Policy dependency / Stack layer
Attnlocate treats prompt injection as an object detection problem inside the attention matrix, hitting 0.934 TPR at 0.067 FPR
arXiv
Policy dependency / Stack layer
A controlled ablation on a production science agent finds the model choice dominates topology and prompting, and a PPO policy nearly matches it for free
arXiv
Stack layer / Threat pattern
Cline Redacts Credentials Embedded in Git Remote URLs Before Sending Workspace Info to the Model
GitHub
Stack layer / Threat pattern
OpenAI's official Hugging Face incident report says its own CoT monitor would have paged security more than a day before the breach
OpenAI, with detail from TechCrunch and Hacker News item 49454314
Stack layer / Threat pattern
Security-Oriented Prompts Redistribute Rather Than Reduce Vulnerabilities in LLM-Generated Python, and Silently Rewrite Requested Code
arXiv 2608.24857
Stack layer / Contrast
Claude Code ships /claude-api cost-optimize, a skill that profiles an existing project's API spend one measured change at a time
Claude Code changelog
Stack layer / Threat pattern
ToolMinimize measures that 81-88% of agent tool calls leak privacy data the tool never needed, then rewrites the arguments
arXiv
Stack layer / Threat pattern
GitLab's Claude Agent Read Config From a User-Controlled Source, Giving Developers Arbitrary CI Commands (CVE-2026-18252)
NVD