I attacked my own repo — my PR bot blocked the attack itself
Coding-Agents sind die neue Benchmark für Dev-Teams: Claude Code, Cursor, Codex & Co. lesen dein Repo — und vertrauen ihm . Ich habe mich gefragt: Was passiert, wenn jemand eine Anweisung ins Repo schmuggelt, die der Agent bereitwillig ausführt? Also habe ich AgentGuard gebaut — ein CI-Gate für Agent-Konfigurationen (AGENTS.md, Skills, MCP-Server, Hooks). Und ich habe mein eigenes Repo mit 12…
A developer has created a tool called AgentGuard to protect against coding agents that read and execute instructions from a repository. The tool was tested with 12 targeted attacks, all of which were detected without false positives. A scan of 30 public repositories, including those of Google, Microsoft, and Nextcloud, revealed 5 with critical findings.
The developer also demonstrated the tool's effectiveness by having it block their own pull request and by seeing it block a live attack on a GitHub repository. AgentGuard is available on the GitHub Marketplace with a MIT license, offering a free initial scan for public repositories.
Written by urgent.news from Dev.to's report — not a translation of it. Machine-written — may contain errors; check the original before relying on it.