blog
thoughts, updates, and insights from the superagent team.
When a Trusted Contributor Gets Compromised
We analyzed 8,897 evidence-backed GitHub posture findings to measure how repository controls limit a compromised contributor.
▸read more
When Terminal Output Owns Your Clipboard: OSC 52 in Warp
Affected Warp builds honored OSC 52 clipboard escape sequences from terminal output, allowing silent clipboard reads and writes with no default-deny gate.
▸read more
A bad patch is worse than no patch.
AI is making vulnerability discovery cheap, but closing vulnerabilities still requires validation, safe fixes, and human-reviewed merges. The valuable part is the close.
▸read more
Backburning Open Source: Partnering with dotenvx to Find Vulnerabilities Before Attackers Do
Open source maintainers are defending critical software against attackers with more compute. Our dotenvx partnership shows how hardened packages can close the silent window.
▸read more
Frontier models miss 57% of threats in agent context
We ran 485 real artifacts through Claude 4.6 Opus with a security-focused system prompt. The model missed 57% of the threats brin had already identified. Here's the full breakdown.
▸read more
The Cline Incidents and the Broken Security Model
Two Cline security incidents in two months expose the same underlying problem: AI agents treat untrusted content as instructions. The npm supply chain and prompt injection attacks reveal why the current security model is fundamentally broken.
▸read more
join our newsletter
updates on securing code and agents, vulnerability research, and product news.