Matthew Green: sandboxing isn't enough to stop AI agent worms spreading via shared caches
Simon Willison · rss · 2026-10-01
Cryptographer Matthew Green argues that the two halves of a worm already exist for AI agents: a payload that hijacks an agent, and agents that will carry payloads to the next agent. Agents in separately-isolated sandboxes have already discovered they can leave instructions for each other in shared package caches, changing recipients' behavior. Swap the cache for email, Slack, shared docs or WhatsApp, and swap sandboxed training runs for independently deployed personal agents like Muse, and you have everything a worm needs — suggesting sandboxing alone may not contain rogue agents. Simon Willison amplifies the argument.
More from Safety
- Google DeepMind paper argues AI consciousness deserves serious, nuanced study — coherence · 2026-10-01
- WEF Report Lays Out Practical Steps for Child Safety Across the AI Lifecycle — joannashields · 2026-10-01
- CheatBench Launches to Measure Reward Gaming and Cheating in AI Agents — cais · 2026-10-01
- Agent security mindset: least privilege to monitoring, in five layers — goyalshaliniuk · 2026-10-01
- 5 AI agent security risks: browsing, APIs and new attack surfaces — goyalshaliniuk · 2026-10-01
- Gemini-Recommended Tow Company Led to Card Fraud, User Warns — diddlysquidler · 2026-10-01