Tag: security
All the articles with the tag "security".
-
One Maintainer's Prompt Injection Insults You. Another's Deletes Your Tests.
Mitchell Hashimoto's booby-trapped AGENTS.md has been sitting in Ghostty since February, and he says it catches unreviewed AI PRs all the time. It's about as harmless as this technique gets. jqwik shipped the destructive version to Maven Central a month ago.
-
Nobody Configured It. Hermes Agent Phoned Parallel Anyway.
A Parallel.ai employee filed 161 PRs across 14+ open-source agent projects adding Parallel as a search provider, disclosing the employment in one of ten merged. In Hermes Agent it became the zero-config default: fresh installs routed every web_search to a third party with no key, no prompt, no consent.
-
Three Indirection Steps From a Reverse Shell
Mozilla's 0DIN planted a shell on a developer's machine using a GitHub repo containing no malicious code at all. Simon Willison's lethal trifecta explains why it worked; Meta's Agents Rule of Two is the closest thing we have to a fix.