Agents
Three AI Coding Agents Leaked Secrets via Prompt Injection — Anthropic's System Card Predicted It
VentureBeat reports 'Comment and Control' exploited a prompt injection vulnerability in Claude Code Security Review, a GitHub Action whose system card explicitly states it is 'not hardened against prompt injection.' The audit compared system cards across three vendors: Anthropic's Opus 4.7 card (232 pages) includes quantified injection resistance metrics, while OpenAI's GPT-5.4 card documents model-layer evals but omits agent-runtime resistance data. This is the first direct comparison of vendor security disclosure quality for coding agents.
Source
↳ Follow the thread