The class is the leak
Classic embargo assumed the secret was
the details. Keep the stack trace off
the mailing list, ship in a week, write
the advisory when the packages are
ready. That bargain is dead when an
agent can turn “path normalisation in
cohttp” into a working probe in a
minute, and a public PR into scanner
traffic in ten. Fang’s 87% versus 7%
is the mechanism: the description is
a search direction. You do not have to
publish a proof of concept. You have to
avoid naming the class where watchers
sit.
So the process inverts. Discussion of
the class stays somewhere that is not
GitHub search. GitHub’s temporary
private forks sound like that, and
then they cut CI, allow one PR, and
enroll reviewers one admin click at a
time — which is not how August
open-source review works. Anil’s other
fork is worse in a different way:
ship continuously, like Chrome’s
twice-a-week security trains, and put
a protocol-layer mitigation in front of
the library the minute the class is
known. Percent-encoded separators can
be rejected at the edge while the
cohttp patch is still in review. The
library fix is the durable artifact.
The edge rule is what closes the
window.
The same geometry shows up in your own
agents, inverted. ChatGPT Work’s cloud
box combines private files, untrusted
pages, and egress. That is not “a
better Chat.” It is a product with
blast radius, and the public docs still
sell a job instead of a tool list.
Simon had to jailbreak the schema out
of the model. Do not make your
operators do that. Name the tools,
the filesystem, the browser, and the
network policy in the repo. Hide the
vuln class from the internet. Publish
the agent class to the people who
run it.
Humans still own taste, product intent,
and whether this agent should hold
production secrets. They do not own a
week of embargo theater after the PR
title already said “traversal.” Stop
condition: once the class has been
named in public, assume exploited —
ship the edge rule and the patch, do
not hunt for a more complete advisory.
Once the agent’s tools are listed and
the sandbox matches the list, stop
adding one more “be careful” paragraph.
A new class needs a new check. Otherwise
you are nerd-sniping the process.
Checklist
-
Do not open a public PR whose title
or diff names a vuln class until the
fix is released or an edge rule is
already live.
-
The minute the class is known, write
the cheap protocol mitigation
(normalize, reject, disable) and
deploy it in front of the library.
-
Count rumour window in minutes, not
embargo weeks. If watchers can see
it, treat it as broadcasting.
-
For your own agents: list tools,
skills, filesystem, and egress in
the repo. Do not describe the job
and hide the schema.
-
Work-class surfaces (browser +
private disk + open net) get a
trifecta budget, not a Chat tab.
This week: pick one public repo. If a
“cleanup” PR would name a class, it
is already a rumour. Write the edge
rule first.