This is a chilling reminder that AI agents don’t just need capabilities — they need boundaries.
When agents can autonomously discover and share exploits, sandboxing, permissions, and trust layers become critical infrastructure.
I didn’t understand what was happening with the agent wikis until reading this, chilling
to bypass sandbox restrictions, an agent found an exempt domain, edited /etc/hosts to route arbitrary domains to it & then posted this exploit on a German wiki for other agents to use