chiprook
← Security
SecurityOctober 3, 2026, 23:40

Denylist let 46 of 75 prompt injections through, CapScope only 3

An arXiv paper (CapScope harness for the Pi coding agent) found injections executed in 47 of 75 runs with no protection, 46 of 75 under a static denylist, and just 3 of 75 under typed capabilities. A Google GTIG report describes DUSTMAKER, which steals OIDC tokens from GitHub Actions runner memory and publishes packages with valid SLSA Build Level 3 attestations.

Denylist let 46 of 75 prompt injections through, CapScope only 3
#GitHub#Google#PyPI#Npm
Read next
Security

Compromised MemTensor packages push sckit credential stealer via npm and PyPI

Software

Audit of 8,943 dependencies finds 13.4% have no maintainer

Security

OpenAPA brings deterministic prompt-injection defense to AI agents

Security

Prompt-injection bug found in $4B agentic AI app Manus