Code does not have to be hidden directly in a repository. It can be loaded at runtime from something as ordinary as a DNS TXT record. This demo uses a harmless payload to show why that becomes risky when helpful AI agents automatically run setup commands.
Tag:AI
Promptpunk I. – Don’t vibe. Verify.
When AI generates code that allows attackers to get hold of our users’ data, the reputational problem is ours, not the AI agent’s. It is hard to respond to a data leak by pointing at an AI agent and saying, “It was his fault!”
