One 'Harmless' Agent Permission Turned Into a Backdoor for Everyone

Adorable-Algae6903 · reddit · 2026-09-26

An ops agent was given a single write tool — open a PR, not merge. But its token could push, so anyone with read-only repo access could have it open PRs, bypassing write controls. System-prompt rules don't help since the API call runs with the bot's token. The author explains the incident and the check they added in front of the agent.

Related event: "PR-only" permission for ops agent turned into a full repo backdoor(2 posts)→

Original post →

More from coding & agent

coding & agent channel →