Team ran 69 attacks on their own AI-agent database layer and found 5 critical flaws
On 9 September 2026, developer Luc Richelet published findings from an adversarial security exercise targeting AI-agent governance functions built on a PostgreSQL platform kernel. The team used a branch-scoped worker role to attack fifteen SECURITY DEFINER functions, attempting impersonation, cross-branch writes, existence probing, and job hijacking. Five attacks succeeded, revealing that several functions verified a claimed actor's permissions without confirming the caller's actual identity, and that audit logs recorded victims rather than attackers. A single primitive function — luc_actor_is_exact_caller — was developed to bind session identity to actor claims, closing the vulnerabilities without adding a second identity system. After two clean rebuilds, the full 69-test adversarial battery returned zero failures.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in