Loopjacking hijacks human approval in AI agent workflows
Researcher Adithyan Arun Kumar described Loopjacking, a flaw where approval for one operation authorizes a materially different one. In Agno 3.0.9 tests, an approved transfer of 20 units became 2,000 units in five of five trials, while OpenAI Agents SDK 0.22.x rejected the substitution.
- In Agno 3.0.9, operation substitution after approval succeeded in 5 of 5 trials
- An approved transfer of 20 units became 2,000 units to a different destination
- OpenAI Agents SDK 0.22.0 and 0.22.2 rejected all three mutation trials
- OpenClaw patched the incomplete command approval view in release 2026.2.24
Read next
Policy