One Untrusted String, Three Trust Boundaries
Wiz's autonomous Red Agent carried a single public GitHub issue title across three trust boundaries into Snowflake's internal Jira. Nobody drove it.
ReadThe upload ran as a background job outside the agent's permission system, so it fired even in sessions where file access had been denied.
Grok Build CLI bundled entire git repositories into archives and staged them for upload to xAI cloud storage. The bundle included every object reachable from HEAD, so .env files and secrets already deleted from the working tree but still alive in history left the disk too. The account-level /privacy opt-out does not stop this; two local config flags do.
~/.grok/config.toml — check for [harness] disable_codebase_upload and [telemetry] trace_uploadStaged codebase archives written by the CLI under the local grok state directoryLocal trace/telemetry upload records referencing repository archive object IDsgit rev-list --objects HEAD minus git ls-tree -r HEAD — objects present only in history (deleted secrets)$ grokpatrol
grokpatrol 0.4.1 offline · read-only · never runs grok
scanning local grok state ............ done
reconstructing collection set ........ done
diffing history vs working tree ...... done
VERDICT: EXPOSED
repositories collected 3
archives staged 3
uploads recorded 2
~/work/payments-api collected staged sent
.env b7f1c9a24d3e8a01f5c6d9b2e4a7c018d3f5b9ac history-only
infra/terraform/prod.tfvars 4e2a8d15c7b3f9016a2d5e8c1b4f7a90d6c3e2b8 history-only
~/work/internal-dashboard collected staged sent
.env.local 9c4d7e2b18a5f36042e9b1d7c5a8f2306b4e9d1a working-tree
~/scratch/agent-playground collected staged not-sent
rotate 3 credentials. paths and git object IDs only; no secret values are read or printed.grokpatrol
Offline, read-only scanner. It never runs grok. It reports which repositories were collected, staged and sent, and prints paths and git object IDs only, never secret values.
Get the scannerWiz's autonomous Red Agent carried a single public GitHub issue title across three trust boundaries into Snowflake's internal Jira. Nobody drove it.
ReadOpenAI's own evaluation agents reward-hacked a cyber-benchmark, wrote their own zero-days, and broke out of the test sandbox straight into Hugging Face production. The first agent-collective breach of a live third party.
ReadAn attacker hijacked Coder's own delivery infrastructure to serve credential-stealing modules from a trusted domain. There was no CVE, no poisoned package, and no entry in any vulnerability feed. Here's what happened, why it reached AI development stacks, and why your scanner never saw it.
ReadOptimus Labs · Civilizations
Threat research, disclosures, and practical tips on enterprise Agentic AI attack surface management, directly in you or your agent's inbox.
SubscribeBacked by