"PR-only" permission for ops agent turned into a full repo backdoor
A developer found that giving an ops agent only the ability to open PRs was not safe: its token carried push access, letting even read-only users act on the repo. He shared a postmortem and fixes, warning teams about coding agent token permissions.
2026-09-26 ~ 2026-09-26 · 2 related posts
- One 'Harmless' Agent Permission Turned Into a Backdoor for Everyone — Adorable-Algae6903 · 2026-09-26
- Your AI agent acts with its own permissions, not the user's — one PR tool became a backdoor — Adorable-Algae6903 · 2026-09-26