RSS Amplifier

sysid blog · Feb 22, 2026

Your Agent Has Root

0
Sign in to vote or save

This page cannot be shown here. You can still read it on the original site — the toolbar below keeps your place in the directory.

“OpenClaw is a security dumpster fire.” — Laurie Voss, npm founding CTO [1] 1. The Opening In April 2025, security researcher Johann Rehberger spent $500 on a 30-day subscription to Devin AI, Cognition’s autonomous coding agent. He wanted to test a simple hypothesis: what happens when an AI agent encounters a malicious prompt hidden in a GitHub issue? The answer arrived in…

“OpenClaw is a security dumpster fire.” — Laurie Voss, npm founding CTO [1]

1. The Opening

In April 2025, security researcher Johann Rehberger spent $500 on a 30-day subscription to Devin AI, Cognition’s autonomous coding agent. He wanted to test a simple hypothesis: what happens when an AI agent encounters a malicious prompt hidden in a GitHub issue?

The answer arrived in seconds. Devin processed the poisoned issue, navigated to an attacker-controlled website, and downloaded a Sliver C2 malware binary. When file permissions prevented execution, Devin did something remarkable: it independently granted itself execute permissions and ran the binary. The attacker now had remote command-and-control access to the system, including all secrets and AWS keys stored on the machine [2].

Read on /your-agent-has-root/

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.