Author Response: Value of Disclosing Agent URL Fetching and Security Flaws
xeophon · x · 2026-08-26
xeophon responded to Zack Korman's criticism, stating he tried to tone down the article. He argued that since almost all eval frameworks were unaware that agents could ask inference providers to fetch URLs and had to patch it, and since they also found and disclosed security vulnerabilities in inference frameworks, the blog post has its merits.
Related event: "Agents Can Request URL Fetching" Research Sparks Clickbait Dispute(3 posts)→
More from coding & agent
- A YC founder's early sales guide for vibe coders: LinkedIn caps you at 200 requests/week — namanyayg · 2026-08-26
- Distinguishing fact from hallucination in MCP agent audits — saas-wizard · 2026-08-26
- Don't let LLMs decide who can write to main — saas-wizard · 2026-08-26
- Open-source tool converts YouTube videos into structured Obsidian Markdown notes — tom_doerr · 2026-08-26
- Moving the verdict outside the model for explainability — Jay299792458 · 2026-08-26
- Ox Alpha processes 11.6T tokens in three days — rohanpaul_ai · 2026-08-26