PM Stack Daily logo

PM Stack Daily

Archives
Log in
Subscribe
September 25, 2026

Amazon blocked Meta's shopping agent. That's the real AI story this week.

Issue #042 · 4 min read

Amazon blocked Meta's shopping agent. That's the real AI story this week.

Amazon just showed Meta's agent the door, and Muse has a 0-day too.

The big story

Amazon just showed everyone what platform power actually looks like in the agent era.

Amazon has blocked Meta's AI shopping agent, Muse, from using Amazon.com. Muse is Meta's new agent that browses and buys on your behalf. Amazon simply shut the door — TechCrunch reports Amazon has its own foundation models and one of the most popular inference platforms around, and faces no legal obligation to let a rival's agent shop its site.

The timing makes it sting more. Appfigures data cited by TechCrunch shows Muse has already out-downloaded and out-DAU'd ChatGPT's early mobile launch in the US and Canada, over the same stretch of time after release. Muse is winning the popularity race and losing the access race, in the same week.

The Verge has the same story from Amazon's side: it's a straightforward gatekeeping move, not a technical glitch.

There's a second wrinkle. Muse also has a serious 0-day — a hole with no patch yet — that a simple trick called ClickFix can use to hijack the agent completely, according to Ars Technica. An agent this privileged, blocked by one retailer and exploitable by attackers, is not a great two-day stretch for Meta.

For anyone building an agent that needs to act on someone else's website: you don't own that door. The site owner does, and they will close it the moment your agent looks like competition rather than a customer.

What shipped

Grok 4.7 landed in GitHub Copilot, built on Grok 4.6 and aimed at agentic coding and multistep work, per the changelog. It's also live on Vercel's AI Gateway at 40% off. If you're routing model choice through Copilot or Vercel, this is a cheap way to try a new reasoning model on real agentic tasks this week rather than a synthetic benchmark.

GitHub's repository pull requests page is now generally available, making it easier to find and act on PRs, per the changelog. Small, but if your team lives in PR review, worth a five-minute look before someone on your team quietly starts complaining about the old one.

GitHub Enterprise now lets owners export a full credential inventory — every SSH key, personal access token, and OAuth token that can touch the enterprise, per the changelog. Not glamorous, but if you own security posture for an eng org, this is the kind of export that turns a vague "who has access to what" question into an actual answer.

Skipping GitHub's CodeQL bundle deprecation and code-coverage API changes today — both are real but squarely for people who maintain CI pipelines, not product roadmaps.

What I'd actually do this week

  1. If your product lets an agent (yours or a partner's) act on a third-party site, check today whether that site could block you the way Amazon just blocked Meta. Write down what happens to your roadmap if they do.
  2. Try Grok 4.7 in Copilot on one real, gnarly multistep coding task your team has been avoiding. Compare it to whatever model you're currently defaulting to, not to a benchmark.
  3. If you own enterprise security or compliance conversations, pull GitHub's new credential inventory export and actually read it before your next audit ask.

Hit reply if you've already run into an agent getting blocked by a partner's site — I want to hear about it.


Tools mentioned

  • GitHub Copilot Grok 4.7
  • Vercel AI Gateway Grok 4.7
  • GitHub repository pull requests page
  • GitHub Enterprise credential inventory exports

Read this issue on the web  ·  PM Stack Daily

Don't miss what's next. Subscribe to PM Stack Daily:
← Newer Meta built a copy of OpenClaw, then got hacked through it Older → Google's agent hacked someone too. It just didn't say so.
Powered by Buttondown, the easiest way to start and grow your newsletter.