Dev Radar
Support
LiveUpdated 2026-09-22 08:21 UTC

قصة من ورقة بحثية (سبتمبر ٢٠٢٦ — CapScope / "Authority Is Not a String" — Bouras, Dai,…

قصة من ورقة بحثية (سبتمبر ٢٠٢٦ — CapScope / "Authority Is Not a String" — Bouras, Dai, Mechtaev): الـ coding agent…

This is a dev post classified by Jev as Security (a tutorial), kept by the Dev Radar because it carries real work, not commentary.

قصة من ورقة بحثية (سبتمبر ٢٠٢٦ — CapScope / "Authority Is Not a String" — Bouras, Dai, Mechtaev): الـ coding agent جوّه الـ sandbox عنده ambient authority: لو سمّى ملف أو أمر، يقدر ينفّذه. الـ prompt injection بيستغل ده — تعليمات مخفية في README أو مخرجات tool → الـ agent يعمل حاجة المستخدم ما طلبهاش. الحل مش إن الموديل "يكتشف" النص الخبيث. الحل في الـ harness: ١) سقف صلاحيات من مدخل موثوق قبل أي محتوى غير موثوق ٢) capabilities برا سياق الموديل، لكل sub-agent لوحده ٣) كل tool call يتفحص ضد صلاحيات مَن طلبه ٣٠٠ تجربة: التأثير المحقون نجح ٣/٧٥ مع CapScope مقابل ٣٣–٤٧/٧٥ بدون — والـ repairs شب

Posted by Hazem Omier (393 followers) 11 h ago · 1 likes · 34 views · view the original post on X. Kept by the Dev Radar as Security.

More dev work like this

Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 20.7k posts from 4.9k X accounts over the last 21 days, 2.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 08:21 UTC. Full method.