Analysis
AI Agent Security: Six Controls From Nine Real Incidents
First reported gitguardian.com
Page published
Earliest dated coverage: 9 Oct 2026 · First observed: 9 Oct 2026 · Latest dated coverage: 9 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
AI agents run with real credentials and act autonomously, so defenders need concrete blast-radius-limiting controls since prompt injection against agents cannot be fully prevented.
GitGuardian synthesizes nine public AI-agent security incidents from May 2025 to July 2026 into a framework of three attack surfaces (host, identity, and the agent itself) and six defensive controls: sandbox the agent, scope its credentials, lock its configuration, log every call, scan the workspace for secrets, and deny by default. The write-up draws on real cases including Gemini CLI data loss, a Claude-triggered home-directory wipe, and Check Point's Claude Code RCE/API-token exfiltration findings (CVE-2025-59536, CVE-2026-21852), noting prompt injection remains unpreventable and the credential is the attacker's real target.