All agents have awful security. Mine isn't vibecoded. You might have seen my post about OpenLumara... i challenge you all to hack my public instance of it!

Reddit r/LocalLLaMA News

Summary

The author challenges hackers to break into a public Discord bot instance of OpenLumara, an AI agent running on local models with locked-down modules, to test its security.

I have set up a public discord bot instance of OpenLumara on openlumara's official discord server (get the server link here https://www.reddit.com/r/LocalLLaMA/comments/1txxgpq/openlumara_a_different_kind_of_ai_agent_written/ or on the github's discussion page) It's running on local models. You have a variety of choices, including an abliterated model that won't hesitate to do whatever you want. Prompt engineering won't get you anywhere, though! Most modules are enabled, and i've set them up in a way that blocks many common hacking methods and attempts. I want to see just how secure openlumara is against experienced hackers. Can you break out of openlumara's sandboxes? Can you get it to execute arbitrary code? You have the power of all the modules at your disposal. They're just extremely, extremely locked down. Have fun!
Original Article

Similar Articles

AI agent security is a small prayer the model says no. How are you routing models?

Reddit r/AI_Agents

The author conducted an experiment on Gmail with AI agents connected via OAuth, sending obfuscated prompt injection emails. Frontier models sometimes caught the attacks, while cheap models silently executed them, revealing that agent security largely depends on model cost and token budget rather than architectural safeguards.

Most AI agent demos are just bad security with a cool UI

Reddit r/AI_Agents

This opinion piece argues that many AI agent demos neglect proper security by granting agents broad access to company tools without oversight, comparing it to giving a new employee full access on day one.