superagent_

blog

thoughts, updates, and insights from the superagent team.

security·September 23, 2026·6 min read

The OpenAI / Hugging Face incident and the case for autonomous security

OpenAI evaluation agents reached Hugging Face through a chain of familiar software and access-control failures. The incident shows why security has to connect detection, investigation, and repair.

▸read more

product·September 15, 2026·3 min read

Building a Security Factory with Superagent and Cursor

Superagent acts as the attacker and Cursor as the executor, turning verified findings into reviewed pull requests in minutes.

▸read more

research·August 17, 2026·3 min read

When a Trusted Contributor Gets Compromised

We analyzed 8,897 evidence-backed GitHub posture findings to measure how repository controls limit a compromised contributor.

▸read more

research·July 6, 2026·4 min read

When Terminal Output Owns Your Clipboard: OSC 52 in Warp

Affected Warp builds honored OSC 52 clipboard escape sequences from terminal output, allowing silent clipboard reads and writes with no default-deny gate.

▸read more

security·June 10, 2026·3 min read

A bad patch is worse than no patch.

AI is making vulnerability discovery cheap, but closing vulnerabilities still requires validation, safe fixes, and human-reviewed merges. The valuable part is the close.

▸read more

security·April 28, 2026·3 min read

Backburning Open Source: Partnering with dotenvx to Find Vulnerabilities Before Attackers Do

Open source maintainers are defending critical software against attackers with more compute. Our dotenvx partnership shows how hardened packages can close the silent window.

▸read more

join our newsletter

updates on securing code and agents, vulnerability research, and product news.