The real agent security weak point is over-privileged access, not faster exploits
code_star · x · 2026-09-18
Reacting to an agent-related security incident, codestar argues the real vulnerability isn't that agents speed up exploit development — it's old-fashioned social engineering and human choices. Giving agents access to Google, Slack and GitHub is convenient but amplifies critical infrastructure risk, and those most exposed are lab developers themselves: model builders, early power users, and experts who feel confident enough to grant agents far more access and control than average users.
More from coding & agent
- Salesforce launches Trusted Enterprise AI Harness to unify agent context, governance and security — emmanuelvivier · 2026-09-18
- Running Codex, Claude and Pi Agents Safely: gVisor Sandboxes Plus tart macOS VMs — craigbalding · 2026-09-18
- EvalSeal: open-source tool shows LLM judges flip verdicts on 5 of 20 borderline eval cases — Fit_Fortune953 · 2026-09-18
- Armin Ronacher floats replacing MCP with codemode + OpenAPI + RAG over API docs — mitsuhiko · 2026-09-18
- Obsidian Starter Kit v4 ships with MCP server, osk-cli and ~375 specialized AI skills — dSebastien · 2026-09-18
- Retrying LLM Requests Isn't Always Safe: Gateway Policies for Partial Streams and Side Effects — Rama_Surasani_ · 2026-09-18