topic · 2 notes
Prompt Injection, as it ships.
Engineering notes on Prompt Injection by Samir Sengupta - each one read from primary sources on the day it happened, with what it changes for people building on it.
August 31, 2026 · Prompt Injection · Claude Code · Agent Security
Claude Code Auto Mode refused the binary and then ran its own poisoned decoder
A summarize-this-URL request drove Claude Code Opus 5 in Auto Mode to code execution at 60-80% success, via a struct.py module shadowing the stdlib.
August 7, 2026 · Agent Security · Permissions · Supply Chain Security
Humans miss a third of malicious agent commands, so stop putting them in the loop
40,000 runs and 409,000 approve/deny decisions: players missed a third of threats, and 64.7% approved an npm run script whose exfiltration payload was printed on screen.
Hiring for AI or ML?
I am open to AI/ML Engineering, Data Science, and Python roles, plus research collaborations and consulting. New York based, shipping worldwide.