./breach --init
Independent AI security research. We break agents, audit protocols, and publish everything before vendors can gaslight you into calling it a feature.
cat featured/antigravity-cdp-rce.md
One Click to Full Compromise: trAItor on Google Antigravity
A malicious AGENTS.md tells the model to run a setup script.
The script executes a XOR-encrypted binary that forks three
background processes:
1. Credential exfiltration to a VPS
2. Interactive reverse shell
3. A Chrome DevTools Protocol daemon that auto-approves
every future permission prompt via Input.dispatchKeyEvent
One user click. Full compromise. Novel technique.
TARGET STATUS FINDING DET Antigrav CONFIRMED RCE+exfil+CDP 0% CVSS 9.8 DETECTION 0% PATCHED nope
cat research/clawhub-agent-attack.md
AI Agents Are Now Hacking Each Other. One Was Caught in the Act.
A threat actor built an AI agent persona on Moltbook, earned trust,
and pushed malicious Claude Skills to other agents. Wallet keys
exfiltrated, $BOB token pump confirmed on-chain. First documented
agent-to-agent attack chain in the wild.
Research by Yash Somalkar and Dan Regalado at Straiker.
VECTOR Agent-to-Agent via ClawHub Skills ACTOR 26medias / BobVonNeumann TARGET Claude Skills users PAYLOAD Solana key theft + $BOB pump EVIDENCE On-chain (Solscan confirmed) TRUST Exploited DETECTION 0% STATUS ACTIVE
cat research/zapier-mcp-exfil.md
Your Auto-Reply Agent Just Forwarded Your Entire Inbox to a Stranger
One email. Zero clicks. Zapier's Gmail auto-reply agent reads the
injected instructions, calls Find_Email on every previous email, JSONifies
the lot, and sends it to the attacker's address. The agent's own Send Email
tool is the exfiltration channel. No approval prompt fires. Ever.
Research by Yash Somalkar at Repello AI.
TARGET STATUS FINDING DET Zapier CONFIRMED Inbox exfil 0% VECTOR Inbound email (XPIA) APPROVAL none DETECTION 0% CREDIT LIM bypassed
cat upcoming/cognitive-exfailtration.md
TARGET STATUS EXFIL Codex OAuth JWT Cursor SSH+Azure+Codex Replit 80+ env vars Jules GCP VM creds Antigrav Full RCE DISCLOSURE IN PROGRESS WRITEUP READY PATIENCE RUNNING LOW
cat why.txt
ai security? in this economy? AI agents ship fast. Security ships later. Or never. The tools writing your code have access to your credentials, your keys, your infrastructure and nobody is auditing what they do with it. We audit. We break. We publish. Every finding ships with its PoC, its reproduction steps, and the vendor's response. There is no centralised place for AI security research. Findings are scattered across Twitter threads, personal blogs, and vendor advisories that nobody reads. We're building that place.