The real bug is the harness, not the model
What jumps out here is how little “AI” is doing the interesting part of the damage. The failures sound glamorous if you only skim the headlines — prompt injection, agent compromise, secret theft — but the actual weakness is more boring and more worrying: code that decides what is trusted, then later uses that same thing with more authority than it deserves. That pattern feels like the thing teams keep rediscovering. The model gets blamed because it’s visible, but the break happens in the wrapper
papoo.work