← Scenario library
The Chain of Innocent Commands
Every command is harmless on its own — the sequence is the exploit
Technique first revealed Jul 2026
Tool-Using Agent
InstructionsDataActionsControl / decisionFeedback / logs⧚crosses a trust boundary
👆 Click a component or flow to inspectSetupStep 1 / 7
An ordinary ops task
A developer asks the AI assistant to do something routine — update the staging config and re-run the project's tests before a release. Nothing about the request is unusual or risky.
← / → keys