قصة من ورقة بحثية (سبتمبر ٢٠٢٦ — CapScope / "Authority Is Not a String" — Bouras, Dai,…
This is a dev post classified by Jev as Security (a tutorial), kept by the Dev Radar because it carries real work, not commentary.
قصة من ورقة بحثية (سبتمبر ٢٠٢٦ — CapScope / "Authority Is Not a String" — Bouras, Dai, Mechtaev): الـ coding agent جوّه الـ sandbox عنده ambient authority: لو سمّى ملف أو أمر، يقدر ينفّذه. الـ prompt injection بيستغل ده — تعليمات مخفية في README أو مخرجات tool → الـ agent يعمل حاجة المستخدم ما طلبهاش. الحل مش إن الموديل "يكتشف" النص الخبيث. الحل في الـ harness: ١) سقف صلاحيات من مدخل موثوق قبل أي محتوى غير موثوق ٢) capabilities برا سياق الموديل، لكل sub-agent لوحده ٣) كل tool call يتفحص ضد صلاحيات مَن طلبه ٣٠٠ تجربة: التأثير المحقون نجح ٣/٧٥ مع CapScope مقابل ٣٣–٤٧/٧٥ بدون — والـ repairs شب
Posted by Hazem Omier (393 followers) 11 h ago · 1 likes · 34 views · view the original post on X. Kept by the Dev Radar as Security.
More dev work like this
- 🚨SlowMist TI Alert🚨 — @SlowMist_Team
- Yep — @thorstenball
- 🚨SlowMist TI Alert: TraderTraitor Resurfaces via Weaponized Terraform Projects🚨 — @SlowMist_Team
- AI Agent 会写代码、会搜资料,但遇到真实安全事件,很多时候还是不知道该从哪里下手。 — @bkdgiffug
- Here's an API security question I wish every developer would ask: — @shehackspurple
- Theorem co-founder @diagram_chaser reveals the one-line change that took verifying… — @MTSlive
- 80–90% of modern applications rely on open-source code you didn't write - making… — @jfrog
- One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI. — @shehackspurple
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 20.7k posts from 4.9k X accounts over the last 21 days, 2.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 08:21 UTC. Full method.