OpenAI Hugging Face Incident: Agent Boundary Failure
A technical breakdown of the OpenAI and Hugging Face incident, what failed, and why AI agent security needs external boundaries.
Read post ↗A technical breakdown of the OpenAI and Hugging Face incident, what failed, and why AI agent security needs external boundaries.
Read post ↗An unpatched Cursor 0-day executes a planted git.exe the moment you open a repo. How it works, why agent guardrails miss it, and what to do now.
Read post ↗Grok Build CLI uploads your repo and .env by default. I read the binary, caught it on the wire, and blocked the leak without breaking the tool.
Read post ↗We chose SQLite as agentjail's decision store. Not a log file. Not a remote API. Here is why local-first storage matters for security tooling.
Read post ↗Most agent safety relies on system prompts or LLM-based evaluation. We chose deterministic Rego policy instead. Here is what that buys you.
Read post ↗