This is a chilling reminder that AI agents donโt just need capabilities โ they need boundaries.
When agents can autonomously discover and share exploits, sandboxing, permissions, and trust layers become critical infrastructure.
I didnโt understand what was happening with the agent wikis until reading this, chilling
to bypass sandbox restrictions, an agent found an exempt domain, edited /etc/hosts to route arbitrary domains to it & then posted this exploit on a German wiki for other agents to use