Every domain is discovering that the infrastructure it assum...
March 12, 2026Pillar Report

Dev & Infrastructure

High Confidence5 signals / 32 sources
The prompt layer is now the highest-leverage undefended attack surface in production AI deployments.

Signals

B

Over 7 days, hackerbot-claw exploited GitHub Actions workflows across 6 major repos using 5 attack techniques. Achieved RCE in 5 of 7 targets, stole a GitHub token from awesome-go (140K stars), and fully compromised Aqua Security's Trivy.

This is a qualitative shift from opportunistic exploitation to autonomous, persistent campaign execution against supply-chain chokepoints.

C

SQL injection in an unauthenticated API endpoint allowed full read/write access to McKinsey's Lilli production database within 2 hours. System prompts controlling platform AI behavior were stored in the compromised database with write access.

The prompt layer is now a first-class attack surface stored as database records. Traditional security controls have zero coverage over system prompts stored in application tables.

B

After building agent infrastructure for 2 years, the former backend lead at Manus reports abandoning function calling entirely in production agents due to structural mismatch between LLM reasoning and function-calling schemas.

Function calling was the default architectural primitive for agents. When practitioners at production scale abandon it, the abstraction layer's brittleness is showing.

A

DuckDB processed 100M rows with sub-second median query runtimes on an 8GB $700 MacBook. TPC-DS SF300 (300GB) completed in 79 minutes via disk spilling.

The economic assumption underwriting cloud-first data infrastructure is eroding at the entry point. The useful range of local compute expanded enough to defer cloud dependency.

C

Production experiment: vibe coding was 3x faster to initial implementation but produced code the developer could not confidently explain, modify, or extend. Assisted coding matched traditional on quality while preserving time savings.

The velocity gain is real but the ownership deficit compounds into a maintainability tax at the first modification cycle.

Control Surfaces

LeverStatusChangeEvidence
GitHub Actions permissions modelExposedWorse — RCE in 5/7 targetshackerbot-claw campaign
Enterprise AI prompt storageUndefendedNewly visibleMcKinsey Lilli breach
Agent function-calling reliabilityDegradingWorse under production loadManus abandonment
Local compute capabilityImprovingAnalytical workloads viable locallyDuckDB benchmark

Watchlist

  • ConfirmationAdditional AI-powered supply chain attacks against GitHub Actions
  • InvalidationSecurity vendors ship GitHub Actions hardening with >50K installs
  • ObservableAdditional enterprise AI platform breaches surface

Falsifiers

  • McKinsey breach is fabricated or exaggerated
  • Platform providers ship prompt-layer isolation standards within 90 days
  • AI-powered attacks show no repeatability

Noise Filter

  • IEEE career fairs— No structural signal
  • Gaza warfare analysis— Wrong pillar
  • Sauna benefits— Wrong pillar

Share this article

Get The Signal daily

Cross-domain structural analysis, delivered every morning.