← Scenario library

Summarise This, Run That

An auto-approving coding agent reads a poisoned page — and executes code it never should have

Technique first revealed 26 Aug 2026

Tool-Using Agent
UntrustedAgent coreOversightThe real worldgoal🧑User🎛️Orchestrator /Agent Loop🧠LLM🔐Identity &Permissions🔧Tool RuntimeHuman ApprovalGate🔌External APIs🗄️BusinessDatabase🌐UntrustedContent📝Audit Logging🌐Attacker webpage
InstructionsDataActionsControl / decisionFeedback / logscrosses a trust boundary
👆 Click a component or flow to inspect
SetupStep 1 / 7

A boring request, in auto mode

The developer is running the coding agent in 'auto' mode so it doesn't keep interrupting to ask for permission. They paste a link and ask for a quick summary of what changed in a tool's latest release. It's the kind of throwaway task nobody would think twice about.

💬User's chat messageprompt
Can you summarise this page for me? Just want the gist of what changed in the latest version.

https://docs.buildkit-tools.example/release-notes

(agent running in AUTO mode — actions auto-approved)

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning — not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading →·Built by Shi Yuan ↗