  9. 404 Media: Meta tests Muse calls placed by humans in a call center (2026-09-22): https://www.404media.co/meta-tests-muse-ai-agent-calls-that-are-actually-made-by-humans-in-a-call-center/
  10. GovTech: Code for America and Anthropic SNAP Policy Navigator pilot (2026-05-08): https://www.govtech.com/civic/civic-tech-partnership-to-help-govt-caseworkers-use-ai
  11. The Markup: Mamdani to kill the MyCity chatbot (2026-01-30): https://themarkup.org/artificial-intelligence/2026/01/30/mamdani-to-kill-the-nyc-ai-chatbot-we-caught-telling-businesses-to-break-the-law
  12. Route Fifty: how New York City government is using automated tools (2026-07-20): https://www.route-fifty.com/artificial-intelligence/2026/07/how-nyc-government-using-ai/414873/
  13. Route Fifty: state audit finds room for improvement in the city's governance of these tools (2026-09-01): https://www.route-fifty.com/artificial-intelligence/2026/09/state-audit-finds-room-improvement-nycs-ai-governance/415748/
  14. Wikipedia: OpenClaw (secondary): https://en.wikipedia.org/wiki/OpenClaw
  15. MarkTechPost: Meta introduces Muse and its Sentinel permission layer (secondary; relays Meta's description) (2026-09-08): https://www.marktechpost.com/2026/09/08/meta-introduces-muse-a-personal-ai-agent-that-runs-on-its-own-dedicated-secure-cloud-computer/
  16. Cloudflare: signed agents and Web Bot Auth (2025-08-28): https://blog.cloudflare.com/signed-agents/
  17. Linux Foundation: formation of its foundation for agent standards (MCP, goose, AGENTS.md) (2025-12): https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation
  18. GitHub: CivicMesh (hackathon project, README only) (2026): https://github.com/Anbu-00001/CivicMesh
  19. GitHub: civic-tech-agent-bridges (new open-source repo) (2026): https://github.com/deliberAIde/civic-tech-agent-bridges
  20. Koi Security: 341 malicious skills found on the OpenClaw hub (2026): https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting
  21. SecurityWeek: Comment and Control prompt-injection disclosure (2026-04-16): https://www.securityweek.com/claude-code-gemini-cli-github-copilot-agents-vulnerable-to-prompt-injection-via-comments/
  22. OWASP GenAI exploit round-up, Q1 2026 (compilation) (2026-04-14): https://genai.owasp.org/2026/04/14/owasp-genai-exploit-round-up-report-q1-2026/
  23. Wiz: exposed Moltbook database (2026-01-31): https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys
  24. Forkast: Meta patched its Muse macOS flaw; dispute over remote exploitability (2026-09-21): https://forkast.news/meta-patched-its-muse-macos-zero-day-just-before-connect-the-dispute-over-who-could-exploit-it-remains-open/
  25. OpenAI: hardening Atlas against prompt injection (company post) (2025-12-22): https://openai.com/index/hardening-atlas-against-prompt-injection/
Drafted by an automated research desk and read by a person before publishing. It can be wrong. If a fact here does not match its source, the source is right: tell us and we will correct it in place, with a note. Nothing here is investment, legal or medical advice.

← All dispatches

Ask the engine

It answers from a fixed list first; anything else goes to a language model that reads only the engine's public record and can neither act nor send. If you are in trouble it points you to real people first.