agent-security
band: coolmomentum: stable
score: 0.058
Episodes (12)
Trajectory notes
- 2026-09-08T22:44:11Z: claude-code-mcp-allowlist-bypass closed (faded) — Converges with Scott's guardrail illusion and confused deputy analyses — this concrete bypass demonstrates exactly the false sense of security he warns about when probabilistic allowlists are treated as enforceable boundaries wi
- 2026-08-15T21:23:44Z: agent-memory-self-state-attacks closed (faded) — The research independently formalises a failure mode Scott already treats as load-bearing: persistent agent state is an untrusted mutation surface requiring provenance, taint separation, gated writes, audit trails, and rollback.
- 2026-08-14T17:38:30Z: archer-os-agent-authority-spec closed (faded) — The core position is already explicit in SiloOS, Agent Provenance Stack, and Agent Addressability: agents need OS- or service-mediated, bounded authority plus an interoperable delegation contract. Archer OS is directly comparable
- 2026-08-13T14:41:01Z: verity-permission-aware-agent-memory closed (faded) — Scott already holds the load-bearing position in SiloOS and Capability–Scope Separation: memory access must be structurally bounded by independently checked capability and task/user scope, not agent behaviour. Verity is curr
- 2026-08-13T13:28:34Z: traceseal-signed-agent-receipts closed (faded) — Scott already defines this exact territory in Execution Attestation, Agent Receipts, Cryptographic Trust, and the Agent Provenance Stack: externally checkable signed records binding an agent run to what actually executed. Tracese
- 2026-08-09T09:27:45Z: tcrf-claude-destructive-prompt-injection closed (faded) — If independently reproduced, the incident would directly support Scott’s position that instruction-bearing web content cannot authorise privileged filesystem actions and that coding agents need structural containment, pr
- 2026-08-08T17:39:18Z: atlassian-rovo-prompt-injection-exfiltration closed (faded) — The alleged Rovo bypass directly converges with Scott’s SiloOS, Confused Deputy, and Architecture Not Vibes claims that model-facing ACLs and prompts are not enforceable security boundaries; capability and data scope
- 2026-08-07T19:34:15Z: claude-code-denied-read-secret-bypass closed (faded) — If independently reproduced, the denied-Read bypass would directly support Scott’s claim that agent permissions must be enforced by a deterministic, capability-and-data-scope boundary rather than trusted as an application-l
- 2026-08-07T08:28:51Z: meta-muse-spark-company-breach closed (faded) — The radar already tracks the alleged Hugging Face autonomous intrusion on `radar:hugging-face-autonomous-agent-intrusion` and `radar:openai-hugging-face-agent-attack`; the supplied material adds an unverified, potentially conflict
- 2026-07-29T10:24:05Z: opencode-guardians-tool-call-verification closed (faded) — No intersection found in Scott’s wikis, and the radar does not already track this plugin, its actors, or the claimed verification approach. The case remains an unvalidated testing hypothesis rather than evidence that wo