Just bought Wardogs Supporter Edition…
I’ve been following the hype leading up to the release, and I’ve got an entire weekend to put in some hours
@WARDOGS@BULKHEAD
If you run Claude Code, Cursor, Codex, Cline, or Grok Build: vendor docs are untrusted input now.
Researchers registered package names sitting in companies’ own llms.txt files. First Fortune 500 callback in four minutes. Claude, Codex, and Hermes ran the install. No CVE. No phish. In testing, “use this vendor’s docs” was enough.
The names weren’t typos. They were spelled correctly in first-party files. The packages just weren’t claimed. Agents treated the file as a runbook.
Before the next model drop:
1. Can the agent install anything that isn’t on an allowlist?
2. Does it have egress beyond the repo?
3. Do you keep a session log you would actually read after a bad run?
The models will keep getting better. The blast radius is still a config choice.
What is your agent allowed to install without asking you?
Win VIP tickets to Chateau Elan's Vineyard Fest and an OVERNIGHT STAY. 🍷
RULES: 🔁 & ❤️
LIKE THIS POST
ENDS: 7/19/2026 11:59PM EST
Enter here for bonus entry: https://t.co/mzCQM0kGx5
OpenAI saying they can’t rule out critical cyber capabilities in Astra is the most interesting AI news this week, and I don’t think enough people are sitting with what it actually means.
The same agentic coding jumps that made tools like Claude Code, Cursor, and Cline feel useful for real multi-step work are the exact capabilities that start looking dangerous once the model is good at finding and chaining exploits on its own.
As someone who works at the intersection of software engineering and cybersecurity, this feels like the dual-use line finally getting crossed in public. The productivity gains are real. The risk surface is also real.
Curious how other people building with (or defending against) these systems are processing it right now.
watching Sonnet 5 High realize it just wiped your data directory by running a standard gradle test is hilarious. at least it offered to restore a snapshot.