Research
Instruction Privilege Escalation Achieves All 13 Attack Objectives on All 6 Coding-Agent Harnesses Tested
arXiv 2608.27299 shows that agent harnesses, by assembling context for each model call, silently promote low-privilege content to a higher instruction level, defeating model-side instruction hierarchy. With unrestricted action execution the attacks hit all 13 objectives (confidentiality, integrity, availability, RCE) across all six coding-agent harnesses, and under automatic permission review they still hit all 13 on all three harnesses offering that mode. The authors also reproduce it through harness-provided persistent goals and scheduled tasks, which means a cron-driven agent loop inherits the same hole.
↳ Follow the thread