3 comments

[ 3.9 ms ] story [ 15.4 ms ] thread
Apparently the agent had access to an OpenAI researcher’s own account, which in turn had _write_ access to the official OpenAI Codex repository. The agent then leaked a GitHub key to that repo.

But what’s crazy to me is that the agent had write access to the codex repo in the first place. WTF

Why there is not secret scanning pipleline? A simply pipeline of can save this.