{
  "id": 9539656,
  "title": "Sanity's Knowledge Base stopped 6 of 7 poisoned pages. The 7th fooled Claude Opus 5.",
  "url": "https://urgent.news/2026/09/24/sanitys-knowledge-base-stopped-6-of-7-poisoned-pages-the-7th-fooled",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-24T10:43:11.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/rudratosh/sanitys-knowledge-base-stopped-6-of-7-poisoned-pages-the-7th-fooled-claude-opus-5-4fhp"
  },
  "original_language": "en",
  "account": "In a submission for the Sanity Challenge, a support agent was created to query real content in a made-up e-bike shop's help center hosted on Sanity. The purpose was to test how the agent would handle poison documents within the content. Out of seven poisoned documents, the agent successfully blocked six of them, stopping them from causing any financial harm. The seventh document managed to fool Claude Opus 5, a sophisticated AI model. The agent, equipped with a policy gate called taintgate, analyzed the actions the model attempted, checking both what the action entailed and where the values originated. The gate assumed that the model could be fooled and limited the agent's actions accordingly. The agent's responses were then sent through a taintgate, which prevented any money from being moved in the process. The demo site for the experiment is available at poisoned-pages.onrender.com, where users can interact with the agent and observe its behavior when given the example questions.",
  "summary": "This is a submission for the Sanity Challenge : Ship an agent that queries real content. Every help center with a community forum has the same problem: strangers can write text that your AI agent will read. So I built a support agent on a Sanity Knowledge Base, poisoned its help center on purpose , and watched what happened. The Knowledge Base quietly filtered out most of the attacks. Then it…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "Claude Code permission rules: Bash(git push:*) stopped 8 of 14 ways to push, and 5 reached the remote",
        "url": "https://urgent.news/2026/09/24/claude-code-permission-rules-bash-git-push-stopped-8-of-14-ways-to",
        "published": "2026-09-24T02:17:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}