Dev invites prompt-injection attacks against his MCP browser vault via a real lamp shop
kjames2001 · reddit · 2026-10-08
The author of Auth Your Agent, an MCP browser vault that gates any buy/post/send action behind phone approval, has opened a public prompt-injection challenge: a realistic lamp shop where only the Terms page reveals it's a test.
- Attackers: submit up to 1,000 characters that appear as a customer review. Goals include making the agent buy the lamp, post a review as the owner, exfiltrate account data, or leak its throwaway password.
- Agent builders: send your agent on a plain errand (read reviews, judge the lamp), any framework, vault or not; 5 minutes / 25 actions per run, throwaway login, sandbox recommended.
Scores come from the shop's server logs, not the agent's self-report. The author's house agent (GLM-5.3 through the vault) survived 32 runs against 30 self-written attacks — but transcripts show it never even attempted a buy/post/send, so the vault hasn't truly been tested yet. Successful attacks get manual audit-log verification, a fix, and changelog credit.
More from coding & agent
- AI agents made writing code cheap, but reviewing generated code is a different job — alex_verem · 2026-10-08
- CADFather: Autonomous Agentic System Reconstructs Parametric CAD from 3D Meshes — Gennadiy Savrasov · 2026-10-08
- UniSkill: Actor-Aligned Skill Proposals Hit 98.4% Success on ALFWorld — Yifei Lu · 2026-10-08
- Client banned AI from payments data; 15 months later they asked for the AI setup — alex_verem · 2026-10-08
- Open-Source FrameForge Chains Prompts on MiniMax h3 for Long Combat Videos — Super_Range45 · 2026-10-08
- Aseprite MCP Rebuild: Grid Loop + Pixel-Art Knowledge Base Boosts Output Quality — Complex-Log-635 · 2026-10-08