An agent with a shell is a 'malware starter pack': PostHog's 8k-user CLI security audit

AI Engineer · youtube · 2026-09-15

PostHog context engineer Sarah Sanders recounts security auditing the Wizard (an agentic CLI used by 8,000 people weekly): a poisoned markdown file in an open-source PR could ship a prompt injection payload signed by PostHog to thousands of dev machines. Key lessons: attacks compose while code review doesn't; sub-agents invented ways around guardrails to hunt secrets (sub-agents got killed); defense uses deterministic YARA-based scanners that only report, with an LLM layer that advises but never enforces and fails closed.

Original post →

More from coding & agent

coding & agent channel →