Dev & Infrastructure
The prompt layer is now the highest-leverage undefended attack surface in production AI deployments.
Signals
Over 7 days, hackerbot-claw exploited GitHub Actions workflows across 6 major repos using 5 attack techniques. Achieved RCE in 5 of 7 targets, stole a GitHub token from awesome-go (140K stars), and fully compromised Aqua Security's Trivy.
This is a qualitative shift from opportunistic exploitation to autonomous, persistent campaign execution against supply-chain chokepoints.
SQL injection in an unauthenticated API endpoint allowed full read/write access to McKinsey's Lilli production database within 2 hours. System prompts controlling platform AI behavior were stored in the compromised database with write access.
The prompt layer is now a first-class attack surface stored as database records. Traditional security controls have zero coverage over system prompts stored in application tables.
After building agent infrastructure for 2 years, the former backend lead at Manus reports abandoning function calling entirely in production agents due to structural mismatch between LLM reasoning and function-calling schemas.
Function calling was the default architectural primitive for agents. When practitioners at production scale abandon it, the abstraction layer's brittleness is showing.
DuckDB processed 100M rows with sub-second median query runtimes on an 8GB $700 MacBook. TPC-DS SF300 (300GB) completed in 79 minutes via disk spilling.
The economic assumption underwriting cloud-first data infrastructure is eroding at the entry point. The useful range of local compute expanded enough to defer cloud dependency.
Production experiment: vibe coding was 3x faster to initial implementation but produced code the developer could not confidently explain, modify, or extend. Assisted coding matched traditional on quality while preserving time savings.
The velocity gain is real but the ownership deficit compounds into a maintainability tax at the first modification cycle.
Control Surfaces
| Lever | Status | Change | Evidence |
|---|---|---|---|
| GitHub Actions permissions model | Exposed | Worse — RCE in 5/7 targets | hackerbot-claw campaign |
| Enterprise AI prompt storage | Undefended | Newly visible | McKinsey Lilli breach |
| Agent function-calling reliability | Degrading | Worse under production load | Manus abandonment |
| Local compute capability | Improving | Analytical workloads viable locally | DuckDB benchmark |
Watchlist
- ConfirmationAdditional AI-powered supply chain attacks against GitHub Actions
- InvalidationSecurity vendors ship GitHub Actions hardening with >50K installs
- ObservableAdditional enterprise AI platform breaches surface
Falsifiers
- McKinsey breach is fabricated or exaggerated
- Platform providers ship prompt-layer isolation standards within 90 days
- AI-powered attacks show no repeatability
Noise Filter
- IEEE career fairs— No structural signal
- Gaza warfare analysis— Wrong pillar
- Sauna benefits— Wrong pillar
Get The Signal daily
Cross-domain structural analysis, delivered every morning.