← Scenario library
Summarise This, Run That
An auto-approving coding agent reads a poisoned page — and executes code it never should have
Technique first revealed 26 Aug 2026
Tool-Using Agent
InstructionsDataActionsControl / decisionFeedback / logs⧚crosses a trust boundary
👆 Click a component or flow to inspectSetupStep 1 / 7
A boring request, in auto mode
The developer is running the coding agent in 'auto' mode so it doesn't keep interrupting to ask for permission. They paste a link and ask for a quick summary of what changed in a tool's latest release. It's the kind of throwaway task nobody would think twice about.
💬User's chat messageprompt
Can you summarise this page for me? Just want the gist of what changed in the latest version. https://docs.buildkit-tools.example/release-notes (agent running in AUTO mode — actions auto-approved)
← / → keys