Overview
Extracted from the local README when available.
AI agents now hold genuine system authority: they execute code, touch credentials, open network egress, parse hostile documents, and in many deployments initiate or approve changes to the very infrastructure they run on. This review, dated 2026-09-10, examines what that shift does to operating-system security. The primary scenario is a technically capable operator whose workstation faces both exploitation — an attacker compromising a browser, parser, dependency, or agent tool and then crossing a boundary — and authorized misuse — an attacker persuading an agent to use its existing, legitimate access to exfiltrate secrets or authorize consequential actions. The second path requires no kernel exploit at all, which reframes the evaluation: the axis of analysis is the authority a component already holds, not merely the difficulty of exploiting it. This revision (0.7.0) refreshes the evidence
Artifacts
Tracked documentation and PDFs served directly from this folder.
- agentic_os_security_combined.pdf 4,174,222 bytes
Full text extraction pending.