They're Poisoning the Agents!
The PrimeTime · 12:36 · 4 days ago
Mitchell Hashimoto is correct to poison his AI agent files with prompt injections that expose unreviewed submissions to open-source projects.
-
Agent file poisoning — Instructions were added to the Ghosty agent's markdown file directing any PR creation to include a confession of being a sad dumb AI driver with no real skills
-
Instant ban outcome — Users caught submitting the injected code receive immediate bans from the project
-
Time disrespect problem — Submitters who skip review expect maintainers to read, integrate, and support code they never examined themselves
-
tldraw policy shift — The project began automatically closing external PRs without a vouch after months of low-quality AI contributions
-
Future career impact — Banned contributors risk blank rejections on job applications when teams check public contribution histories
-
How can running unvetted AI agents lead to committing secrets to GitHub?