Analysis · curated 3 Aug 2026
What Happens When AI Agents Go Off the Rails
First reported adversis.io
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Over-permissioned AI agents operating with a user's full credentials at machine speed can turn a single prompt injection into cross-system data exfiltration, and the piece explains why traditional permission models fail to contain it.
An Adversis field-notes analysis argues that most deployed AI agents are over-permissioned and that human role-based access control breaks down for autonomous agents. It uses Invariant Labs' finding that GitHub's official MCP server could be hijacked via a poisoned public-repo issue containing hidden prompt injection—causing a connected agent to exfiltrate private repo contents into a public pull request—as the anchor example, then explains why agent scope expands dynamically and chains across system boundaries in ways RBAC cannot capture.