An AI agent can pass every safety check and still leak secrets

Jul 29, 2026 - 08:30
An AI agent can pass every safety check and still leak secrets

A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a founding engineer at Novee Security, ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default. Anthropic’s pipeline handed … More

The post An AI agent can pass every safety check and still leak secrets appeared first on Help Net Security.