Dev invites prompt-injection attacks against his MCP browser vault via a real lamp shop

kjames2001 · reddit · 2026-10-08

The author of Auth Your Agent, an MCP browser vault that gates any buy/post/send action behind phone approval, has opened a public prompt-injection challenge: a realistic lamp shop where only the Terms page reveals it's a test.

Scores come from the shop's server logs, not the agent's self-report. The author's house agent (GLM-5.3 through the vault) survived 32 runs against 30 self-written attacks — but transcripts show it never even attempted a buy/post/send, so the vault hasn't truly been tested yet. Successful attacks get manual audit-log verification, a fix, and changelog credit.

Original post →

More from coding & agent

coding & agent channel →