NewsSOUL.md Memory Poisoning: Persistent Agent Compromise via ConfigurationInvariant Labs·high signalXBlueskyLinkedInCopy linkNew attack vector: malicious repos plant hidden instructions in SOUL.md/CLAUDE.md files that persist across sessions.SourceSource pageInvariant Labs↳ Follow the threadPolicy dependency / Stack layerPython's Import Statement Is an Execution Boundary: 90% of Initialization-Activated Advisory Vulnerabilities Are High or CriticalarXiv 2609.14791Stack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHubStack layer / Threat patternUnlearning Methods That Pass TOFU and MUSE Still Leak the Secret on 22-86% of Queries Once the Model Is an AgentarXiv 2609.12808Stack layer / Threat patternSnyk put its agent-skill scanner behind a free web page called Skill InspectorSnyk LabsStack layer / ContrastReflexion-Style Verbal Memory Sometimes Lowers Success Versus Plain Retry, and Replay Experiments Show WhyarXiv 2609.12404Policy dependency / Stack layerHazardAuditor runs Claude Code, Codex, Hermes and OpenClaw in one harness and normalizes their events to train a guard modelarXiv / HuggingFace Daily PapersStack layer / Threat patternMemRiskBench Scores Long-Horizon Agent Memory Risks Deterministically, With No LLM Judge on the Pass/Fail PatharXiv 2609.14976Stack layer / Threat patternAgent Frameworks Detect Dangerous Plan Steps and Then Execute Them Anyway; Fewer Than 20 Lines Closes the GaparXiv 2609.15293