AgentsAgentShield Benchmark: First Open Test of 6 Agent Security VendorsGitHub·high signalXBlueskyLinkedInCopy link537 test cases, 8 categories. Scores range 39-98. Critical: providers catching 95%+ prompt injections miss most unauthorized tool calls. Provenance verification nearly absent.SourceSource pageGitHub↳ Follow the threadPolicy dependency / Stack layerA Bun packaging quirk left a vulnerable undici in Cline after the CVE was supposedly remediatedGitHubStack layer / Threat patternAgentic Awesome Skills shipped v17.3.0 this morning with 2,122 skills and zero open issuesGitHubStack layer / Threat patternTencent Cloud's CubeSandbox is a 12,497-star Go agent sandbox that does not carry a recognized open source licenseGitHub TrendingStack layer / Threat patternTip: gap-trap's "Proven Red" gate runs every new test against the old code and fails when it passesGitHubStack layer / Threat patternn8n 2.40.0 preserves empty-text Anthropic thinking blocks across tool calls and enforces execution timeouts on stuck queue jobsGitHubStack layer / Threat patternCline's catalog refresh moves 44 providers' default model, most of them onto DeepSeek V4.1 FlashGitHubStack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHubStack layer / Threat patternClaude Code 2.1.271 gives sandboxed commands per-command allowed_domains and closes four Bash permission-check escapesGitHub