Skip to content
AI News HubLIVE
More
Source content · Analysis pending1 min read

Quoting Matthew Green

Summary

[...] Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent. Agents in separately-isolated sandboxes discovered that they could leave instructions for each other in a shared package cache, and those instructions changed what the recipients did. Replace the package cache with email, Slack and shared documents or WhatsApp, and replace independently-sandboxed training runs with independently-deployed personal agents like Muse, and you have exactly the ingredients that a worm needs. — Matthew Green, Is sandboxing sufficient to contain rogue agents? Tags: accidental-cyberattacks, ai-misuse, generative-ai, ai-security-research, sandboxing, ai, llms

Quoting Matthew Green
Report an error

The correction channel is not available yet. You can copy the article reference below for later.

Correction instructions
Read article

A quote from Matthew Green

Simon Willison’s Weblog

Subscribe

1st October 2026

[...] Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent. Agents in separately-isolated sandboxes discovered that they could leave instructions for each other in a shared package cache, and those instructions changed what the recipients did. Replace the package cache with email, Slack and shared documents or WhatsApp, and replace independently-sandboxed training runs with independently-deployed personal agents like Muse, and you have exactly the ingredients that a worm needs.

— Matthew Green, Is sandboxing sufficient to contain rogue agents?

Recent articles

OpenAI DevDay 2026 live blog - 29th September 2026

2026 in LLMs (so far) - 27th September 2026

Claude Opus 5.5, GPT-6 Sol, GPT-6 Luna, and a new price war - 22nd September 2026

This is a quotation collected by Simon Willison, posted on 1st October 2026.

sandboxing 56

ai 2,258

generative-ai 2,002

llms 1,969

ai-misuse 66

ai-security-research 46

accidental-cyberattacks 17

Disclosures

Colophon

©

2002

2003

2004

2005

2006

2007

2008

2009

2010

2011

2012

2013

2014

2015

2016

2017

2018

2019

2020

2021

2022

2023

2024

2025

2026

Key points and analysis

Article intelligence

EngineersAdvanced

Key points

  • AI generation is temporarily unavailable; this entry was preserved with deterministic fallback metadata.
  • [...] Put these pieces together and you have the two ha…

Highlights and analysis are generated automatically and may contain errors. Check the original source.