Analysis · curated 3 Aug 2026

What Happens When AI Agents Go Off the Rails

Coverage timeline

3 Aug 2026adversis.io

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Over-permissioned AI agents operating with a user's full credentials at machine speed can turn a single prompt injection into cross-system data exfiltration, and the piece explains why traditional permission models fail to contain it.

An Adversis field-notes analysis argues that most deployed AI agents are over-permissioned and that human role-based access control breaks down for autonomous agents. It uses Invariant Labs' finding that GitHub's official MCP server could be hijacked via a poisoned public-repo issue containing hidden prompt injection—causing a connected agent to exfiltrate private repo contents into a public pull request—as the anchor example, then explains why agent scope expands dynamically and chains across system boundaries in ways RBAC cannot capture.