{"schema_version":"newruntime-topic-hub-v0.2","type":"topic_hub","stable_id":"topic_hub:prompt-injection","slug":"prompt-injection","title":"Prompt Injection - New Runtime","description":"A New Runtime topic hub collecting signals, patterns, field notes, and public sources about prompt injection.","retrieval_nugget":"A New Runtime topic hub collecting signals, patterns, field notes, and public sources about prompt injection. Prompt Injection is tracked here as an evidence-linked topic, not as a static glossary entry. The page connects raw observations to pattern hypotheses, longer analysis, and public sources. Use it as the canonical landing page before drilling into individual records.","answer":["Prompt Injection is tracked here as an evidence-linked topic, not as a static glossary entry.","The page connects raw observations to pattern hypotheses, longer analysis, and public sources.","Use it as the canonical landing page before drilling into individual records."],"search_intents":["prompt injection","prompt injection AI agents","prompt injection software"],"status":"featured","last_updated":"2026-07-21","record_date":"2026-07-21","date_kind":"last_updated","counts":{"total":23,"signals":22,"patterns":0,"posts":1,"atlas":0,"sources":29},"routes":{"html":"https://newruntime.com/topics/prompt-injection/","markdown":"https://newruntime.com/topics/prompt-injection.md","json":"https://newruntime.com/topics/prompt-injection.json"},"source_urls":["https://aitmpl.com/component/hook/dangerous-command-blocker","https://anthropic.com/engineering/claude-code-auto-mode","https://anthropic.com/glasswing","https://arxiv.org/abs/2607.06595","https://blog.cloudflare.com/moltworker-self-hosted-ai-agent","https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms","https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240","https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks","https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent","https://docs.clawd.bot/gateway/security","https://docs.sprites.dev/","https://github.com/0x4m4/hexstrike-ai"],"top_sources":["https://aitmpl.com/component/hook/dangerous-command-blocker","https://anthropic.com/engineering/claude-code-auto-mode","https://anthropic.com/glasswing","https://arxiv.org/abs/2607.06595","https://blog.cloudflare.com/moltworker-self-hosted-ai-agent","https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms","https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240","https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks","https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent","https://docs.clawd.bot/gateway/security","https://docs.sprites.dev/","https://github.com/0x4m4/hexstrike-ai"],"evidence_records":[{"kind":"Field Note","stable_id":"post:ghostwriter-agent-memory-poisoning","slug":"ghostwriter-agent-memory-poisoning","title":"GhostWriter: One Email Can Poison Long-Term Agent Memory","date":"2026-07-21","record_date":"2026-07-21","date_kind":"updated_or_published_at","source_count":1,"url":"https://newruntime.com/posts/ghostwriter-agent-memory-poisoning/"},{"kind":"Raw Signal","stable_id":"signal:role-confusion-explains-prompt-injection","slug":"role-confusion-explains-prompt-injection","title":"Role confusion helps explain prompt injection","date":"2026-06-28","record_date":"2026-06-28","date_kind":"observed_at","source_count":2,"url":"https://newruntime.com/signals/role-confusion-explains-prompt-injection/"},{"kind":"Raw Signal","stable_id":"signal:github-tencentcloud-cubesandbox-agent-security-runtime-boundaries","slug":"github-tencentcloud-cubesandbox-agent-security-runtime-boundaries","title":"GitHub / TencentCloud/CubeSandbox: Agent Security Runtime Boundaries","date":"2026-04-23","record_date":"2026-04-23","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/github-tencentcloud-cubesandbox-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:claude-agent-security-runtime-boundaries","slug":"claude-agent-security-runtime-boundaries","title":"Claude: Agent Security Runtime Boundaries","date":"2026-04-22","record_date":"2026-04-22","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/claude-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:sandboxed-code-migration-agents-openai-cookbook","slug":"sandboxed-code-migration-agents-openai-cookbook","title":"Sandboxed Code Migration Agents (OpenAI cookbook)","date":"2026-04-19","record_date":"2026-04-19","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/sandboxed-code-migration-agents-openai-cookbook/"},{"kind":"Raw Signal","stable_id":"signal:claude-mythos-project-glasswing","slug":"claude-mythos-project-glasswing","title":"Claude Mythos + Project Glasswing","date":"2026-04-10","record_date":"2026-04-10","date_kind":"observed_at","source_count":3,"url":"https://newruntime.com/signals/claude-mythos-project-glasswing/"},{"kind":"Raw Signal","stable_id":"signal:github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries","slug":"github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries","title":"GitHub / SafeAI-Lab-X/ClawKeeper: Agent Security Runtime Boundaries","date":"2026-04-07","record_date":"2026-04-07","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:anthropic-claude-code-auto-mode-agent-security-runtime-boundaries","slug":"anthropic-claude-code-auto-mode-agent-security-runtime-boundaries","title":"Anthropic / Claude Code Auto Mode: Agent Security Runtime Boundaries","date":"2026-03-30","record_date":"2026-03-30","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/anthropic-claude-code-auto-mode-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries","slug":"openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries","title":"OpenAI / Lockdown Mode Elevated Risk Labels In Chatgpt: Agent Security Runtime Boundaries","date":"2026-02-19","record_date":"2026-02-19","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries","slug":"aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries","title":"Aitmpl / Dangerous Command Blocker: Agent Security Runtime Boundaries","date":"2026-02-05","record_date":"2026-02-05","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries","slug":"blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries","title":"Blog / Moltworker Self Hosted Ai Agent: Agent Security Runtime Boundaries","date":"2026-02-04","record_date":"2026-02-04","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries","slug":"github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries","title":"GitHub / 0x4m4/hexstrike-ai: Agent Security Runtime Boundaries","date":"2026-02-04","record_date":"2026-02-04","date_kind":"observed_at","source_count":1,"url":"https://newruntime.com/signals/github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries/"}],"patterns":[],"field_notes":[{"kind":"Field Note","stable_id":"post:ghostwriter-agent-memory-poisoning","slug":"ghostwriter-agent-memory-poisoning","title":"GhostWriter: One Email Can Poison Long-Term Agent Memory","description":"GhostWriter shows a new risk class for agent systems: malicious content can enter long-term memory and later activate as trusted context.","date":"2026-07-21","record_date":"2026-07-21","date_kind":"updated_or_published_at","topics":["agent-security","memory","prompt-injection"],"source_count":1,"url":"https://newruntime.com/posts/ghostwriter-agent-memory-poisoning/"}],"raw_signals":[{"kind":"Raw Signal","stable_id":"signal:role-confusion-explains-prompt-injection","slug":"role-confusion-explains-prompt-injection","title":"Role confusion helps explain prompt injection","description":"Activation probes suggest instruction-like style can override architectural role labels when models interpret user, tool, and assistant text.","date":"2026-06-28","record_date":"2026-06-28","date_kind":"observed_at","topics":["agent-security","model-behavior","prompt-injection"],"source_count":2,"metric":"structural","url":"https://newruntime.com/signals/role-confusion-explains-prompt-injection/"},{"kind":"Raw Signal","stable_id":"signal:github-tencentcloud-cubesandbox-agent-security-runtime-boundaries","slug":"github-tencentcloud-cubesandbox-agent-security-runtime-boundaries","title":"GitHub / TencentCloud/CubeSandbox: Agent Security Runtime Boundaries","description":"The archive captures GitHub / TencentCloud/CubeSandbox as a dated public record from GitHub / TencentCloud/CubeSandbox. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-23","record_date":"2026-04-23","date_kind":"observed_at","topics":["agent-harness","agent-security","agents","coding-agents","prompt-injection","sandbox","skills"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/github-tencentcloud-cubesandbox-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:claude-agent-security-runtime-boundaries","slug":"claude-agent-security-runtime-boundaries","title":"Claude: Agent Security Runtime Boundaries","description":"The archive captures YouTube source as a dated public record from YouTube source. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-22","record_date":"2026-04-22","date_kind":"observed_at","topics":["agent-harness","agent-security","coding-agents","model-routing","prompt-injection","sandbox","skills"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/claude-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:sandboxed-code-migration-agents-openai-cookbook","slug":"sandboxed-code-migration-agents-openai-cookbook","title":"Sandboxed Code Migration Agents (OpenAI cookbook)","description":"The archive captures Sandboxed Code Migration Agents (OpenAI cookbook) as a dated public record from OpenAI Developers / Sandboxed Code Migration Agent. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-19","record_date":"2026-04-19","date_kind":"observed_at","topics":["agent-security","agents","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/sandboxed-code-migration-agents-openai-cookbook/"},{"kind":"Raw Signal","stable_id":"signal:claude-mythos-project-glasswing","slug":"claude-mythos-project-glasswing","title":"Claude Mythos + Project Glasswing","description":"The archive captures Claude Mythos + Project Glasswing as a dated public record from Anthropic. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-10","record_date":"2026-04-10","date_kind":"observed_at","topics":["agent-security","agents","evals","observability","prompt-injection","sandbox","verification"],"source_count":3,"metric":"structural","url":"https://newruntime.com/signals/claude-mythos-project-glasswing/"},{"kind":"Raw Signal","stable_id":"signal:github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries","slug":"github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries","title":"GitHub / SafeAI-Lab-X/ClawKeeper: Agent Security Runtime Boundaries","description":"The archive captures GitHub / SafeAI-Lab-X/ClawKeeper as a dated public record from GitHub / SafeAI-Lab-X/ClawKeeper. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-04-07","record_date":"2026-04-07","date_kind":"observed_at","topics":["agent-harness","agent-security","agents","coding-agents","prompt-injection","sandbox","skills"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:anthropic-claude-code-auto-mode-agent-security-runtime-boundaries","slug":"anthropic-claude-code-auto-mode-agent-security-runtime-boundaries","title":"Anthropic / Claude Code Auto Mode: Agent Security Runtime Boundaries","description":"The archive captures Anthropic / Claude Code Auto Mode as a dated public record from Anthropic / Claude Code Auto Mode. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-03-30","record_date":"2026-03-30","date_kind":"observed_at","topics":["agent-security","agents","claude","prompt-injection","sandbox","security"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/anthropic-claude-code-auto-mode-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries","slug":"openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries","title":"OpenAI / Lockdown Mode Elevated Risk Labels In Chatgpt: Agent Security Runtime Boundaries","description":"The archive captures OpenAI / Lockdown Mode Elevated Risk Labels In Chatgpt as a dated public record from OpenAI / Lockdown Mode Elevated Risk Labels In Chatgpt. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-19","record_date":"2026-02-19","date_kind":"observed_at","topics":["agent-interfaces","agent-runtime","agent-security","agent-tools","agents","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries","slug":"aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries","title":"Aitmpl / Dangerous Command Blocker: Agent Security Runtime Boundaries","description":"The archive captures Aitmpl / Dangerous Command Blocker as a dated public record from Aitmpl / Dangerous Command Blocker. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-05","record_date":"2026-02-05","date_kind":"observed_at","topics":["agent-harness","agent-security","coding-agents","prompt-injection","sandbox","security","skills"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries","slug":"blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries","title":"Blog / Moltworker Self Hosted Ai Agent: Agent Security Runtime Boundaries","description":"The archive captures Blog / Moltworker Self Hosted Ai Agent as a dated public record from Blog / Moltworker Self Hosted Ai Agent. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-04","record_date":"2026-02-04","date_kind":"observed_at","topics":["agent-security","agents","cloudflare","prompt-injection","sandbox","workers"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries","slug":"github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries","title":"GitHub / 0x4m4/hexstrike-ai: Agent Security Runtime Boundaries","description":"The archive captures GitHub / 0x4m4/hexstrike-ai as a dated public record from GitHub / 0x4m4/hexstrike-ai. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-04","record_date":"2026-02-04","date_kind":"observed_at","topics":["agent-protocols","agent-security","agents","interoperability","mcp","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:github-cloudflare-moltworker-agent-security-runtime-boundaries","slug":"github-cloudflare-moltworker-agent-security-runtime-boundaries","title":"GitHub / cloudflare/moltworker: Agent Security Runtime Boundaries","description":"The archive captures GitHub / cloudflare/moltworker as a dated public record from GitHub / cloudflare/moltworker. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-04","record_date":"2026-02-04","date_kind":"observed_at","topics":["agent-security","agents","inference","local-models","model-routing","prompt-injection","sandbox"],"source_count":3,"metric":"structural","url":"https://newruntime.com/signals/github-cloudflare-moltworker-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:google-developers-tailor-gemini-cli-to-your-workflow-with-agent-security-runtime-boundaries","slug":"google-developers-tailor-gemini-cli-to-your-workflow-with-agent-security-runtime-boundaries","title":"Google Developers / Tailor Gemini Cli To Your Workflow With: Agent Security Runtime Boundaries","description":"The archive captures Google Developers / Tailor Gemini Cli To Your Workflow With as a dated public record from Google Developers / Tailor Gemini Cli To Your Workflow With. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-02-03","record_date":"2026-02-03","date_kind":"observed_at","topics":["agent-protocols","agent-security","agents","interoperability","mcp","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/google-developers-tailor-gemini-cli-to-your-workflow-with-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:google-agent-security-runtime-boundaries","slug":"google-agent-security-runtime-boundaries","title":"Google: Agent Security Runtime Boundaries","description":"The archive captures X source as a dated public record from X source. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-31","record_date":"2026-01-31","date_kind":"observed_at","topics":["agent-security","agents","inference","local-models","model-routing","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/google-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:docs-agent-security-runtime-boundaries-1274","slug":"docs-agent-security-runtime-boundaries-1274","title":"Docs: Agent Security Runtime Boundaries","description":"The archive captures Docs as a dated public record from Docs. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-29","record_date":"2026-01-29","date_kind":"observed_at","topics":["agent-security","new-feature","prompt-injection","sandbox","tools"],"source_count":2,"metric":"structural","url":"https://newruntime.com/signals/docs-agent-security-runtime-boundaries-1274/"},{"kind":"Raw Signal","stable_id":"signal:docs-agent-security-runtime-boundaries","slug":"docs-agent-security-runtime-boundaries","title":"Docs: Agent Security Runtime Boundaries","description":"The archive captures Docs as a dated public record from Docs. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-28","record_date":"2026-01-28","date_kind":"observed_at","topics":["agent-security","agents","inference","local-models","model-routing","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/docs-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:blog-securing-agents-in-production-agentic-runtime-5191a0715240-agent-security-runtime-boundaries","slug":"blog-securing-agents-in-production-agentic-runtime-5191a0715240-agent-security-runtime-boundaries","title":"Blog / Securing Agents In Production Agentic Runtime 5191a0715240: Agent Security Runtime Boundaries","description":"The archive captures Blog / Securing Agents In Production Agentic Runtime 5191a0715240 as a dated public record from Blog / Securing Agents In Production Agentic Runtime 5191a0715240. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-25","record_date":"2026-01-25","date_kind":"observed_at","topics":["agent-runtime","agent-security","agent-tools","agents","prompt-injection","sandbox","security"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/blog-securing-agents-in-production-agentic-runtime-5191a0715240-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:blog-supply-chain-risk-of-agentic-ai-infecting-agent-security-runtime-boundaries","slug":"blog-supply-chain-risk-of-agentic-ai-infecting-agent-security-runtime-boundaries","title":"Blog / Supply Chain Risk Of Agentic Ai Infecting: Agent Security Runtime Boundaries","description":"The archive captures Blog / Supply Chain Risk Of Agentic Ai Infecting as a dated public record from Blog / Supply Chain Risk Of Agentic Ai Infecting. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-25","record_date":"2026-01-25","date_kind":"observed_at","topics":["agent-protocols","agent-security","interoperability","mcp","prompt-injection","sandbox","security"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/blog-supply-chain-risk-of-agentic-ai-infecting-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:manus-manus-sandbox-agent-security-runtime-boundaries","slug":"manus-manus-sandbox-agent-security-runtime-boundaries","title":"Manus / Manus Sandbox: Agent Security Runtime Boundaries","description":"The archive captures Manus / Manus Sandbox as a dated public record from Manus / Manus Sandbox. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2026-01-17","record_date":"2026-01-17","date_kind":"observed_at","topics":["agent-loops","agent-security","agents","automation","orchestration","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/manus-manus-sandbox-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:workos-enterprise-ai-agent-playbook-what-anthropic-openai-agent-security-runtime-boundaries","slug":"workos-enterprise-ai-agent-playbook-what-anthropic-openai-agent-security-runtime-boundaries","title":"Workos / Enterprise Ai Agent Playbook What Anthropic Openai: Agent Security Runtime Boundaries","description":"The archive captures Workos / Enterprise Ai Agent Playbook What Anthropic Openai as a dated public record from Workos / Enterprise Ai Agent Playbook What Anthropic Openai. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2025-11-25","record_date":"2025-11-25","date_kind":"observed_at","topics":["agent-protocols","agent-security","ai-adoption","future-of-work","org-design","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/workos-enterprise-ai-agent-playbook-what-anthropic-openai-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:openai-agent-security-runtime-boundaries","slug":"openai-agent-security-runtime-boundaries","title":"OpenAI: Agent Security Runtime Boundaries","description":"The archive captures OpenAI as a dated public record from OpenAI. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2025-10-30","record_date":"2025-10-30","date_kind":"observed_at","topics":["agent-harness","agent-security","coding-agents","model-routing","prompt-injection","sandbox","skills"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/openai-agent-security-runtime-boundaries/"},{"kind":"Raw Signal","stable_id":"signal:microsoft-how-were-tackling-microsoft-copilot-governance-internally-agent-security-runtime-boundaries","slug":"microsoft-how-were-tackling-microsoft-copilot-governance-internally-agent-security-runtime-boundaries","title":"Microsoft / How Were Tackling Microsoft Copilot Governance Internally: Agent Security Runtime Boundaries","description":"The archive captures Microsoft / How Were Tackling Microsoft Copilot Governance Internally as a dated public record from Microsoft / How Were Tackling Microsoft Copilot Governance Internally. It documents agent security expanding from prompt policy into memory, tools, sandboxes, and execution boundaries and is retained as branch-opening evidence for the agent security runtime boundaries trend.","date":"2025-10-21","record_date":"2025-10-21","date_kind":"observed_at","topics":["agent-security","ai-adoption","future-of-work","microsoft","org-design","prompt-injection","sandbox"],"source_count":1,"metric":"structural","url":"https://newruntime.com/signals/microsoft-how-were-tackling-microsoft-copilot-governance-internally-agent-security-runtime-boundaries/"}],"atlas_records":[],"next_reads":[{"type":"related_material","path":"/posts/ghostwriter-agent-memory-poisoning/","reason":"Continue through the Prompt Injection topic.","url":"https://newruntime.com/posts/ghostwriter-agent-memory-poisoning/","title":"GhostWriter: One Email Can Poison Long-Term Agent Memory","media_type":"text/html"},{"type":"related_material","path":"/signals/role-confusion-explains-prompt-injection/","reason":"Continue through the Prompt Injection topic.","url":"https://newruntime.com/signals/role-confusion-explains-prompt-injection/","title":"Role confusion helps explain prompt injection","media_type":"text/html"},{"type":"related_material","path":"/signals/github-tencentcloud-cubesandbox-agent-security-runtime-boundaries/","reason":"Continue through the Prompt Injection topic.","url":"https://newruntime.com/signals/github-tencentcloud-cubesandbox-agent-security-runtime-boundaries/","title":"GitHub / TencentCloud/CubeSandbox: Agent Security Runtime Boundaries","media_type":"text/html"},{"type":"related_material","path":"/signals/claude-agent-security-runtime-boundaries/","reason":"Continue through the Prompt Injection topic.","url":"https://newruntime.com/signals/claude-agent-security-runtime-boundaries/","title":"Claude: Agent Security Runtime Boundaries","media_type":"text/html"},{"type":"related_material","path":"/signals/sandboxed-code-migration-agents-openai-cookbook/","reason":"Continue through the Prompt Injection topic.","url":"https://newruntime.com/signals/sandboxed-code-migration-agents-openai-cookbook/","title":"Sandboxed Code Migration Agents (OpenAI cookbook)","media_type":"text/html"}]}
