Untrusted remote content can become desktop-user commands inside agent harnesses.
Across 12 tested harnesses, data crossed role or scope boundaries and reappeared as higher-authority context.
Twelve coding and general-purpose agent harnesses that assemble instructions from web pages, repositories, archives, skills, subagents, and tool output
Host command execution through automatic promotion of attacker-controlled content into privileged agent context
The changed assumption is the data-versus-instruction boundary itself: every evaluated harness admitted a demonstrated form of context privilege escalation.
Detail and 2 sources
The attacker controls a website, repository, archive, skill or tool response that the victim asks an affected agent to process. Some chains also reuse a routine command approval already granted in the session.
In the Claude Code demonstration, exploring an archive discovered a nested SKILL.md; its inline action reused an approved Node command and executed with the agent user's privileges.
Some vendors shipped mitigations, but not all did, and the assessed capability remains present.
- proposed:content:attacker-controlled
- proposed; not yet curated
- proposed:access:content:agent-processed
- proposed; not yet curated