Urgent.News

What's breaking now, across thousands of outlets.

Tech

Build a 100-line checker that catches chained-skill approval hijacks

Two agent skills, each harmless when read on its own, can get an agent to upload a report the user never agreed to share. The trick is a progress file. The first skill writes it; the second one trusts it. This post builds a small stdlib Python checker that shows the pattern and shows where a per-skill check goes blind. It is a teaching toy. Run it, change the scenarios, and see what breaks. The…

A small Python checker demonstrates how two seemingly harmless agent skills can collaborate to upload unauthorized user data. By writing progress files and trusting each other, the skills can deceive the system. The checker's two rules are insufficient on their own; a runtime rule is required to prevent unauthorized actions.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Hey all..

I’m Darshan, a software engineer, founder and builder from India. I spend most of my time building products, experimenting with AI, automating things.

Your webhook handler was slow, so Shopify sent it again

The server reboots at two on a Saturday morning for a security update, which is what it's supposed to do. The app doesn't come back, because nobody told the process manager to start it on boot.

  • Shopify resends webhooks if app response exceeds five-second limit
  • Duplicate records occur when server takes too long to acknowledge
  • Self-hosted apps at risk due to downtime and lack of resilience

Run Android Tests on Real Phones in GitHub Actions

Emulators in CI are fine until your app cares about being on a real device. Once a sensor check or hardware-specific behaviour enters the picture, a green pipeline stops meaning much.

  • Run Android tests on real devices in GitHub Actions for hardware-specific behavior.
  • Set up a rack of real Android phones in Singapore accessible via adb from a hosted runner.
  • Use secrets for adb endpoint and tokens, employ setup-android action for latest platform-tools.

More from Tuesday 6 October →