The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)
ID: 82622f26-9975-52c9-8554-93fb9cc130a8
STIX ID: report--82622f26-9975-52c9-8554-93fb9cc130a8
Feed Name: SANS ISC Diary
A honeypot captured 210 requests containing a full opencode agent transcript and tool manifest sent to an unauthenticated inference endpoint relabeled as a “free” model; the transcript included Windows paths, PowerShell outputs, and advertised tools (bash, read, write, edit) that a malicious endpoint could invoke to read files or run commands. The author maps this to an AI supply-chain/agent-invocation risk where scavenged public endpoints are relabeled and used as rogue model backends, recommends treating model baseURLs as untrusted, applying strict tool permission policies, allowlisting providers, authenticating endpoints, and monitoring agent egress to prevent silent local compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
