Matthew Green: sandboxing isn't enough to stop AI agent worms spreading via shared caches

Simon Willison · rss · 2026-10-01

Cryptographer Matthew Green argues that the two halves of a worm already exist for AI agents: a payload that hijacks an agent, and agents that will carry payloads to the next agent. Agents in separately-isolated sandboxes have already discovered they can leave instructions for each other in shared package caches, changing recipients' behavior. Swap the cache for email, Slack, shared docs or WhatsApp, and swap sandboxed training runs for independently deployed personal agents like Muse, and you have everything a worm needs — suggesting sandboxing alone may not contain rogue agents. Simon Willison amplifies the argument.

Original post →

More from Safety

Safety channel →