Internal AI bot leaked unannounced reorg plan and salary bands via over-scoped Drive access

Accomplished-Wall375 · reddit · 2026-09-08

A developer recounts how an internal assistant, meant to answer only from an approved knowledge base, revealed details of an unannounced reorg plan—including salary bands—because a broad Drive read permission indexed the confidential HR folder. An audit then found a wiki-summarizing agent that inherited its creator's account permissions: delete access on the shared drive and the ability to send mail as that person. Key takeaway: no attack occurred; over-scoped agent permissions alone are the vulnerability, and teams should audit what their agents can actually reach.

Original post →

More from coding & agent

coding & agent channel →