proomt

Search

Search posts, papers, and topics

All posts

Freek Van der Herten1 min readintro

How to Stop an AI Agent from Destroying Your Laravel App

Summary

This text is an abstract for an article on hardening Laravel applications against destructive AI agent behavior, referencing the "PocketOS incident" and suggesting safeguards like deny rules and credential isolation. It does not contain the actual article content, only a brief description.

1/10

Related reading

  1. AI Agents Are Disrupting Open Source Security Disclosure

    AI agents can turn minimal public hints about software bugs into working exploits, rendering traditional embargoes ineffective. The article cites a study where a GPT‑4 agent exploited 87% of a 15‑vulnerability benchmark from CVE descriptions and discusses faster releases and revocable capabilities as mitigations.

    InfoQinfoq.com2 min
  2. Building Sentry's Laravel AI Integration

    Sentry added zero‑config Agent Tracing for Laravel AI agents. The integration hooks into Laravel AI events and HTTP request events to create Chat spans for each LLM call, matching requests by provider URL prefix. Updating to sentry‑laravel 4.27 automatically instruments agents without any user code changes.

    Sentrysentry.io4 min
  3. Confused Deputy: The Old Bug That AI Agents Keep Reintroducing

    The Confused Deputy problem—where a privileged component is tricked into misusing its authority—has resurfaced in AI agents that process natural‑language prompts. The article shows real 2026 attacks, explains why agents are especially vulnerable, and outlines mitigations like least‑privilege scopes, capability‑based tokens, and human‑in‑the‑loop approvals.

    Auth0auth0.com9 min
  4. Laravel Scalpel Scans for Filesystem Intrusion Evidence

    Laravel Scalpel is a Laravel‑native scanner that looks for post‑deployment filesystem tampering – rogue PHP files, obfuscated backdoors, altered .htaccess/.user.ini, missing or mis‑configured .env, and diffs against a signed baseline. It ships with six built‑in scanners, baseline snapshot commands, fast vs strict hashing modes, CI‑friendly output (JSON, SARIF, GitHub annotations) and a ScanFinish…

    Laravellaravel-news.com5 min
  5. Why we taught agents to break distributed safety properties

    The post introduces an Antithesis skill that lets AI agents perform mutation testing on distributed systems, injecting subtle bugs to check whether generated test suites can falsify safety properties. Using rqlite, the agents ran ~24 hours of tests, falsified 11 of 13 properties, and uncovered three real upstream bugs, demonstrating the technique’s practical value.

    Antithesisantithesis.com7 minHN3