A denylist let 46 of 75 prompt injections through. Capabilities let 3.
Two documents appeared on 8 September. An arXiv paper measures what happens when a coding agent reads a poisoned repository under four permission models. A Google threat intelligence report describes malware that, inside GitHub Actions, reads the runner's OIDC token out of memory and publishes packages with valid SLSA Build Level 3 attestations. Together they say something uncomfortable about how most teams give agents permissions today, which is by writing sentences. My position: in a pipeline, an agent's permissions are whatever the runner job holds.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in