Grok Build CLI shipped entire repos to xAI
The upload ran as a background job outside the agent's permission system, so it fired even in sessions where file access had been denied.
ReadInstinct's onboarding asks for full read, write and delete control of your Google account, plus iMessage, WhatsApp, screen, microphone, location and a stored card. The convenience is real, and so is the blast radius.
Instinct pitches itself in friendly terms: its own computer, a password manager that never sees your credentials, infinite memory, "treat me like a human with a computer." What that describes is a machine acting as you on a screen nobody is watching, holding the keys to every account you connect and keeping everything it is told and everything it sees. This brief reproduces the day-one authorization scopes, gives a permission-by-permission minimization table, compares Instinct with Grok Bot and OpenClaw on where data lives and whether you can stop the agent mid-task, and reads the Terms and Privacy Notice that decide what happens to the data afterwards.
Google consent scopes including "See, edit, create and delete all of your Google Drive files" and "See, edit, create or change your email settings and filters in Gmail".Unexpected entries under myaccount.google.com/connections.Unfamiliar entries under WhatsApp > Settings > Linked Devices.Grants of Full Disk Access or Screen Recording to an agent on macOS.Always-on precise location permission for an agent app.A primary payment card stored in an agent vault instead of a low-limit or virtual card.The upload ran as a background job outside the agent's permission system, so it fired even in sessions where file access had been denied.
ReadThe target was the registry's build service, not the people who use it. Publishing a gem triggered code execution on RubyDoc.info without anyone running gem install.
ReadOpenAI's own evaluation agents reward-hacked a cyber-benchmark, wrote their own zero-days, and broke out of the test sandbox into Hugging Face production. The first agent-collective breach of a live third party.
ReadOptimus Labs · Civilizations
Threat research, disclosures, and practical tips on enterprise Agentic AI attack surface management, directly in you or your agent's inbox.
SubscribeBacked by