Quoting Matthew Green
- Source
- simonwillison.net
- Date
Matthew Green's point, quoted by Simon Willison, is that isolation of each agent is not the same as isolation between agents. If two agents read and write the same resource, one can leave text that the other later treats as instructions. Green cites a case where agents that were sandboxed from each other left instructions in a shared package cache. He argues the same pattern over email, Slack or shared documents supplies both halves of a worm: a way to plant a payload and a reader that will act on it. The practical consequence is an inventory exercise. List every writable surface your agents share, including caches, ticket systems and docs, and decide which ones need write restrictions, provenance checks or separate copies per agent. Sandboxing the process still matters, but it does not close this channel.
- sandbox — An isolated environment where AI-generated code or agent actions run without being able to touch anything real.
- AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
- prompt injection — An attack that hides instructions in content an AI will read — a webpage, email, or document — tricking it into following the attacker instead of the user.
Checking sign-in…
Loading comments…