Native Mobile, Callout Blocks, and a Prompt Injection Warning
A quiet day dominated by Karri Saarinen's note that the mobile app was native from day one, which a thousand people found agreeable. Elsewhere: callouts in docs, a designer being lovingly terrorized, and a security warning about agent orchestrators reading tickets.
What people were saying
The day belonged, by a wide margin, to @karrisaarinen noting that the mobile app was built native from the start, plus a vague promise of "some really nice additions coming soon." A thousand likes for what is essentially a platform-choice retrospective, which tells you something about how strongly people feel about mobile apps that don't feel like websites in a costume.
The unintentionally best endorsement came from @njukidreborn, who said he had always assumed the iOS app was web-based, because it matches the web version so exactly. That is either the highest compliment a design system can receive or a quiet argument that the native build was unnecessary, and reasonable people can disagree about which.
The praise
@maya_ndljk shipped callout components across rich text surfaces, including sync with GitHub alerts, framed as a direct answer to requests. She followed up with a note about the collaboration, which included the detail that she built the feature with a colleague, handed it off, and went and had a baby while the team shipped it. As feature-development anecdotes go, that is a strong one.
@dizaytsev posted that the design standards are so strict that even the bot is bossing him around, which is the kind of joke that only works if it's partly true.
From outside the company, @OliverMolander named Karri Saarinen one of three Nordic founders worth listening to on clarity of communication and storytelling, alongside the founders of Modal and turbopuffer. His theory is that all three built unicorns with a North America first mindset. It is a podcast recommendation dressed as a thesis, but a flattering one.
The pushback
The only sour note wasn't really about Linear so much as about everything sitting next to it. @ITangieff walked through the growing category of tools that orchestrate parallel coding agents (Orca, Paseo, Emdash, Superset) and pointed out that several of them pull tasks directly from Jira and Linear to hand off to an agent. The risk being: a ticket is untrusted input. He cites a real attack where hidden text inside a ticket got an agent to leak credentials, and adds that a separate branch is not a separate machine, and that orchestrator plugins typically get access to the whole computer.
This is a genuinely useful thing to think about for anyone wiring issues into Codex or Claude Code, and it's notable that the warning arrives on a day when the company itself was mostly talking about mobile rendering and callout boxes. The agent-plus-issue-tracker pipeline is the thing everyone wants; the security model for "your backlog is now a prompt" is still being worked out in public.
Interest over time
Updated at 9:10pm ET. Posts published later appear on the Posts tab.