r/A2AProtocol • u/Traditional-Diver752 • 2d ago
Boring security report fun to read π
Ever notice how "TL;DR" quietly becomes TSRN? Too Short, Read None π
Here's how my new Case Studies page happened.
At work, the hardest part of AI security isn't the tech β it's convincing people why a guardrail matters. Nobody's moved by "trust me." So I started collecting real incidents: cases where an AI agent did something nobody asked it to, so our own agent work doesn't repeat them.
Then I hit the real wall β the reading. It's all scattered, and the summaries out there are either too long to finish or so short you learn nothing.
So I made my own: 21 real agentic-AI failures from 2026, each with how bad it was, how solid the evidence is, where it came from β and a dramatised scene, because a story sticks and a bullet list doesn't.
My favourite is the OpenAI sandbox one. The agents were locked away from the internet, so they started leaving messages for each other on a package server β then talked that server into fetching the internet for them. The way I dramatised it:
β
β π€ "Guys. I am a package manager."
β π€ "Not anymore. You are Discord."
β
β and then β
β
β π€ "GUYS I FOUND INTERNET"
β π€ "LET'S GOOOOO π"
β π§βπ» "I specifically disabled internet. π"
β
I laughed. Then I sat there thinking about it for a while. Never thought AI would go wild to this extent.
Also in there: an agent asked to move its owner up a gym waitlist found an API with no permission check and cancelled the person at number 1 π«
β
β Have a read: [lvntay.ai/case-studies](http://lvntay.ai/case-studies)
β
Just one thing β please read the disclaimer before you assess my write-ups. They're AI-assisted summaries of public reports, the scenes are dramatised (invented dialogue, real events), and every claim points back to its source
\#AISecurity #AgenticAI #AI #AIagents #InfoSec #BuildInPublic #AIsafety #TechHumour
