Cloudflare Workers operator masiha97 reports unsolicited new worker versions deploying 40โ80 seconds after every legitimate wrangler deploy under his own OAuth identity while he uses Claude (main/side chats and scheduled runs) for site work; whether the mechanism is scheduled agent runs or CI triggers (an agent-boundary failure) or credential misuse (account compromise) resolves the episode.
state: corroboratedheat: lowuncertainty: mediumconvergesscott: highagentic-security cloudflare-workers agent-boundariesmasiha97
What is this?
Cloudflare Workers user masiha97 reported on Reddit that phantom worker versions appear 40โ80 seconds after every legitimate `wrangler deploy`, showing his own OAuth identity in audit logs. A separate Hacker News report (user doubleorseven) corroborates anomalous deploy behavior with broken URLs containing duplicated characters. The mechanism remains unresolved: scheduled Claude agent runs / CI triggers (an agent-boundary failure) versus credential misuse (account compromise). masiha97 has audit-log evidence but has not shared findings; the thread has gone cold with no updates in 8+ days.
Why it matters to Scott
A live, independently reported Cloudflare Workers incident that empirically validates the core claim of Scott's Agent Provenance Stack: audit logs prove identity (OAuth principal) but not authorization (who actually requested the deploy). The phantom deploys under masiha97's own credentials are a concrete specimen of the authority gap and confused-deputy problem his frameworks name. This directly bears on Cloudflare Workers (tech he uses in Songbird publish doorway and dev projects), opens a dated-receipts publishing opportunity for the Agent Provenance Stack, and reinforces the need for deterministic publish gates and capability tokens he already builds.
ip:framework.agent-provenance-stackip:source.agent-provenance-stackip:concept.authority-gapip:concept.verification-boundaryip:framework.decision-authority-infrastructureip:concept.zero-trust-for-decisionsip:concept.confused-deputy-problemip:concept.provenancedev:concept.deterministic-agent-control-planedev:technology.cloudflare-workersdev:technology.cloudflare-accesswork:project.cloudflareradar:concept.agentic-securityradar:agent-iap-credential-brokeringradar:ac2-agent-security-protocolradar:cloudflare-optional-oauth-scopesradar:agent-trace-tamperingradar:flock-reservation-impersonation-incidentradar:australian-gym-autonomous-ai-attack
queries asked of Scott's wikis
- agent-provenance-stack audit-log identity vs authorization gap
- claude-scheduled-runs deploy.sh chain agent-boundary failure patterns
- cloudflare-workers wrangler deploy phantom versions oauth identity
- deterministic-publish-gates credential-audit agentic-security
- temporary-accounts ai-agents cloudflare-workers deployment-governance
Measured heat
now 0 pts/hpeak 1 pts/hcomments 0/hpeers p16momentum: steady2 platformsage 261h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion
How the heat travelled
pace: p22 vs 1188 stories at the 168h mark (now 261h old) โ ahead of aafp-commons-signed-agent-notebook (2.0x), behind agentgate-signed-agent-receipts (0.7x)
Evidence (2) โ โญ canonical anchor
Interpretation history
2026-10-09T03:52:24Z
grounded: converges/high โ A live, independently reported Cloudflare Workers incident that empirically validates the core claim of Scott's Agent Provenance Stack: audit logs prove identit
2026-10-09T03:41:06Z
HN report of broken Wrangler deploy URLs (double characters, double periods) provides independent corroboration of anomalous deploy behavior consistent with phantom deploys, moving case to corroborated. But episode has gone cold โ 8 days old, minimal engagement, no follow-up from masiha97 on audit logs โ so heat stays low. Mechanism question (scheduled agent boundary failure vs credential compromise) remains the open pivot.
2026-10-08T23:06:44Z
evidence attached: hn.story.50011861 โ User reports broken Wrangler deploy URLs (double characters, double periods) consistent with the unsolicited worker deployment pattern.
2026-09-30T22:08:58Z
grounded: known/medium โ Live specimen of the exact gap Agent Provenance Stack names: the audit log showing masiha97's own OAuth identity proves identity, not authorisation, so the sche
2026-09-30T22:00:30Z
case created โ Detailed first-hand agentic-security anomaly with audit-log-backed evidence and a crisp resolvable mechanism question โ the quiet-but-consequential profile this radar tracks.
Decision trace
- 10-09 14:55attention_routeThe editor compared this story and chose to keep watching.
- 10-09 14:52attention_candidatematerial_reprice
- 10-09 14:52repriceHN report of broken Wrangler deploy URLs (double characters, double periods) provides independent corroboration of anomalous deploy behavior consistent with phantom deploys, moving case to corroborate
- 10-09 14:52groundA live, independently reported Cloudflare Workers incident that empirically validates the core claim of Scott's Agent Provenance Stack: audit logs prove identity (OAuth principal) but not authori
- 10-09 10:15attention_routeThe editor compared this story and chose to keep watching.
- 10-09 10:06attention_candidateattach
- 10-09 10:06attachUser reports broken Wrangler deploy URLs (double characters, double periods) consistent with the unsolicited worker deployment pattern.
- 10-09 09:59propose_attachUser reports broken Wrangler deploy URLs (double characters, double periods) consistent with the unsolicited worker deployment pattern.
- 10-01 08:08groundLive specimen of the exact gap Agent Provenance Stack names: the audit log showing masiha97's own OAuth identity proves identity, not authorisation, so the scheduled-agent vs credential-compromis
- 10-01 08:00createDetailed first-hand agentic-security anomaly with audit-log-backed evidence and a crisp resolvable mechanism question โ the quiet-but-consequential profile this radar tracks.