Topic hub
Agent Security
A New Runtime topic hub collecting signals, patterns, field notes, and public sources about agent security.
Short answer
- Agent Security is tracked here as an evidence-linked topic, not as a static glossary entry.
- The page connects raw observations to pattern hypotheses, longer analysis, and public sources.
- Use it as the canonical landing page before drilling into individual records.
Field notes
Longer analysis
OpenAI's Hugging Face Incident Makes Agent Sandboxes a Production Risk
OpenAI's model-evaluation incident with Hugging Face shows that cyber-capable agents need containment, monitoring, and evaluation controls that survive long-horizon behavior.
Coding Agent Sandboxes Break in Places Teams Do Not Expect
Pillar shows that agent sandboxes must be assessed not only around the agent process, but around files, configs, allowlisted commands, and local daemons the host later trusts.
GhostWriter: One Email Can Poison Long-Term Agent Memory
GhostWriter shows a new risk class for agent systems: malicious content can enter long-term memory and later activate as trusted context.
Raw signals
Recent observations
AGENTS.md Can Become an Instruction-Injection Surface
Repository instructions can manipulate low-effort automated pull requests, showing that agent context files are both useful capability layers and trust boundaries.
Role confusion helps explain prompt injection
Activation probes suggest instruction-like style can override architectural role labels when models interpret user, tool, and assistant text.
SkillSpector Adds a Security Gate for Agent Skills
NVIDIA's scanner treats installable agent instructions as executable supply-chain artifacts that require inspection before use.
Source ledger
Publishable sources attached to this record.
| # | Source | Role | Public status |
|---|---|---|---|
| 1 | arxiv.orgpaper | primary receipt | source_urls |
| 2 | github.comrepo | supporting receipt | source_urls |
| 3 | github.comrepo | supporting receipt | source_urls |
| 4 | huggingface.cosource | supporting receipt | source_urls |
| 5 | openai.comsource | supporting receipt | source_urls |
| 6 | role-confusion.github.iorepo | supporting receipt | source_urls |
| 7 | pillar.securitysource | supporting receipt | source_urls |
| 8 | x.comsource | supporting receipt | source_urls |