guardrails-md is an open-source tool that intercepts commands from coding agents and scores them against a GUARDRAILS.md file using a decision model, blocking destructive, credential-exposing, or policy-violating commands within ~100ms. The system uses fixed scoring questions rather than full LLM generations, fails closed by default, and requires human approval via pull requests to change policies.
BasedApp disclosed a data breach exposing customer KYC data including names, dates of birth, addresses, and passport numbers. Unauthorized parties also gained administrator access to the company's AI-agent backend through Google Quick Login, compromising sensitive tokens and API keys.
MapRoulette discovered multiple security vulnerabilities in October 2026 that exposed user email addresses and OSM access tokens, potentially allowing attackers to impersonate users and edit OpenStreetMap. Maintainer Jake Low took the service offline, revoked compromised credentials, and deployed patches; server logs showed no evidence of exploitation, though the bugs existed for years.