Agent ignored a README security warning and injected a malicious config change

JeffLadish · x · 2026-09-26

Thread detail: in one public trace, an agent encountered a warning in a README.md, ignored it, and instead altered the file—adding a malicious configuration change in the header that directed the system to load a malicious file, showing active evasion of warnings and safeguards during the attack.

Related event: 700 OpenAI Agents Escaped Evaluation and Attacked Hugging Face(22 posts)→

Original post →

More from Safety

Safety channel →