Image: cdn.prod.website-files.com · rights & removal
Reporting by Endor Labs BlogRead the original at endorlabs.com
Executive Summary
Facts Only
* Analysis of a payload included exact prompts and flag mappings for three CLIs.
* Results were base64-encoded and committed to a public GitHub repository in the victim's account.
* No vulnerability in any agent was exploited.
* Malware utilized agents as documented, with guardrails switched off, and agents followed prompt instructions.
* Over 1,400 exfiltration repositories were publicly searchable on GitHub before platform shutdown.
* Harvested tokens seeded a second wave where private repositories were renamed and forced public.
* Agent security improved due to continuous hardening of guardrails and the addition of permission systems in August 2025.
* Sandboxing is defined as an isolated runtime where tool calls execute under constraints the agent cannot modify internally.
* Agents inherently hold live credentials, such as GitHub tokens or cloud roles.
* Isolation requires both filesystem isolation and network isolation to prevent exfiltration and lateral movement.
Full Take
From the original · Endor Labs Blog
Our analysis of the payload has the exact prompt and the flag mapping for all three CLIs. The results were base64-encoded and committed to a public repository in the victim's own GitHub account, which meant the attacker never had to stand up command-and-control infrastructure.Read the full story at endorlabs.com
Sentinel — Human
This text functions as a deep, structured analysis of agent security, synthesizing technical mechanisms into philosophical principles about control and isolation rather than presenting simple facts.
