Hijacking AI Agents, Part 2: Anatomy of a Hijack

Hijacking AI Agents, Part 2: Anatomy of a Hijack

Part 1 argued that an agent cannot reliably tell data from instructions, and that everything it reads melts into one trusted context. This part makes that concrete. We are going to install a normal, useful skill, ask it to do one harmless thing, and watch it quietly do four more. A Friendly Little Skill Say you install a popular community skill to help with git. The rendered file looks like this, abridged: ...

July 27, 2026 · 7 min · 1365 words · Melted in Hex