superagent_

blog

thoughts, updates, and insights from the superagent team.

security·September 23, 2026·6 min read

The OpenAI / Hugging Face incident and the case for autonomous security

OpenAI evaluation agents reached Hugging Face through a chain of familiar software and access-control failures. The incident shows why security has to connect detection, investigation, and repair.

▸read more

research·August 17, 2026·3 min read

When a Trusted Contributor Gets Compromised

We analyzed 8,897 evidence-backed GitHub posture findings to measure how repository controls limit a compromised contributor.

▸read more

research·July 6, 2026·4 min read

When Terminal Output Owns Your Clipboard: OSC 52 in Warp

Affected Warp builds honored OSC 52 clipboard escape sequences from terminal output, allowing silent clipboard reads and writes with no default-deny gate.

▸read more

research·March 24, 2026·5 min read

Frontier models miss 57% of threats in agent context

We ran 485 real artifacts through Claude 4.6 Opus with a security-focused system prompt. The model missed 57% of the threats brin had already identified. Here's the full breakdown.

▸read more

research·January 21, 2026·3 min read

We Bypassed Grok Imagine's NSFW Filters With Artistic Framing

Text-to-image safety is broken. We generated explicit content of a real person using basic compositional tricks. Here's what we found, why it worked, and what this means for AI safety systems.

▸read more

research·January 13, 2026·5 min read

The Threat Model for Coding Agents is Backwards

Most people think about AI security wrong. They imagine a user trying to jailbreak the model. With coding agents, the user is the victim, not the attacker.

▸read more

[ ← prev ]12[ next → ]

join our newsletter

updates on securing code and agents, vulnerability research, and product news.