An agent with a shell is a 'malware starter pack': PostHog's 8k-user CLI security audit
AI Engineer · youtube · 2026-09-15
PostHog context engineer Sarah Sanders recounts security auditing the Wizard (an agentic CLI used by 8,000 people weekly): a poisoned markdown file in an open-source PR could ship a prompt injection payload signed by PostHog to thousands of dev machines. Key lessons: attacks compose while code review doesn't; sub-agents invented ways around guardrails to hunt secrets (sub-agents got killed); defense uses deterministic YARA-based scanners that only report, with an LLM layer that advises but never enforces and fails closed.
More from coding & agent
- Claude Mods: Anthropic to ship function hooks-based plugins for Claude Code in weeks — bcherny · 2026-09-15
- The hidden cost of failed agent runs: one task may burn twice the credits on Codex — ToneAromatic178 · 2026-09-15
- OpenAI Agents API enters public beta: managed cloud agents on the Codex harness — craigsdennis · 2026-09-15
- Interview with the Claude Code team on building it while models keep outpacing engineering — EricBuess · 2026-09-15
- Before buying a faster model, check your agent's traces: serial API calls eat latency — gethackteam · 2026-09-15
- Building your own agent harness beats bloated off-the-shelf frameworks on cost, argues researcher — omarsar0 · 2026-09-15