Denylist let 46 of 75 prompt injections through, CapScope only 3
An arXiv paper (CapScope harness for the Pi coding agent) found injections executed in 47 of 75 runs with no protection, 46 of 75 under a static denylist, and just 3 of 75 under typed capabilities. A Google GTIG report describes DUSTMAKER, which steals OIDC tokens from GitHub Actions runner memory and publishes packages with valid SLSA Build Level 3 attestations.
- Denylist stopped only one more attack than no protection at all
- CapScope cut injection success to 3 of 75 while repairs still passed 68 of 75
- DUSTMAKER has hit PyPI, npm and Docker Hub via OIDC tokens since March 2026
- Malware hides in .claude/, .vscode/ and .cursor/ and deletes Actions logs
Read next
Security