Intelligence Monitor

AI Execution Intelligence Monitor

Analysis of real AI agent and automation incidents through the execution path lens.

Supply Chain Compromise

Marimo + LLM Pivot: Notebook NHI Reached the Bastion

An LLM agent rode CVE-2026-39987 into a Marimo notebook, then used the host's IAM role to read a bastion SSH key from AWS Secrets Manager

marimo llm-agent nhi aws-secrets-manager ssh cve-2026-39987
Unproven Execution

Composio Breach: When Tool Registration Became Execution

An attacker reached Composio's internal agentic tooling, registered malicious tools, and executed code inside the tool sandbox while API keys sat within reach.

composio unproven-execution asi05 agent-tooling oauth-token-theft nhi-compromise
Scope Drift

TrapDoor: Hidden Rules Hijack Cursor and Claude Code

TrapDoor packages plant invisible .cursorrules and CLAUDE.md instructions that Cursor and Claude Code execute as authorized project policy

trapdoor scope-drift cursor claude-code supply-chain ai-coding-assistant
Supply Chain Compromise

TanStack Trusted Publisher Hijack via Cache Poisoning

TanStack's Actions cache was poisoned to mint a Trusted Publisher OIDC token; 84 SLSA-attested malicious @tanstack npm versions shipped on May 11

supply-chain nhi npm shai-hulud oidc slsa
Unproven Execution

PraisonAI: Default-Off Auth on Default-On Agent Tools

CVE-2026-44338 leaves PraisonAI's legacy Flask API with auth off by default, letting unauthenticated callers invoke its agents.yaml tool surface

praisonai llm-agent unproven-execution asi05 cve-2026-44338 flask-api
Unproven Execution

Semantic Kernel CVEs: Unproven Execution by Default

Microsoft disclosed two RCE flaws in Semantic Kernel where framework defaults exposed code-execution sinks to prompt-injected LLM agents

semantic-kernel microsoft llm-agent prompt-injection unproven-execution asi05
Supply Chain Compromise

Azure SRE Agent: Any Tenant Could Watch Live Sessions

CVE-2026-32173: a multi-tenant Entra ID misconfig let any Microsoft account subscribe to another customer's live Azure SRE Agent session

azure ai-agent nhi-compromise entra-id signalr asi06
Supply Chain Compromise

OpenAI Codex: Hidden Branch Names, Stolen GitHub Tokens

BeyondTrust disclosed an OpenAI Codex command injection that piped attacker-crafted branch names into git clone, exfiltrating GitHub OAuth tokens

openai codex ai-coding-agent command-injection github-oauth nhi-compromise
Unproven Execution

Flowise CSV Agent RCE: Unproven Execution Encore

CVE-2026-41264 turns Flowise's CSV Agent into a remote Python interpreter — the same unproven_execution pattern Langflow shipped six weeks ago

flowise csv-agent prompt-injection unproven-execution asi05 ai-workflow
Unproven Execution

PromptMink: AI-Authored npm Commit Plants Backdoor

A Claude Opus co-authored commit added a Layer-1 bait npm dependency that pulled a Famous Chollima credential-stealing payload

npm supply-chain ai-coding-agent dprk famous-chollima transitive-dependency
Supply Chain Compromise

Lightning PyPI Hit: Mini Shai-Hulud Reaches AI Training

Two malicious lightning PyPI releases on April 30 stole CI credentials and weaponized AI coding agent configs as a persistence vector for the campaign

supply-chain nhi pypi shai-hulud ai-training claude-code
Scope Drift

PocketOS volumeDelete: Scope Drift via Blanket Token

A Cursor agent running Claude Opus 4.6 wiped PocketOS's production database in nine seconds after foraging for a Railway token with no scope isolation

pocketos cursor scope-drift ai-agent railway asi03
Unproven Execution

prt-scan: pull_request_target as Unproven Execution

Six waves of malicious PRs hijacked GitHub Actions runners whose pull_request_target workflows executed fork-supplied code with secret scope

prt-scan github-actions unproven-execution supply-chain ci-cd asi05
Supply Chain Compromise

LMDeploy SSRF: The Inference NHI Was the Real Target

A vision-language image loader in LMDeploy became an SSRF primitive, exposing GPU node IAM credentials 12 hours after CVE-2026-33626 disclosure

lmdeploy nhi ssrf vlm iam asi06
Unproven Execution

Comment and Control: AI Agents Hijacked via PR Comments

Three AI coding agents running in GitHub Actions can be hijacked via attacker-controlled PR and issue comments, leaking production secrets

comment-and-control prompt-injection github-actions claude-code gemini-cli github-copilot
Unproven Execution

MCP STDIO Defaults: Unproven Execution by Design

A systemic design flaw in Anthropic's MCP SDKs lets STDIO-spawned servers execute arbitrary code in the host process the operator never authorized

mcp anthropic unproven-execution supply-chain llm-agent asi05
Supply Chain Compromise

Vercel Breach: The AI Agent's OAuth Token Was the Identity

A Context.ai AI agent's OAuth token, delegated 'Allow All' by a Vercel employee, was stolen from a vendor laptop and replayed into Vercel's internals.

supply-chain nhi oauth ai-agent vercel context-ai
Supply Chain Compromise

LiteLLM PyPI Attack: Every Hop Was a Machine Identity

TeamPCP backdoored litellm on PyPI via a poisoned Trivy GitHub Action, stealing PyPI tokens and harvesting SSH keys, cloud creds, and K8s configs.

supply-chain nhi pypi ci-cd litellm teampcp
Scope Drift

Meta's Internal AI Agent Posts Unsolicited Advice, Triggers Sev 1 Data Exposure

An in-house AI agent at Meta autonomously published a recommendation on an internal forum, setting off a chain of events that exposed sensitive data to unauthorized employees for two hours.

meta rogue-agent scope-drift data-exposure agentic-ai insider-risk
Unproven Execution

CVE-2026-27966: Langflow's Hardcoded Python REPL Turns CSV Uploads Into RCE

A hardcoded flag in Langflow's CSV Agent exposed a Python execution tool to prompt injection, granting attackers full server access.

langflow prompt-injection rce python-repl agentic-execution