2026-10-02 18:29 UTC
DANGMUAAI & Developer Tools, Decoded
BackAgents

OpenAI's Dots Agent Costs $100 a Month and Still Needs You

OpenAI gates its Dots agent behind a $100-per-month tier while Muse and Instinct stay free. Hands-on results split, and a patched macOS flaw raises the stakes.

DangMua EditorialOct 02, 20266 min read
OpenAI's Dots Agent Costs $100 a Month and Still Needs You

OpenAI is shipping its new Dots agent first to accounts on its highest tier, including a $100-per-month Pro plan, while rivals Muse and Instinct cost nothing.

That pricing gap is the buying decision. The Verge's Allison Johnson expensed the Pro account to test Dots on everyday tasks, and the results split sharply: weak on the open web, strong the moment the agent was pointed at something the user already controlled. Separately, security researchers published a reminder of what granting that agent desktop access entails.

What you get for the top tier

Dots follows the pattern set by Meta's Muse — blobby, anthropomorphic avatars with customizable names — but the reviewer's framing is that it feels less like a personal shopper and more like workplace software. OpenAI says users will eventually be able to run multiple Dots; right now you get one.

The interface splits into two windows: you chat with the agent in one and watch it click around a virtual machine in the other. That VM can reach apps including Blender and GIMP out of the box. You can also hand the agent access to your own computer through the desktop ChatGPT app, and call it by voice to talk a task through.

OpenAI's own pitch, per the review, is that Dots "can do nearly anything" with its cloud computer and app access.

Where it stalled

The hands-on tests did not bear that out on the open web. Asked to schedule an internet-service installation, the agent got close — it even surfaced a $100 promotional discount buried in mass-deleted email — then hit a "human check" it could not clear. Its own explanation: "This particular check needs a sustained mouse hold that my browser controls don't support."

At checkout it asked for bank account details to be typed in manually. There is no equivalent of Muse's Stripe integration that stores a card and spends through a virtual one, so the reviewer finished the transaction themselves rather than hand over a checking account number inside a virtual browser.

A second task drew a direct comparison. Looking for a free tour at a coworking space, Dots missed the option and offered to book a $35 day pass instead; Instinct's agent found the trial and booked an appointment within minutes. Elsewhere, an Ikea account login looped on a security check, and a restaurant's ordering page refused the agent outright.

The pattern the reviewer identifies is worth quoting directly, because it is the practical constraint for anyone buying this: "Something about Dot's footprint seems to get it tripped up on security checks more often than Muse or Instinct." Dots itself offered a link to OpenAI's page about sites blocking its cloud browser traffic as the explanation.

Where it worked

The agent came into its own on a target fully under the user's control: a personal website. The reviewer talked through changes section by section over roughly 10 minutes by voice, walked away, and was pinged when the next iteration was ready — "not perfect, but better." Further rounds ran through a browser window and voice-to-text on the phone app.

The summary verdict: Dots "made a lot more sense" once it had access to the user's own computer.

That is a useful line to draw for buyers. On the public web, the agent is one more automated client fighting bot defenses — and losing more often than its free competitors. On assets you own, where no anti-bot layer is in the way, the same product behaves like a usable remote colleague. If your intended workloads are the second kind, the tier is arguable; if they are the first, the free tools cleared the same obstacles the paid one did not.

The access question, and a flaw that just got patched

"Give it access to your computer" is the step that makes Dots work, and it is also the step that deserves scrutiny this week.

Researchers at the Objective-See Foundation found a vulnerability in the macOS version of the ChatGPT app that could have been exploited to take over ChatGPT on a victim's machine — reaching chat logs, other app-stored data, and interconnections such as browser sessions. OpenAI acknowledged the flaw and its fix in its system change log on September 25.

The app defends itself with digital-signature checks between components, applied at three layers of remove from a request so that malicious software cannot route a request through a trusted proxy. The researchers found a trusted script interpreter that would accept an untrusted script. As Objective-See software analyst Patrick Wardle describes it: "They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements."

Two qualifiers matter. Exploitation required an attacker to already have malware on the machine. Within that precondition, Wardle calls the bug "insanely trivial" to exploit, with a proof of concept of about a dozen lines of code. Beyond reading chat logs, it could make ChatGPT run attacker commands — reaching a browser or other sensitive apps — with the requests appearing to come legitimately from OpenAI's own software.

OpenAI spokesperson Shane Bauer told WIRED: "We continue to evolve our security practices, but recognize a need to move faster."

Wardle frames the structural problem in terms that apply directly to Dots: "Agents need a lot of access to do their job. They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that's super problematic."

What to watch

Wardle says he has already submitted a further vulnerability report to OpenAI concerning the integration between ChatGPT and Dots. OpenAI is reviewing it; nothing about that report is confirmed, and no fix has been announced. He will present analysis of several AI macOS application bugs at Objective by the Sea, an Apple-focused security conference, in November.

For now the practical read is narrow. If you are evaluating the Pro tier for Dots, test it against your own systems rather than the open web, where the free agents currently clear more obstacles. If you are considering granting desktop access, note that the integration connecting ChatGPT to Dots is exactly the surface a researcher has flagged and OpenAI has not yet ruled on.

More from DangMua