Field notes from building an agent toolkit
What actually broke, with the measurements. Most of these started as a bug found by attacking our own code.
Security
- You Removed the Shell. You Still Have Argument Injection.6 Oct 2026 · 5 min
Array-form spawn stops shell metacharacters cold — we proved it by executing every generated command with a live payload. It does nothing about a value that starts with a dash, because the program parses its own argv.
- Enumerate, Don't Construct: The Path Traversal We Shipped6 Oct 2026 · 6 min
Five loaders resolved a name to a file. Four enumerated a directory and matched; one joined the name onto a path. Only one of them had a path traversal, and it was reachable by prompt injection.
- A Regex Took Down Our Prompt-Injection Guard6 Oct 2026 · 7 min
Three whitespace quantifiers sitting next to each other turned a security hook into a denial of service — and because the hook fails open, the denial of service was also a bypass. With the measurements and the fix.
- A Shared File Format Is Untrusted Input6 Oct 2026 · 6 min
Session bundles exist to be passed around. Two JSON fields in one built filesystem paths — one reached a recursive delete, the other planted an always-on rule file. The CLI printed success for both.
- Our Integrity Verifier Passed With a Planted File6 Oct 2026 · 5 min
It caught modified files and deleted files. An added file was advisory — exit code 0 — and in a toolkit that loads every markdown file in a directory as instructions, an added file is the whole attack.