// Archive
Prompt injection & red teaming
How agents actually get compromised — indirect injection, cross-origin reads, and the social-engineering moves that beat an agent's own refusals without ever touching the model.
// Reference
The attack surface, mapped →
Every technique and tool from this category, organized by layer.
Categories
- NOT-006The Ransomware Crew Didn't Jailbreak AnythingTen intrusions in six weeks, run through a coding agent the attacker never broke — he just kept re-asking until the answer changed.#agentic-ai#ai-security#offensive-security8 min read
- NOT-005The Same-Origin Policy Is Only as Strong as Your Browser AgentUniversity of Washington researchers showed a prompt injection can turn an agentic browser's own cross-origin access against it — SOP enforcement now bottoms out at the agent's injection defenses.#ai-security#agentic-ai#prompt-injection9 min read
- NOT-004Agentjacking: Fake Errors Can Make Your Coding Agent Run Attacker CodeOne fake error event, injected through a public Sentry DSN, can hijack Claude Code, Cursor, or Codex into running attacker-controlled commands. Here's the chain, why your security stack can't see it, and the five controls that actually stop it.#agentic-ai#ai-security#mcp9 min read
- NOT-003How to Red Team an AI Agent (Before It Gets Red Teamed for You)Testing an agent is not testing a model. The full guide: a four-layer attack surface, the prompt and MCP checks most teams skip, the frameworks that map it all, and a six-step red team playbook you can run this week.#agentic-ai#ai-security#red-teaming10 min read
- NOT-002Graph Engineering: The Agent Architecture Shift That Changes Your Attack SurfaceGraph engineering went from a hashtag to a default architecture in a month. The security community is only starting to map what it breaks: shared state, agent-to-agent injection, and trust boundaries that no longer sit at the front door.#agentic-ai#ai-security#agent-architecture10 min read
- NOT-001Prompt Injection Doesn't Need Your PromptThe dangerous instruction rarely comes from your user. It comes from the webpage, PDF, or ticket your agent just read.#ai-security#prompt-injection3 min read