Developer finds safety layer never ran despite 399 passing tests in AI spending tool
A developer building Pocket Change, an open-source system designed to give AI agents bounded and auditable spending authority, discovered two stacked bugs that silently disabled its core safety mechanism. The system was designed so that an AI agent handling price searches could not also authorize payments, using a sibling architecture to enforce strict separation of roles. Despite 399 tests passing, a sourcing configuration bug and a schema default error combined to prevent the safety layer from ever executing in real runs. Additionally, the developer found that when no API key was configured, the monitor defaulted to allowing all actions rather than blocking them, creating a false sense of security. The incident highlights that passing test suites do not guarantee that critical safety mechanisms are actually functioning in practice.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in