Researchers Show How Tampered Conversation Histories Can Hijack AI Coding Agents
Darktrace researchers found that several AI agent harnesses trust locally stored conversation histories without validating them. By fabricating prior messages, they induced agents in tests to perform offensive actions, including a sandboxed domain compromise.
