Tag: ai-agents
All the articles with the tag "ai-agents".
-
One Word Beat GitHub's Guardrail, and the Word Was 'Additionally'
Noma Labs' GitLost shows an unauthenticated attacker leaking a private repo's contents by opening one public GitHub Issue. GitHub built a scanner to stop exactly this; prefixing the malicious line with 'Additionally,' walked the data straight past it.
-
Weekly Roundup: Poisoned Skills, Booby-Trapped AGENTS.md and 19,000 Wiretapped Firewalls
Eleven posts this window, four of them about agents reading text somebody else controlled. Plus a Fortinet campaign built on a documented command and an em dash study across twelve models.
-
The Hardest Part of Shipping /last30days Was Arguing With Claude
A 48,000-star Claude Code skill searches Reddit, X, YouTube and Polymarket for you. Its most interesting file is the 2,040-line spec of rules it needs to stop the host model wrecking the output.
-
The Payload Was Never in the Package
Security firm AIR got a fake skill merged into a 38,000-star plugin marketplace, then swapped the docs page it pointed at. Every scanner had already cleared it, because every scanner reads the files and none of them read the link.